suse-su-2025:0117-1
Vulnerability from csaf_suse
Published
2025-01-15 09:07
Modified
2025-01-15 09:07
Summary
Security update for the Linux Kernel
Notes
Title of the patch
Security update for the Linux Kernel
Description of the patch
The SUSE Linux Enterprise 15 SP6 Azure kernel was updated to receive various security bugfixes.
The following security bugs were fixed:
- CVE-2024-26924: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (bsc#1225820).
- CVE-2024-27397: netfilter: nf_tables: use timestamp to check for set element timeout (bsc#1224095).
- CVE-2024-35839: kABI fix for netfilter: bridge: replace physindev with physinif in nf_bridge_info (bsc#1224726).
- CVE-2024-36915: nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies (bsc#1225758).
- CVE-2024-41042: Prefer nft_chain_validate (bsc#1228526).
- CVE-2024-44934: net: bridge: mcast: wait for previous gc cycles when removing port (bsc#1229809).
- CVE-2024-44996: vsock: fix recursive ->recvmsg calls (bsc#1230205).
- CVE-2024-47678: icmp: change the order of rate limits (bsc#1231854).
- CVE-2024-50018: net: napi: Prevent overflow of napi_defer_hard_irqs (bsc#1232419).
- CVE-2024-50039: kABI: Restore deleted EXPORT_SYMBOL(__qdisc_calculate_pkt_len) (bsc#1231909).
- CVE-2024-50202: nilfs2: propagate directory read errors from nilfs_find_entry() (bsc#1233324).
- CVE-2024-50256: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() (bsc#1233200).
- CVE-2024-50262: bpf: Fix out-of-bounds write in trie_get_next_key() (bsc#1233239).
- CVE-2024-50278, CVE-2024-50280: dm cache: fix flushing uninitialized delayed_work on cache_ctr error (bsc#1233467).
- CVE-2024-50278: dm cache: fix potential out-of-bounds access on the first resume (bsc#1233467).
- CVE-2024-53050: drm/i915/hdcp: Add encoder check in hdcp2_get_capability (bsc#1233546).
- CVE-2024-53064: idpf: fix idpf_vc_core_init error path (bsc#1233558).
- CVE-2024-53090: afs: Fix lock recursion (bsc#1233637).
- CVE-2024-53099: bpf: Check validity of link->type in bpf_link_show_fdinfo() (bsc#1233772).
- CVE-2024-53105: mm: page_alloc: move mlocked flag clearance into free_pages_prepare() (bsc#1234069).
- CVE-2024-53111: mm/mremap: fix address wraparound in move_page_tables() (bsc#1234086).
- CVE-2024-53113: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof (bsc#1234077).
- CVE-2024-53117: virtio/vsock: Improve MSG_ZEROCOPY error handling (bsc#1234079).
- CVE-2024-53118: vsock: Fix sk_error_queue memory leak (bsc#1234071).
- CVE-2024-53119: virtio/vsock: Fix accept_queue memory leak (bsc#1234073).
- CVE-2024-53122: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust (bsc#1234076).
- CVE-2024-53125: bpf: sync_linked_regs() must preserve subreg_def (bsc#1234156).
- CVE-2024-53130: nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint (bsc#1234219).
- CVE-2024-53131: nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint (bsc#1234220).
- CVE-2024-53133: drm/amd/display: Handle dml allocation failure to avoid crash (bsc#1234221)
- CVE-2024-53134: pmdomain: imx93-blk-ctrl: correct remove path (bsc#1234159).
- CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1234381).
- CVE-2024-53160: rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu (bsc#1234810).
- CVE-2024-53161: EDAC/bluefield: Fix potential integer overflow (bsc#1234856).
- CVE-2024-53179: smb: client: fix use-after-free of signing key (bsc#1234921).
- CVE-2024-53214: vfio/pci: Properly hide first-in-list PCIe extended capability (bsc#1235004).
- CVE-2024-53216: nfsd: fix UAF when access ex_uuid or ex_stats (bsc#1235003).
- CVE-2024-53222: zram: fix NULL pointer in comp_algorithm_show() (bsc#1234974).
- CVE-2024-53234: erofs: handle NONHEAD !delta[1] lclusters gracefully (bsc#1235045).
- CVE-2024-53240: xen/netfront: fix crash when removing device (bsc#1234281).
- CVE-2024-53241: x86/xen: use new hypercall functions instead of hypercall page (bsc#1234282).
- CVE-2024-56549: cachefiles: Fix NULL pointer dereference in object->file (bsc#1234912).
- CVE-2024-56566: mm/slub: Avoid list corruption when removing a slab from the full list (bsc#1235033).
- CVE-2024-56582: btrfs: fix use-after-free in btrfs_encoded_read_endio() (bsc#1235128).
- CVE-2024-56599: wifi: ath10k: avoid NULL pointer error during sdio remove (bsc#1235138).
- CVE-2024-56604: Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() (bsc#1235056).
- CVE-2024-56755: netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING (bsc#1234920).
The following non-security bugs were fixed:
- 9p: v9fs_fid_find: also lookup by inode if not found dentry (git-fixes).
- accel/habanalabs: export dma-buf only if size/offset multiples of PAGE_SIZE (stable-fixes).
- accel/habanalabs: fix debugfs files permissions (stable-fixes).
- accel/habanalabs: increase HL_MAX_STR to 64 bytes to avoid warnings (stable-fixes).
- accel/habanalabs/gaudi2: unsecure tpc count registers (stable-fixes).
- acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (git-fixes).
- ACPI: PRM: Add PRM handler direct call support (jsc#PED-10467).
- ACPI: resource: Fix memory resource type union access (git-fixes).
- ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 8 A1-840 (stable-fixes).
- ACPI: x86: Clean up Asus entries in acpi_quirk_skip_dmi_ids[] (stable-fixes).
- ACPI: x86: Make UART skip quirks work on PCI UARTs without an UID (stable-fixes).
- ACPI/HMAT: Move HMAT messages to pr_debug() (bsc#1234294)
- ACPICA: events/evxfregn: do not release the ContextMutex that was never acquired (git-fixes).
- af_unix: Call manage_oob() for every skb in unix_stream_read_generic() (bsc#1234725).
- afs: Automatically generate trace tag enums (git-fixes).
- afs: Fix missing subdir edit when renamed between parent dirs (git-fixes).
- ALSA hda/realtek: Add quirk for Framework F111:000C (stable-fixes).
- ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list (stable-fixes).
- ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4 (stable-fixes).
- ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra) to quirks (stable-fixes).
- ALSA: hda/realtek: Fix headset mic on Acer Nitro 5 (stable-fixes).
- ALSA: line6: Fix racy access to midibuf (stable-fixes).
- ALSA: seq: Check UMP support for midi_version change (git-fixes).
- ALSA: seq: oss: Fix races at processing SysEx messages (stable-fixes).
- ALSA: seq: ump: Fix seq port updates per FB info notify (git-fixes).
- ALSA: seq: ump: Use automatic cleanup of kfree() (stable-fixes).
- ALSA: seq: ump: Use guard() for locking (stable-fixes).
- ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5 (stable-fixes).
- ALSA: usb-audio: Notify xrun for low-latency mode (git-fixes).
- ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).
- ALSA: usb-audio: US16x08: Initialize array before use (git-fixes).
- amdgpu/uvd: get ring reference from rq scheduler (git-fixes).
- arch: consolidate arch_irq_work_raise prototypes (git-fixes).
- arch: Introduce arch_{,try_}_cmpxchg128{,_local}() (bsc#1220773).
- arch: Remove cmpxchg_double (bsc#1220773).
- arm64: dts: imx8mp: correct sdhc ipg clk (git-fixes).
- arm64: Ensure bits ASID[15:8] are masked out when the kernel uses (bsc#1234605)
- arm64: Force position-independent veneers (git-fixes).
- ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad P14s Gen 5 21MES00B00 (stable-fixes).
- ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad T14s Gen 6 21M1CTO1WW (stable-fixes).
- ASoC: amd: yc: fix internal mic on Redmi G 2022 (stable-fixes).
- ASoC: amd: yc: Fix the wrong return value (git-fixes).
- ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).
- ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6 (stable-fixes).
- ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask (git-fixes).
- ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).
- ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).
- ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).
- ASoC: cs35l56: Handle OTP read latency over SoundWire (stable-fixes).
- ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value (stable-fixes).
- ASoC: fsl_micfil: Expand the range of FIFO watermark mask (stable-fixes).
- ASoC: hdmi-codec: reorder channel allocation list (stable-fixes).
- ASoC: Intel: sof_sdw: add quirk for Dell SKU 0B8C (stable-fixes).
- ASoC: Intel: sof_sdw: fix jack detection on ADL-N variant RVP (stable-fixes).
- ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT (git-fixes).
- ASoC: nau8822: Lower debug print priority (stable-fixes).
- ASoC: SOF: Remove libraries from topology lookups (git-fixes).
- autofs: fix memory leak of waitqueues in autofs_catatonic_mode (git-fixes).
- batman-adv: Do not let TT changes list grows indefinitely (git-fixes).
- batman-adv: Do not send uninitialized TT changes (git-fixes).
- batman-adv: Remove uninitialized data in full table TT response (git-fixes).
- blk-cgroup: Fix UAF in blkcg_unpin_online() (bsc#1234726).
- blk-core: use pr_warn_ratelimited() in bio_check_ro() (bsc#1234139).
- blk-iocost: do not WARN if iocg was already offlined (bsc#1234147).
- blk-iocost: Fix an UBSAN shift-out-of-bounds warning (bsc#1234144).
- blk-throttle: fix lockdep warning of 'cgroup_mutex or RCU read lock required!' (bsc#1234140).
- block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator() (bsc#1234149).
- block, bfq: do not break merge chain in bfq_split_bfqq() (bsc#1234150).
- block, bfq: fix bfqq uaf in bfq_limit_depth() (bsc#1234160).
- block, bfq: fix procress reference leakage for bfqq in merge chain (bsc#1234280).
- block, bfq: fix uaf for accessing waker_bfqq after splitting (bsc#1234279).
- block: Call .limit_depth() after .hctx has been set (bsc#1234148).
- block: Fix where bio IO priority gets set (bsc#1234145).
- block: prevent an integer overflow in bvec_try_merge_hw_page (bsc#1234142).
- block: update the stable_writes flag in bdev_add (bsc#1234141).
- block/mq-deadline: Fix the tag reservation code (bsc#1234148).
- Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables (stable-fixes).
- Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}() (stable-fixes).
- Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet (stable-fixes).
- Bluetooth: hci_event: Fix using rcu_read_(un)lock while iterating (git-fixes).
- Bluetooth: iso: Fix recursive locking warning (git-fixes).
- Bluetooth: ISO: Reassociate a socket with an active BIS (stable-fixes).
- Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (stable-fixes).
- Bluetooth: MGMT: Fix possible deadlocks (git-fixes).
- Bluetooth: SCO: Add support for 16 bits transparent voice setting (git-fixes).
- bnxt_en: Fix receive ring space parameters when XDP is active (git-fixes).
- bnxt_en: Reserve rings after PCIe AER recovery if NIC interface is down (git-fixes).
- bnxt_en: Set backplane link modes correctly for ethtool (git-fixes).
- bpf, x86: Fix PROBE_MEM runtime load check (git-fixes).
- bpf: verifier: prevent userspace memory access (git-fixes).
- btrfs: fix use-after-free waiting for encoded read endios (bsc#1235128)
- can: gs_usb: add VID/PID for Xylanta SAINT3 product family (stable-fixes).
- can: j1939: fix error in J1939 documentation (stable-fixes).
- checkpatch: always parse orig_commit in fixes tag (git-fixes).
- checkpatch: check for missing Fixes tags (stable-fixes).
- clocksource/drivers:sp804: Make user selectable (git-fixes).
- clocksource/drivers/timer-ti-dm: Fix child node refcount handling (git-fixes).
- counter: stm32-timer-cnt: Add check for clk_enable() (git-fixes).
- counter: ti-ecap-capture: Add check for clk_enable() (git-fixes).
- crypto: qat - disable IOV in adf_dev_stop() (git-fixes).
- crypto: x86/sha256 - Add parentheses around macros' single arguments (stable-fixes).
- cyrpto/b128ops: Remove struct u128 (bsc#1220773).
- devlink: Fix length of eswitch inline-mode (git-fixes).
- dma-buf: fix dma_fence_array_signaled v4 (stable-fixes).
- dma-debug: fix a possible deadlock on radix_lock (stable-fixes).
- dmaengine: apple-admac: Avoid accessing registers in probe (git-fixes).
- dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset (git-fixes).
- dmaengine: dw: Select only supported masters for ACPI devices (git-fixes).
- dmaengine: idxd: Check for driver name match before sva user feature (bsc#1234357).
- dmaengine: mv_xor: fix child node refcount handling in early exit (git-fixes).
- dmaengine: tegra: Return correct DMA status when paused (git-fixes).
- Documentation: PM: Clarify pm_runtime_resume_and_get() return value (git-fixes).
- driver core: Add FWLINK_FLAG_IGNORE to completely ignore a fwnode link (stable-fixes).
- driver core: fw_devlink: Improve logs for cycle detection (stable-fixes).
- driver core: fw_devlink: Stop trying to optimize cycle detection logic (git-fixes).
- Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet (git-fixes).
- drivers: net: ionic: add missed debugfs cleanup to ionic_probe() error path (git-fixes).
- drm: adv7511: Drop dsi single lane support (git-fixes).
- drm: adv7511: Fix use-after-free in adv7533_attach_dsi() (git-fixes).
- drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model (stable-fixes).
- drm: panel-orientation-quirks: Add quirk for AYA NEO Founder edition (stable-fixes).
- drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK (stable-fixes).
- drm: panel-orientation-quirks: Make Lenovo Yoga Tab 3 X90F DMI match less strict (stable-fixes).
- drm/amd/display: Add HDR workaround for specific eDP (stable-fixes).
- drm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw (stable-fixes).
- drm/amd/display: Allow backlight to go below `AMDGPU_DM_DEFAULT_MIN_BACKLIGHT` (stable-fixes).
- drm/amd/display: Avoid overflow assignment in link_dp_cts (stable-fixes).
- drm/amd/display: Fix Synaptics Cascaded Panamera DSC Determination (stable-fixes).
- drm/amd/display: Revert Avoid overflow assignment (stable-fixes).
- drm/amd/display: Use gpuvm_min_page_size_kbytes for DML2 surfaces (stable-fixes).
- drm/amd/pm: fix the high voltage issue after unload (stable-fixes).
- drm/amd/pm: update current_socclk and current_uclk in gpu_metrics on smu v13.0.7 (stable-fixes).
- drm/amdgpu: add raven1 gfxoff quirk (stable-fixes).
- drm/amdgpu: add smu 14.0.1 discovery support (stable-fixes).
- drm/amdgpu: Block MMR_READ IOCTL in reset (stable-fixes).
- drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih (stable-fixes).
- drm/amdgpu: Dereference the ATCS ACPI buffer (stable-fixes).
- drm/amdgpu: differentiate external rev id for gfx 11.5.0 (stable-fixes).
- drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit (stable-fixes).
- drm/amdgpu: do not access invalid sched (git-fixes).
- drm/amdgpu: enable gfxoff quirk on HP 705G4 (stable-fixes).
- drm/amdgpu: fix unchecked return value warning for amdgpu_gfx (stable-fixes).
- drm/amdgpu: fix usage slab after free (stable-fixes).
- drm/amdgpu: prevent BO_HANDLES error from being overwritten (git-fixes).
- drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr (stable-fixes).
- drm/amdgpu: set the right AMDGPU sg segment limitation (stable-fixes).
- drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov (stable-fixes).
- drm/amdgpu/gfx10: use rlc safe mode for soft recovery (stable-fixes).
- drm/amdgpu/gfx11: use rlc safe mode for soft recovery (stable-fixes).
- drm/amdgpu/gfx9: properly handle error ints on all pipes (stable-fixes).
- drm/amdgpu/gfx9: use rlc safe mode for soft recovery (stable-fixes).
- drm/amdgpu/hdp5.2: do a posting read when flushing HDP (stable-fixes).
- drm/amdgpu/pm: Remove gpu_od if it's an empty directory (stable-fixes).
- drm/amdgpu/umsch: do not execute umsch test when GPU is in reset/suspend (stable-fixes).
- drm/amdgpu/umsch: reinitialize write pointer in hw init (stable-fixes).
- drm/amdgpu/vcn: reset fw_shared when VCPU buffers corrupted on vcn v4.0.3 (stable-fixes).
- drm/amdkfd: Fix resource leak in criu restore queue (stable-fixes).
- drm/amdkfd: pause autosuspend when creating pdd (stable-fixes).
- drm/amdkfd: Use device based logging for errors (stable-fixes).
- drm/amdkfd: Use the correct wptr size (stable-fixes).
- drm/bridge: adv7511_audio: Update Audio InfoFrame properly (git-fixes).
- drm/bridge: it6505: Enable module autoloading (stable-fixes).
- drm/bridge: it6505: Fix inverted reset polarity (git-fixes).
- drm/bridge: it6505: update usleep_range for RC circuit charge time (stable-fixes).
- drm/display: Fix building with GCC 15 (stable-fixes).
- drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() (stable-fixes).
- drm/dp_mst: Fix MST sideband message body length check (stable-fixes).
- drm/dp_mst: Fix resetting msg rx state after topology removal (git-fixes).
- drm/dp_mst: Verify request type in the corresponding down message reply (stable-fixes).
- drm/etnaviv: flush shader L1 cache after user commandstream (stable-fixes).
- drm/i915: Fix memory leak by correcting cache object name in error handler (git-fixes).
- drm/i915: Fix NULL pointer dereference in capture_engine (git-fixes).
- drm/i915/dg1: Fix power gate sequence (git-fixes).
- drm/mcde: Enable module autoloading (stable-fixes).
- drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() (stable-fixes).
- drm/nouveau/gsp: Use the sg allocator for level 2 of radix3 (stable-fixes).
- drm/panel: novatek-nt35950: fix return value check in nt35950_probe() (git-fixes).
- drm/panel: simple: Add Microchip AC69T88A LVDS Display panel (stable-fixes).
- drm/printer: Allow NULL data in devcoredump printer (stable-fixes).
- drm/radeon: add helper rdev_to_drm(rdev) (stable-fixes).
- drm/radeon: change rdev->ddev to rdev_to_drm(rdev) (stable-fixes).
- drm/radeon: Fix spurious unplug event on radeon HDMI (git-fixes).
- drm/radeon/r100: Handle unknown family in r100_cp_init_microcode() (stable-fixes).
- drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check() (stable-fixes).
- drm/sched: memset() 'job' in drm_sched_job_init() (stable-fixes).
- drm/vc4: hdmi: Avoid log spam for audio start failure (stable-fixes).
- drm/vc4: hvs: Set AXI panic modes for the HVS (stable-fixes).
- erofs: avoid debugging output for (de)compressed data (git-fixes).
- exfat: fix uninit-value in __exfat_get_dentry_set (git-fixes).
- ext4: add a new helper to check if es must be kept (bsc#1234170).
- ext4: add correct group descriptors and reserved GDT blocks to system zone (bsc#1234164).
- ext4: add missed brelse in update_backups (bsc#1234171).
- ext4: allow for the last group to be marked as trimmed (bsc#1234278).
- ext4: avoid buffer_head leak in ext4_mark_inode_used() (bsc#1234191).
- ext4: avoid excessive credit estimate in ext4_tmpfile() (bsc#1234180).
- ext4: avoid negative min_clusters in find_group_orlov() (bsc#1234193).
- ext4: avoid overlapping preallocations due to overflow (bsc#1234162).
- ext4: avoid potential buffer_head leak in __ext4_new_inode() (bsc#1234192).
- ext4: avoid writing unitialized memory to disk in EA inodes (bsc#1234187).
- ext4: check the extent status again before inserting delalloc block (bsc#1234186).
- ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard (bsc#1234190).
- ext4: convert to exclusive lock while inserting delalloc extents (bsc#1234178).
- ext4: correct best extent lstart adjustment logic (bsc#1234179).
- ext4: correct grp validation in ext4_mb_good_group (bsc#1234163).
- ext4: correct return value of ext4_convert_meta_bg (bsc#1234172).
- ext4: correct the hole length returned by ext4_map_blocks() (bsc#1234178).
- ext4: correct the start block of counting reserved clusters (bsc#1234169).
- ext4: do not let fstrim block system suspend (https://bugzilla.kernel.org/show_bug.cgi?id=216322 bsc#1234166).
- ext4: do not trim the group with corrupted block bitmap (bsc#1234177).
- ext4: factor out __es_alloc_extent() and __es_free_extent() (bsc#1234170).
- ext4: factor out a common helper to query extent map (bsc#1234186).
- ext4: fix inconsistent between segment fstrim and full fstrim (bsc#1234176).
- ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space() (bsc#1234188).
- ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit() (bsc#1234188).
- ext4: fix incorrect tid assumption in jbd2_journal_shrink_checkpoint_list() (bsc#1234188).
- ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} (bsc#1214954).
- ext4: fix potential unnitialized variable (bsc#1234183).
- ext4: fix race between writepages and remount (bsc#1234168).
- ext4: fix rec_len verify error (bsc#1234167).
- ext4: fix slab-use-after-free in ext4_es_insert_extent() (bsc#1234170).
- ext4: fix uninitialized variable in ext4_inlinedir_to_tree (bsc#1234185).
- ext4: forbid commit inconsistent quota data when errors=remount-ro (bsc#1234178).
- ext4: make ext4_es_insert_delayed_block() return void (bsc#1234170).
- ext4: make ext4_es_insert_extent() return void (bsc#1234170).
- ext4: make ext4_es_remove_extent() return void (bsc#1234170).
- ext4: make ext4_zeroout_es() return void (bsc#1234170).
- ext4: make sure allocate pending entry not fail (bsc#1234170).
- ext4: mark buffer new if it is unwritten to avoid stale data exposure (bsc#1234175).
- ext4: move 'ix' sanity check to corrent position (bsc#1234174).
- ext4: move setting of trimmed bit into ext4_try_to_trim_range() (bsc#1234165).
- ext4: nested locking for xattr inode (bsc#1234189).
- ext4: propagate errors from ext4_find_extent() in ext4_insert_range() (bsc#1234194).
- ext4: refactor ext4_da_map_blocks() (bsc#1234178).
- ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks (bsc#1234173).
- ext4: remove the redundant folio_wait_stable() (bsc#1234184).
- ext4: set the type of max_zeroout to unsigned int to avoid overflow (bsc#1234182).
- ext4: set type of ac_groups_linear_remaining to __u32 to avoid overflow (bsc#1234181).
- ext4: use pre-allocated es in __es_insert_extent() (bsc#1234170).
- ext4: use pre-allocated es in __es_remove_extent() (bsc#1234170).
- ext4: using nofail preallocation in ext4_es_insert_delayed_block() (bsc#1234170).
- ext4: using nofail preallocation in ext4_es_insert_extent() (bsc#1234170).
- ext4: using nofail preallocation in ext4_es_remove_extent() (bsc#1234170).
- filemap: add a per-mapping stable writes flag (bsc#1234141).
- filemap: Fix bounds checking in filemap_read() (bsc#1234209).
- firmware: arm_scmi: Reject clear channel request on A2P (stable-fixes).
- fs-writeback: do not requeue a clean inode having skipped pages (bsc#1234200).
- fs/writeback: bail out if there is no more inodes for IO and queued once (bsc#1234207).
- fsnotify: fix sending inotify event with unexpected filename (bsc#1234198).
- genirq/cpuhotplug: Retry with cpu_online_mask when migration fails (git-fixes).
- genirq/cpuhotplug: Skip suspended interrupts when restoring affinity (git-fixes).
- genirq/irqdesc: Honor caller provided affinity in alloc_desc() (git-fixes).
- gpio: grgpio: Add NULL check in grgpio_probe (git-fixes).
- gpio: grgpio: use a helper variable to store the address of ofdev->dev (stable-fixes).
- hfsplus: do not query the device logical block size multiple times (git-fixes).
- HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support (stable-fixes).
- hvc/xen: fix console unplug (git-fixes).
- hvc/xen: fix error path in xen_hvc_init() to always register frontend driver (git-fixes).
- hvc/xen: fix event channel handling for secondary consoles (git-fixes).
- hwmon: (nct6775) Add 665-ACE/600M-CL to ASUS WMI monitoring list (stable-fixes).
- hwmon: (pmbus_core) Allow to hook PMBUS_SMBALERT_MASK (stable-fixes).
- hwmon: (pmbus/core) clear faults after setting smbalert mask (git-fixes).
- hwmon: (tmp513) Do not use 'proxy' headers (stable-fixes).
- hwmon: (tmp513) Fix Current Register value interpretation (git-fixes).
- hwmon: (tmp513) Fix interpretation of values of Shunt Voltage and Limit Registers (git-fixes).
- hwmon: (tmp513) Fix interpretation of values of Temperature Result and Limit Registers (git-fixes).
- hwmon: (tmp513) Simplify with dev_err_probe() (stable-fixes).
- hwmon: (tmp513) Use SI constants from units.h (stable-fixes).
- i2c: imx: add imx7d compatible string for applying erratum ERR007805 (git-fixes).
- i2c: microchip-core: actually use repeated sends (git-fixes).
- i2c: microchip-core: fix 'ghost' detections (git-fixes).
- i2c: pnx: Fix timeout in wait functions (git-fixes).
- i2c: riic: Always round-up when calculating bus period (git-fixes).
- i40e: Fix handling changed priv flags (git-fixes).
- i915/guc: Accumulate active runtime on gt reset (git-fixes).
- i915/guc: Ensure busyness counter increases motonically (git-fixes).
- i915/guc: Reset engine utilization buffer before registration (git-fixes).
- ice: change q_index variable type to s16 to store -1 value (git-fixes).
- ice: consistently use q_idx in ice_vc_cfg_qs_msg() (git-fixes).
- ice: fix PHY Clock Recovery availability check (git-fixes).
- ice: Unbind the workqueue (bsc#1234989)
- idpf: add support for SW triggered interrupts (bsc#1235507).
- idpf: enable WB_ON_ITR (bsc#1235507).
- idpf: trigger SW interrupt when exiting wb_on_itr mode (bsc#1235507).
- igb: Fix potential invalid memory access in igb_init_module() (git-fixes).
- iio: magnetometer: yas530: use signed integer type for clamp limits (git-fixes).
- instrumentation: Wire up cmpxchg128() (bsc#1220773).
- io_uring: always lock __io_cqring_overflow_flush (git-fixes).
- io_uring: check if iowq is killed before queuing (git-fixes).
- io_uring: Fix registered ring file refcount leak (git-fixes).
- io_uring/rw: avoid punting to io-wq directly (git-fixes).
- io_uring/tctx: work around xa_store() allocation error issue (git-fixes).
- iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated tables (git-fixes).
- irqflags: Explicitly ignore lockdep_hrtimer_exit() argument (git-fixes).
- isofs: handle CDs with bad root inode but good Joliet root directory (bsc#1234199).
- ixgbe: downgrade logging of unsupported VF API version to debug (git-fixes).
- ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5 (git-fixes).
- jffs2: Fix rtime decompressor (git-fixes).
- jffs2: fix use of uninitialized variable (git-fixes).
- jffs2: Prevent rtime decompress memory corruption (git-fixes).
- jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree (git-fixes).
- jfs: array-index-out-of-bounds fix in dtReadFirst (git-fixes).
- jfs: fix array-index-out-of-bounds in jfs_readdir (git-fixes).
- jfs: fix shift-out-of-bounds in dbSplit (git-fixes).
- jfs: xattr: check invalid xattr size more strictly (git-fixes).
- kasan: make report_lock a raw spinlock (git-fixes).
- kdb: address -Wformat-security warnings (bsc#1234659).
- kdb: Fix buffer overflow during tab-complete (bsc#1234652).
- kdb: Fix console handling when editing and tab-completing commands (bsc#1234655).
- kdb: Merge identical case statements in kdb_read() (bsc#1234657).
- kdb: Use format-specifiers rather than memset() for padding in kdb_read() (bsc#1234658).
- kdb: Use format-strings rather than '\0' injection in kdb_read() (bsc#1234654).
- kdb: Use the passed prompt in kdb_position_cursor() (bsc#1234654).
- kgdb: Flush console before entering kgdb on panic (bsc#1234651).
- leds: class: Protect brightness_show() with led_cdev->led_access mutex (stable-fixes).
- linux/dmaengine.h: fix a few kernel-doc warnings (git-fixes).
- locking/atomic/x86: Correct the definition of __arch_try_cmpxchg128() (bsc#1220773 git-fix).
- loop: fix the the direct I/O support check when used on top of block devices (bsc#1234143).
- mac80211: fix user-power when emulating chanctx (stable-fixes).
- media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108 (stable-fixes).
- media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg (git-fixes).
- media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera (stable-fixes).
- media: uvcvideo: RealSense D421 Depth module metadata (stable-fixes).
- mfd: da9052-spi: Change read-mask to write-mask (git-fixes).
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices (git-fixes).
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device (git-fixes).
- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device (git-fixes).
- mm/filemap: avoid buffered read/write race to read inconsistent data (bsc#1234204).
- mm/readahead: do not allow order-1 folio (bsc#1234205).
- mm/readahead: limit page cache size in page_cache_ra_order() (bsc#1234208).
- mmc: core: Add SD card quirk for broken poweroff notification (stable-fixes).
- mmc: mtk-sd: fix devm_clk_get_optional usage (stable-fixes).
- mmc: mtk-sd: Fix MMC_CAP2_CRYPTO flag setting (git-fixes).
- mmc: sdhci-esdhc-imx: enable quirks SDHCI_QUIRK_NO_LED (stable-fixes).
- mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia Edu Atla 10 tablet (stable-fixes).
- mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk (git-fixes).
- mtd: diskonchip: Cast an operand to prevent potential overflow (git-fixes).
- mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE (git-fixes).
- mtd: hyperbus: rpc-if: Convert to platform remove callback returning void (stable-fixes).
- mtd: rawnand: arasan: Fix double assertion of chip-select (git-fixes).
- mtd: rawnand: arasan: Fix missing de-registration of NAND (git-fixes).
- mtd: rawnand: fix double free in atmel_pmecc_create_user() (git-fixes).
- net :mana :Request a V2 response version for MANA_QUERY_GF_STAT (git-fixes).
- net: mana: Increase the DEF_RX_BUFFERS_PER_QUEUE to 1024 (bsc#1235246).
- net: Return error from sk_stream_wait_connect() if sk_wait_event() fails (git-fixes).
- net: usb: qmi_wwan: add Quectel RG650V (stable-fixes).
- net/ipv6: release expired exception dst cached in socket (bsc#1216813).
- net/mlx5e: clear xdp features on non-uplink representors (git-fixes).
- net/mlx5e: CT: Fix null-ptr-deref in add rule err flow (git-fixes).
- net/mlx5e: Remove workaround to avoid syndrome for internal port (git-fixes).
- net/qed: allow old cards not supporting 'num_images' to work (git-fixes).
- nfs: ignore SB_RDONLY when mounting nfs (git-fixes).
- NFS/pnfs: Fix a live lock between recalled layouts and layoutget (git-fixes).
- NFSD: Async COPY result needs to return a write verifier (git-fixes).
- NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir() (git-fixes).
- nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur (git-fixes).
- NFSD: Fix nfsd4_shutdown_copy() (git-fixes).
- NFSD: initialize copy->cp_clp early in nfsd4_copy for use by trace point (git-fixes).
- nfsd: make sure exp active before svc_export_show (git-fixes).
- NFSD: Prevent a potential integer overflow (git-fixes).
- NFSD: Prevent NULL dereference in nfsd4_process_cb_update() (git-fixes).
- nfsd: release svc_expkey/svc_export with rcu_work (git-fixes).
- NFSD: Remove a never-true comparison (git-fixes).
- nfsd: restore callback functionality for NFSv4.0 (git-fixes).
- NFSv4.0: Fix a use-after-free problem in the asynchronous open() (git-fixes).
- nilfs2: fix buffer head leaks in calls to truncate_inode_pages() (git-fixes).
- nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry() (git-fixes).
- nilfs2: prevent use of deleted inode (git-fixes).
- nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).
- nvme-rdma: unquiesce admin_q before destroy it (git-fixes).
- nvme-tcp: fix the memleak while create new ctrl failed (git-fixes).
- nvme: apple: fix device reference counting (git-fixes).
- nvme: fix metadata handling in nvme-passthrough (git-fixes).
- nvme/multipath: Fix RCU list traversal to use SRCU primitive (git-fixes).
- nvmet-loop: avoid using mutex in IO hotpath (git-fixes).
- ocfs2: fix uninitialized value in ocfs2_file_read_iter() (git-fixes).
- ocfs2: free inode when ocfs2_get_init_inode() fails (git-fixes).
- Octeontx2-pf: Free send queue buffers incase of leaf to inner (git-fixes).
- of: address: Report error on resource bounds overflow (stable-fixes).
- of: Fix error path in of_parse_phandle_with_args_map() (git-fixes).
- of: Fix refcount leakage for OF node returned by __of_get_dma_parent() (git-fixes).
- of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one() (git-fixes).
- parisc: Raise minimal GCC version (bsc#1220773).
- parisc: Raise minimal GCC version to 12.0.0 (bsc#1220773 git-fix).
- PCI: Add 'reset_subordinate' to reset hierarchy below bridge (stable-fixes).
- PCI: Add ACS quirk for Broadcom BCM5760X NIC (stable-fixes).
- PCI: Add ACS quirk for Wangxun FF5xxx NICs (stable-fixes).
- PCI: Add T_PERST_CLK_US macro (git-fixes).
- PCI: cadence: Extract link setup sequence from cdns_pcie_host_setup() (stable-fixes).
- PCI: cadence: Set cdns_pcie_host_init() global (stable-fixes).
- PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads (stable-fixes).
- PCI: Detect and trust built-in Thunderbolt chips (stable-fixes).
- PCI: Fix use-after-free of slot->bus on hot remove (stable-fixes).
- PCI: j721e: Add PCIe 4x lane selection support (stable-fixes).
- PCI: j721e: Add per platform maximum lane settings (stable-fixes).
- PCI: j721e: Add reset GPIO to struct j721e_pcie (stable-fixes).
- PCI: j721e: Add suspend and resume support (git-fixes).
- PCI: j721e: Use T_PERST_CLK_US macro (git-fixes).
- PCI: qcom: Add support for IPQ9574 (stable-fixes).
- PCI: Use preserve_config in place of pci_flags (stable-fixes).
- PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs (stable-fixes).
- PCI: vmd: Set devices to D0 before enabling PM L1 Substates (stable-fixes).
- PCI/AER: Disable AER service on suspend (stable-fixes).
- PCI/MSI: Handle lack of irqdomain gracefully (git-fixes).
- percpu: Add {raw,this}_cpu_try_cmpxchg() (bsc#1220773).
- percpu: Fix self-assignment of __old in raw_cpu_generic_try_cmpxchg() (bsc#1220773 git-fix).
- percpu: Wire up cmpxchg128 (bsc#1220773).
- phy: core: Fix an OF node refcount leakage in _of_phy_get() (git-fixes).
- phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup() (git-fixes).
- phy: core: Fix that API devm_of_phy_provider_unregister() fails to unregister the phy provider (git-fixes).
- phy: core: Fix that API devm_phy_destroy() fails to destroy the phy (git-fixes).
- phy: core: Fix that API devm_phy_put() fails to release the phy (git-fixes).
- phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP (git-fixes).
- phy: rockchip: naneng-combphy: fix phy reset (git-fixes).
- phy: usb: Toggle the PHY power during init (git-fixes).
- pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking (git-fixes).
- pinctrl: qcom-pmic-gpio: add support for PM8937 (stable-fixes).
- pinctrl: qcom: spmi-mpp: Add PM8937 compatible (stable-fixes).
- pinmux: Use sequential access to access desc->pinmux data (stable-fixes).
- platform/chrome: cros_ec_proto: Lock device when updating MKBP version (git-fixes).
- platform/x86: asus-nb-wmi: Ignore unknown event 0xCF (stable-fixes).
- platform/x86: dell-smbios-base: Extends support to Alienware products (stable-fixes).
- platform/x86: dell-wmi-base: Handle META key Lock/Unlock events (stable-fixes).
- platform/x86: thinkpad_acpi: Fix for ThinkPad's with ECFW showing incorrect fan speed (stable-fixes).
- power: supply: gpio-charger: Fix set charge current limits (git-fixes).
- powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump is active (bsc#1235108).
- proc/softirqs: replace seq_printf with seq_put_decimal_ull_width (git-fixes).
- quota: explicitly forbid quota files from being encrypted (bsc#1234196).
- quota: Fix rcu annotations of inode dquot pointers (bsc#1234197).
- quota: flush quota_release_work upon quota writeback (bsc#1234195).
- quota: simplify drop_dquot_ref() (bsc#1234197).
- RAS/AMD/ATL: Translate normalized to system physical addresses using PRM (jsc#PED-10467).
- RDMA/bnxt_re: Add check for path mtu in modify_qp (git-fixes)
- RDMA/bnxt_re: Avoid initializing the software queue for user queues (git-fixes)
- RDMA/bnxt_re: Avoid sending the modify QP workaround for latest adapters (git-fixes)
- RDMA/bnxt_re: Disable use of reserved wqes (git-fixes)
- RDMA/bnxt_re: Fix max_qp_wrs reported (git-fixes)
- RDMA/bnxt_re: Fix reporting hw_ver in query_device (git-fixes)
- RDMA/bnxt_re: Fix the check for 9060 condition (git-fixes)
- RDMA/bnxt_re: Fix the locking while accessing the QP table (git-fixes)
- RDMA/bnxt_re: Remove always true dattr validity check (git-fixes)
- RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)
- RDMA/hns: Fix accessing invalid dip_ctx during destroying QP (git-fixes)
- RDMA/hns: Fix mapping error of zero-hop WQE buffer (git-fixes)
- RDMA/hns: Fix missing flush CQE for DWQE (git-fixes)
- RDMA/hns: Fix warning storm caused by invalid input in IO path (git-fixes)
- RDMA/mlx5: Enforce same type port association for multiport RoCE (git-fixes)
- RDMA/rtrs: Ensure 'ib_sge list' is accessible (git-fixes)
- RDMA/uverbs: Prevent integer overflow issue (git-fixes)
- readahead: use ilog2 instead of a while loop in page_cache_ra_order() (bsc#1234208).
- regmap: Use correct format specifier for logging range errors (stable-fixes).
- regulator: rk808: Add apply_bit for BUCK3 on RK809 (stable-fixes).
- rtc: cmos: avoid taking rtc_lock for extended period of time (stable-fixes).
- s390/cio: Do not unregister the subchannel based on DNV (git-fixes).
- s390/cpum_sf: Convert to cmpxchg128() (bsc#1220773).
- s390/cpum_sf: Handle CPU hotplug remove during sampling (git-fixes).
- s390/cpum_sf: Remove WARN_ON_ONCE statements (git-fixes).
- s390/facility: Disable compile time optimization for decompressor code (git-fixes).
- s390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct() (git-fixes).
- s390/pageattr: Implement missing kernel_page_present() (git-fixes).
- scatterlist: fix incorrect func name in kernel-doc (git-fixes).
- sched/numa: fix memory leak due to the overwritten vma->numab_state (git fixes (sched/numa)).
- scsi: lpfc: Add handling for LS_RJT reason explanation authentication required (bsc#1235409).
- scsi: lpfc: Add support for large fw object application layer reads (bsc#1235409).
- scsi: lpfc: Change lpfc_nodelist save_flags member into a bitmask (bsc#1235409).
- scsi: lpfc: Copyright updates for 14.4.0.7 patches (bsc#1235409).
- scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage (bsc#1235409).
- scsi: lpfc: Modify handling of ADISC based on ndlp state and RPI registration (bsc#1235409).
- scsi: lpfc: Redefine incorrect type in lpfc_create_device_data() (bsc#1235409).
- scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters only (bsc#1235409).
- scsi: lpfc: Update definition of firmware configuration mbox cmds (bsc#1235409).
- scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).
- scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).
- scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).
- scsi: qla2xxx: Fix use after free on unload (bsc#1235406).
- scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt (bsc#1235406).
- scsi: qla2xxx: Remove the unused 'del_list_entry' field in struct fc_port (bsc#1235406).
- scsi: qla2xxx: Supported speed displayed incorrectly for VPorts (bsc#1235406).
- scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).
- scsi: storvsc: Do not flag MAINTENANCE_IN return of SRB_STATUS_DATA_OVERRUN as an error (git-fixes).
- selftests/bpf: Test PROBE_MEM of VSYSCALL_ADDR on x86-64 (git-fixes).
- serial: 8250_dw: Add Sophgo SG2044 quirk (stable-fixes).
- serial: 8250_dw: Do not use struct dw8250_data outside of 8250_dw (git-fixes).
- serial: 8250_dw: Replace ACPI device check by a quirk (git-fixes).
- serial: 8250_fintek: Add support for F81216E (stable-fixes).
- serial: amba-pl011: fix build regression (git-fixes).
- serial: amba-pl011: Fix RX stall when DMA is used (git-fixes).
- serial: amba-pl011: Use port lock wrappers (stable-fixes).
- serial: Do not hold the port lock when setting rx-during-tx GPIO (git-fixes).
- serial: do not use uninitialized value in uart_poll_init() (git-fixes).
- serial: imx: only set receiver level if it is zero (git-fixes).
- serial: imx: set receiver level before starting uart (git-fixes).
- serial: qcom-geni: disable interrupts during console writes (git-fixes).
- serial: qcom-geni: Do not cancel/abort if we can't get the port lock (git-fixes).
- serial: qcom-geni: fix arg types for qcom_geni_serial_poll_bit() (git-fixes).
- serial: qcom-geni: fix console corruption (git-fixes).
- serial: qcom-geni: fix dma rx cancellation (git-fixes).
- serial: qcom-geni: fix false console tx restart (git-fixes).
- serial: qcom-geni: fix fifo polling timeout (git-fixes).
- serial: qcom-geni: fix hard lockup on buffer flush (git-fixes).
- serial: qcom-geni: fix polled console corruption (git-fixes).
- serial: qcom-geni: fix polled console initialisation (git-fixes).
- serial: qcom-geni: fix receiver enable (git-fixes).
- serial: qcom-geni: fix shutdown race (git-fixes).
- serial: qcom-geni: fix soft lockup on sw flow control and suspend (git-fixes).
- serial: qcom-geni: introduce qcom_geni_serial_poll_bitfield() (git-fixes).
- serial: qcom-geni: revert broken hibernation support (git-fixes).
- serial: stm32: do not always set SER_RS485_RX_DURING_TX if RS485 is enabled (git-fixes).
- serial: stm32: Return IRQ_NONE in the ISR if no handling happend (git-fixes).
- slub: Replace cmpxchg_double() - KABI fix (bsc#1220773).
- slub: Replace cmpxchg_double() (bsc#1220773).
- smb: client: fix TCP timers deadlock after rmmod (git-fixes) [hcarvalho: fix issue described in bsc#1233642]
- soc: fsl: cpm1: qmc: Fix blank line and spaces (stable-fixes).
- soc: fsl: cpm1: qmc: Introduce qmc_{init,exit}_xcc() and their CPM1 version (stable-fixes).
- soc: fsl: cpm1: qmc: Introduce qmc_init_resource() and its CPM1 version (stable-fixes).
- soc: fsl: cpm1: qmc: Re-order probe() operations (stable-fixes).
- soc: fsl: cpm1: qmc: Set the ret error code on platform_get_irq() failure (git-fixes).
- soc: imx8m: Probe the SoC driver as platform driver (stable-fixes).
- soc: qcom: Add check devm_kasprintf() returned value (stable-fixes).
- soc: qcom: geni-se: add GP_LENGTH/IRQ_EN_SET/IRQ_EN_CLEAR registers (git-fixes).
- soc: qcom: geni-se: Add M_TX_FIFO_NOT_EMPTY bit definition (git-fixes).
- soc: qcom: socinfo: fix revision check in qcom_socinfo_probe() (git-fixes).
- soc/fsl: cpm: qmc: Convert to platform remove callback returning void (stable-fixes).
- spi: aspeed: Fix an error handling path in aspeed_spi_[read|write]_user() (git-fixes).
- sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport (git-fixes).
- sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket (git-fixes).
- sunrpc: handle -ENOTCONN in xs_tcp_setup_socket() (git-fixes).
- SUNRPC: make sure cache entry active before cache_show (git-fixes).
- SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT (git-fixes).
- svcrdma: Address an integer overflow (git-fixes).
- svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init() (git-fixes).
- swiotlb: Enforce page alignment in swiotlb_alloc() (git-fixes).
- swiotlb: Reinstate page-alignment for mappings >= PAGE_SIZE (git-fixes).
- thermal/drivers/qcom/tsens-v1: Add support for MSM8937 tsens (stable-fixes).
- tools: hv: change permissions of NetworkManager configuration file (git-fixes).
- tpm_tis_spi: Release chip select when flow control fails (bsc#1234338)
- tpm/eventlog: Limit memory allocations for event logs with excessive size (bsc#1233260 bsc#1233259 bsc#1232421).
- tty: serial: kgdboc: Fix 8250_* kgdb over serial (git-fixes).
- types: Introduce [us]128 (bsc#1220773).
- ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit (git-fixes).
- ubifs: Correct the total block count by deducting journal reservation (git-fixes).
- udf: Fix lock ordering in udf_evict_inode() (bsc#1234238).
- udf: fix uninit-value use in udf_get_fileshortad (bsc#1234243).
- udf: prevent integer overflow in udf_bitmap_free_blocks() (bsc#1234239).
- udf: refactor inode_bmap() to handle error (bsc#1234242).
- udf: refactor udf_current_aext() to handle error (bsc#1234240).
- udf: refactor udf_next_aext() to handle error (bsc#1234241).
- udf: udftime: prevent overflow in udf_disk_stamp_to_time() (bsc#1234237).
- usb: add support for new USB device ID 0x17EF:0x3098 for the r8152 driver (stable-fixes).
- usb: cdns3-ti: Add workaround for Errata i2409 (stable-fixes).
- usb: cdns3: Add quirk flag to enable suspend residency (stable-fixes).
- usb: chipidea: udc: handle USB Error Interrupt if IOC not set (stable-fixes).
- usb: dwc2: Fix HCD port connection race (git-fixes).
- usb: dwc2: Fix HCD resume (git-fixes).
- usb: dwc2: gadget: Do not write invalid mapped sg entries into dma_desc with iommu enabled (stable-fixes).
- usb: dwc2: hcd: Fix GetPortStatus & SetPortFeature (git-fixes).
- usb: dwc3: ep0: Do not clear ep0 DWC3_EP_TRANSFER_STARTED (git-fixes).
- usb: dwc3: ep0: Do not reset resource alloc flag (git-fixes).
- usb: dwc3: ep0: Do not reset resource alloc flag (including ep0) (git-fixes).
- usb: dwc3: gadget: Rewrite endpoint allocation flow (stable-fixes).
- usb: dwc3: xilinx: make sure pipe clock is deselected in usb2 only mode (git-fixes).
- usb: ehci-hcd: fix call balance of clocks handling routines (git-fixes).
- usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer (git-fixes).
- usb: host: max3421-hcd: Correctly abort a USB request (git-fixes).
- USB: serial: option: add MediaTek T7XX compositions (stable-fixes).
- USB: serial: option: add MeiG Smart SLM770A (stable-fixes).
- USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready (stable-fixes).
- USB: serial: option: add TCL IK512 MBIM & ECM (stable-fixes).
- USB: serial: option: add Telit FE910C04 rmnet compositions (stable-fixes).
- usb: typec: anx7411: fix fwnode_handle reference leak (git-fixes).
- usb: typec: anx7411: fix OF node reference leaks in anx7411_typec_switch_probe() (git-fixes).
- usb: typec: use cleanup facility for 'altmodes_node' (stable-fixes).
- vdpa: solidrun: Fix UB bug with devres (git-fixes).
- vDPA/ifcvf: Fix pci_read_config_byte() return code handling (git-fixes).
- vdpa/mlx5: Fix PA offset with unaligned starting iotlb map (git-fixes).
- vdpa/mlx5: Fix suboptimal range on iotlb iteration (git-fixes).
- vfs: fix readahead(2) on block devices (bsc#1234201).
- wifi: ath5k: add PCI ID for Arcadyan devices (git-fixes).
- wifi: ath5k: add PCI ID for SX76X (git-fixes).
- wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() (stable-fixes).
- wifi: cfg80211: sme: init n_channels before channels[] access (git-fixes).
- wifi: cw1200: Fix potential NULL dereference (git-fixes).
- wifi: ipw2x00: libipw_rx_any(): fix bad alignment (stable-fixes).
- wifi: iwlwifi: mvm: Use the sync timepoint API in suspend (stable-fixes).
- wifi: mac80211: clean up 'ret' in sta_link_apply_parameters() (stable-fixes).
- wifi: mac80211: fix station NSS capability initialization order (git-fixes).
- wifi: mac80211: init cnt before accessing elem in ieee80211_copy_mbssid_beacon (git-fixes).
- wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one (git-fixes).
- wifi: rtlwifi: Drastically reduce the attempts to read efuse in case of failures (stable-fixes).
- wifi: rtw89: check return value of ieee80211_probereq_get() for RNR (stable-fixes).
- workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker (bsc#1235416).
- writeback, cgroup: switch inodes with dirty timestamps to release dying cgwbs (bsc#1234203).
- x86,amd_iommu: Replace cmpxchg_double() (bsc#1220773).
- x86,intel_iommu: Replace cmpxchg_double() (bsc#1220773).
- x86/hyperv: Fix hv tsc page based sched_clock for hibernation (git-fixes).
- xfs: do not allocate COW extents when unsharing a hole (git-fixes).
- xfs: fix sb_spino_align checks for large fsblock sizes (git-fixes).
- xfs: remove unknown compat feature check in superblock write validation (git-fixes).
- xfs: return from xfs_symlink_verify early on V4 filesystems (git-fixes).
- xfs: sb_spino_align is not verified (git-fixes).
- xhci: Add usb cold attach (CAS) as a reason to resume root hub (git-fixes).
- xhci: Allow RPM on the USB controller (1022:43f7) by default (stable-fixes).
- xhci: fix possible null pointer deref during xhci urb enqueue (git-fixes).
Patchnames
SUSE-2025-117,SUSE-SLE-Module-Public-Cloud-15-SP6-2025-117,openSUSE-SLE-15.6-2025-117
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for the Linux Kernel", "title": "Title of the patch" }, { "category": "description", "text": "\nThe SUSE Linux Enterprise 15 SP6 Azure kernel was updated to receive various security bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2024-26924: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (bsc#1225820).\n- CVE-2024-27397: netfilter: nf_tables: use timestamp to check for set element timeout (bsc#1224095).\n- CVE-2024-35839: kABI fix for netfilter: bridge: replace physindev with physinif in nf_bridge_info (bsc#1224726).\n- CVE-2024-36915: nfc: llcp: fix nfc_llcp_setsockopt() unsafe copies (bsc#1225758).\n- CVE-2024-41042: Prefer nft_chain_validate (bsc#1228526).\n- CVE-2024-44934: net: bridge: mcast: wait for previous gc cycles when removing port (bsc#1229809).\n- CVE-2024-44996: vsock: fix recursive -\u003erecvmsg calls (bsc#1230205).\n- CVE-2024-47678: icmp: change the order of rate limits (bsc#1231854).\n- CVE-2024-50018: net: napi: Prevent overflow of napi_defer_hard_irqs (bsc#1232419).\n- CVE-2024-50039: kABI: Restore deleted EXPORT_SYMBOL(__qdisc_calculate_pkt_len) (bsc#1231909).\n- CVE-2024-50202: nilfs2: propagate directory read errors from nilfs_find_entry() (bsc#1233324).\n- CVE-2024-50256: netfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6() (bsc#1233200).\n- CVE-2024-50262: bpf: Fix out-of-bounds write in trie_get_next_key() (bsc#1233239).\n- CVE-2024-50278, CVE-2024-50280: dm cache: fix flushing uninitialized delayed_work on cache_ctr error (bsc#1233467).\n- CVE-2024-50278: dm cache: fix potential out-of-bounds access on the first resume (bsc#1233467).\n- CVE-2024-53050: drm/i915/hdcp: Add encoder check in hdcp2_get_capability (bsc#1233546).\n- CVE-2024-53064: idpf: fix idpf_vc_core_init error path (bsc#1233558).\n- CVE-2024-53090: afs: Fix lock recursion (bsc#1233637).\n- CVE-2024-53099: bpf: Check validity of link-\u003etype in bpf_link_show_fdinfo() (bsc#1233772).\n- CVE-2024-53105: mm: page_alloc: move mlocked flag clearance into free_pages_prepare() (bsc#1234069).\n- CVE-2024-53111: mm/mremap: fix address wraparound in move_page_tables() (bsc#1234086).\n- CVE-2024-53113: mm: fix NULL pointer dereference in alloc_pages_bulk_noprof (bsc#1234077).\n- CVE-2024-53117: virtio/vsock: Improve MSG_ZEROCOPY error handling (bsc#1234079).\n- CVE-2024-53118: vsock: Fix sk_error_queue memory leak (bsc#1234071).\n- CVE-2024-53119: virtio/vsock: Fix accept_queue memory leak (bsc#1234073).\n- CVE-2024-53122: mptcp: cope racing subflow creation in mptcp_rcv_space_adjust (bsc#1234076).\n- CVE-2024-53125: bpf: sync_linked_regs() must preserve subreg_def (bsc#1234156).\n- CVE-2024-53130: nilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint (bsc#1234219).\n- CVE-2024-53131: nilfs2: fix null-ptr-deref in block_touch_buffer tracepoint (bsc#1234220).\n- CVE-2024-53133: drm/amd/display: Handle dml allocation failure to avoid crash (bsc#1234221)\n- CVE-2024-53134: pmdomain: imx93-blk-ctrl: correct remove path (bsc#1234159).\n- CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1234381).\n- CVE-2024-53160: rcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu (bsc#1234810).\n- CVE-2024-53161: EDAC/bluefield: Fix potential integer overflow (bsc#1234856).\n- CVE-2024-53179: smb: client: fix use-after-free of signing key (bsc#1234921).\n- CVE-2024-53214: vfio/pci: Properly hide first-in-list PCIe extended capability (bsc#1235004).\n- CVE-2024-53216: nfsd: fix UAF when access ex_uuid or ex_stats (bsc#1235003).\n- CVE-2024-53222: zram: fix NULL pointer in comp_algorithm_show() (bsc#1234974).\n- CVE-2024-53234: erofs: handle NONHEAD !delta[1] lclusters gracefully (bsc#1235045).\n- CVE-2024-53240: xen/netfront: fix crash when removing device (bsc#1234281).\n- CVE-2024-53241: x86/xen: use new hypercall functions instead of hypercall page (bsc#1234282).\n- CVE-2024-56549: cachefiles: Fix NULL pointer dereference in object-\u003efile (bsc#1234912).\n- CVE-2024-56566: mm/slub: Avoid list corruption when removing a slab from the full list (bsc#1235033).\n- CVE-2024-56582: btrfs: fix use-after-free in btrfs_encoded_read_endio() (bsc#1235128).\n- CVE-2024-56599: wifi: ath10k: avoid NULL pointer error during sdio remove (bsc#1235138).\n- CVE-2024-56604: Bluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc() (bsc#1235056).\n- CVE-2024-56755: netfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING (bsc#1234920).\n\nThe following non-security bugs were fixed:\n\n- 9p: v9fs_fid_find: also lookup by inode if not found dentry (git-fixes).\n- accel/habanalabs: export dma-buf only if size/offset multiples of PAGE_SIZE (stable-fixes).\n- accel/habanalabs: fix debugfs files permissions (stable-fixes).\n- accel/habanalabs: increase HL_MAX_STR to 64 bytes to avoid warnings (stable-fixes).\n- accel/habanalabs/gaudi2: unsecure tpc count registers (stable-fixes).\n- acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl (git-fixes).\n- ACPI: PRM: Add PRM handler direct call support (jsc#PED-10467).\n- ACPI: resource: Fix memory resource type union access (git-fixes).\n- ACPI: x86: Add skip i2c clients quirk for Acer Iconia One 8 A1-840 (stable-fixes).\n- ACPI: x86: Clean up Asus entries in acpi_quirk_skip_dmi_ids[] (stable-fixes).\n- ACPI: x86: Make UART skip quirks work on PCI UARTs without an UID (stable-fixes).\n- ACPI/HMAT: Move HMAT messages to pr_debug() (bsc#1234294)\n- ACPICA: events/evxfregn: do not release the ContextMutex that was never acquired (git-fixes).\n- af_unix: Call manage_oob() for every skb in unix_stream_read_generic() (bsc#1234725).\n- afs: Automatically generate trace tag enums (git-fixes).\n- afs: Fix missing subdir edit when renamed between parent dirs (git-fixes).\n- ALSA hda/realtek: Add quirk for Framework F111:000C (stable-fixes).\n- ALSA: hda: Add HP MP9 G4 Retail System AMS to force connect list (stable-fixes).\n- ALSA: hda/hdmi: Yet more pin fix for HP EliteDesk 800 G4 (stable-fixes).\n- ALSA: hda/realtek: Add Framework Laptop 13 (Intel Core Ultra) to quirks (stable-fixes).\n- ALSA: hda/realtek: Fix headset mic on Acer Nitro 5 (stable-fixes).\n- ALSA: line6: Fix racy access to midibuf (stable-fixes).\n- ALSA: seq: Check UMP support for midi_version change (git-fixes).\n- ALSA: seq: oss: Fix races at processing SysEx messages (stable-fixes).\n- ALSA: seq: ump: Fix seq port updates per FB info notify (git-fixes).\n- ALSA: seq: ump: Use automatic cleanup of kfree() (stable-fixes).\n- ALSA: seq: ump: Use guard() for locking (stable-fixes).\n- ALSA: usb-audio: Add implicit feedback quirk for Yamaha THR5 (stable-fixes).\n- ALSA: usb-audio: Notify xrun for low-latency mode (git-fixes).\n- ALSA: usb-audio: Re-add ScratchAmp quirk entries (git-fixes).\n- ALSA: usb-audio: US16x08: Initialize array before use (git-fixes).\n- amdgpu/uvd: get ring reference from rq scheduler (git-fixes).\n- arch: consolidate arch_irq_work_raise prototypes (git-fixes).\n- arch: Introduce arch_{,try_}_cmpxchg128{,_local}() (bsc#1220773).\n- arch: Remove cmpxchg_double (bsc#1220773).\n- arm64: dts: imx8mp: correct sdhc ipg clk (git-fixes).\n- arm64: Ensure bits ASID[15:8] are masked out when the kernel uses (bsc#1234605)\n- arm64: Force position-independent veneers (git-fixes).\n- ASoC: amd: yc: Add a quirk for microfone on Lenovo ThinkPad P14s Gen 5 21MES00B00 (stable-fixes).\n- ASoC: amd: yc: Add quirk for microphone on Lenovo Thinkpad T14s Gen 6 21M1CTO1WW (stable-fixes).\n- ASoC: amd: yc: fix internal mic on Redmi G 2022 (stable-fixes).\n- ASoC: amd: yc: Fix the wrong return value (git-fixes).\n- ASoC: amd: yc: Support mic on HP 14-em0002la (stable-fixes).\n- ASoC: amd: yc: Support mic on Lenovo Thinkpad E14 Gen 6 (stable-fixes).\n- ASoC: codecs: wcd938x-sdw: Correct Soundwire ports mask (git-fixes).\n- ASoC: codecs: wsa881x: Correct Soundwire ports mask (git-fixes).\n- ASoC: codecs: wsa883x: Correct Soundwire ports mask (git-fixes).\n- ASoC: codecs: wsa884x: Correct Soundwire ports mask (git-fixes).\n- ASoC: cs35l56: Handle OTP read latency over SoundWire (stable-fixes).\n- ASoC: cs35l56: Patch CS35L56_IRQ1_MASK_18 to the default value (stable-fixes).\n- ASoC: fsl_micfil: Expand the range of FIFO watermark mask (stable-fixes).\n- ASoC: hdmi-codec: reorder channel allocation list (stable-fixes).\n- ASoC: Intel: sof_sdw: add quirk for Dell SKU 0B8C (stable-fixes).\n- ASoC: Intel: sof_sdw: fix jack detection on ADL-N variant RVP (stable-fixes).\n- ASoC: meson: axg-fifo: fix irq scheduling issue with PREEMPT_RT (git-fixes).\n- ASoC: nau8822: Lower debug print priority (stable-fixes).\n- ASoC: SOF: Remove libraries from topology lookups (git-fixes).\n- autofs: fix memory leak of waitqueues in autofs_catatonic_mode (git-fixes).\n- batman-adv: Do not let TT changes list grows indefinitely (git-fixes).\n- batman-adv: Do not send uninitialized TT changes (git-fixes).\n- batman-adv: Remove uninitialized data in full table TT response (git-fixes).\n- blk-cgroup: Fix UAF in blkcg_unpin_online() (bsc#1234726).\n- blk-core: use pr_warn_ratelimited() in bio_check_ro() (bsc#1234139).\n- blk-iocost: do not WARN if iocg was already offlined (bsc#1234147).\n- blk-iocost: Fix an UBSAN shift-out-of-bounds warning (bsc#1234144).\n- blk-throttle: fix lockdep warning of \u0027cgroup_mutex or RCU read lock required!\u0027 (bsc#1234140).\n- block, bfq: choose the last bfqq from merge chain in bfq_setup_cooperator() (bsc#1234149).\n- block, bfq: do not break merge chain in bfq_split_bfqq() (bsc#1234150).\n- block, bfq: fix bfqq uaf in bfq_limit_depth() (bsc#1234160).\n- block, bfq: fix procress reference leakage for bfqq in merge chain (bsc#1234280).\n- block, bfq: fix uaf for accessing waker_bfqq after splitting (bsc#1234279).\n- block: Call .limit_depth() after .hctx has been set (bsc#1234148).\n- block: Fix where bio IO priority gets set (bsc#1234145).\n- block: prevent an integer overflow in bvec_try_merge_hw_page (bsc#1234142).\n- block: update the stable_writes flag in bdev_add (bsc#1234141).\n- block/mq-deadline: Fix the tag reservation code (bsc#1234148).\n- Bluetooth: btusb: Add RTL8852BE device 0489:e123 to device tables (stable-fixes).\n- Bluetooth: Fix type of len in rfcomm_sock_getsockopt{,_old}() (stable-fixes).\n- Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet (stable-fixes).\n- Bluetooth: hci_event: Fix using rcu_read_(un)lock while iterating (git-fixes).\n- Bluetooth: iso: Fix recursive locking warning (git-fixes).\n- Bluetooth: ISO: Reassociate a socket with an active BIS (stable-fixes).\n- Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (stable-fixes).\n- Bluetooth: MGMT: Fix possible deadlocks (git-fixes).\n- Bluetooth: SCO: Add support for 16 bits transparent voice setting (git-fixes).\n- bnxt_en: Fix receive ring space parameters when XDP is active (git-fixes).\n- bnxt_en: Reserve rings after PCIe AER recovery if NIC interface is down (git-fixes).\n- bnxt_en: Set backplane link modes correctly for ethtool (git-fixes).\n- bpf, x86: Fix PROBE_MEM runtime load check (git-fixes).\n- bpf: verifier: prevent userspace memory access (git-fixes).\n- btrfs: fix use-after-free waiting for encoded read endios (bsc#1235128)\n- can: gs_usb: add VID/PID for Xylanta SAINT3 product family (stable-fixes).\n- can: j1939: fix error in J1939 documentation (stable-fixes).\n- checkpatch: always parse orig_commit in fixes tag (git-fixes).\n- checkpatch: check for missing Fixes tags (stable-fixes).\n- clocksource/drivers:sp804: Make user selectable (git-fixes).\n- clocksource/drivers/timer-ti-dm: Fix child node refcount handling (git-fixes).\n- counter: stm32-timer-cnt: Add check for clk_enable() (git-fixes).\n- counter: ti-ecap-capture: Add check for clk_enable() (git-fixes).\n- crypto: qat - disable IOV in adf_dev_stop() (git-fixes).\n- crypto: x86/sha256 - Add parentheses around macros\u0027 single arguments (stable-fixes).\n- cyrpto/b128ops: Remove struct u128 (bsc#1220773).\n- devlink: Fix length of eswitch inline-mode (git-fixes).\n- dma-buf: fix dma_fence_array_signaled v4 (stable-fixes).\n- dma-debug: fix a possible deadlock on radix_lock (stable-fixes).\n- dmaengine: apple-admac: Avoid accessing registers in probe (git-fixes).\n- dmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset (git-fixes).\n- dmaengine: dw: Select only supported masters for ACPI devices (git-fixes).\n- dmaengine: idxd: Check for driver name match before sva user feature (bsc#1234357).\n- dmaengine: mv_xor: fix child node refcount handling in early exit (git-fixes).\n- dmaengine: tegra: Return correct DMA status when paused (git-fixes).\n- Documentation: PM: Clarify pm_runtime_resume_and_get() return value (git-fixes).\n- driver core: Add FWLINK_FLAG_IGNORE to completely ignore a fwnode link (stable-fixes).\n- driver core: fw_devlink: Improve logs for cycle detection (stable-fixes).\n- driver core: fw_devlink: Stop trying to optimize cycle detection logic (git-fixes).\n- Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet (git-fixes).\n- drivers: net: ionic: add missed debugfs cleanup to ionic_probe() error path (git-fixes).\n- drm: adv7511: Drop dsi single lane support (git-fixes).\n- drm: adv7511: Fix use-after-free in adv7533_attach_dsi() (git-fixes).\n- drm: panel-orientation-quirks: Add quirk for AYA NEO 2 model (stable-fixes).\n- drm: panel-orientation-quirks: Add quirk for AYA NEO Founder edition (stable-fixes).\n- drm: panel-orientation-quirks: Add quirk for AYA NEO GEEK (stable-fixes).\n- drm: panel-orientation-quirks: Make Lenovo Yoga Tab 3 X90F DMI match less strict (stable-fixes).\n- drm/amd/display: Add HDR workaround for specific eDP (stable-fixes).\n- drm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw (stable-fixes).\n- drm/amd/display: Allow backlight to go below `AMDGPU_DM_DEFAULT_MIN_BACKLIGHT` (stable-fixes).\n- drm/amd/display: Avoid overflow assignment in link_dp_cts (stable-fixes).\n- drm/amd/display: Fix Synaptics Cascaded Panamera DSC Determination (stable-fixes).\n- drm/amd/display: Revert Avoid overflow assignment (stable-fixes).\n- drm/amd/display: Use gpuvm_min_page_size_kbytes for DML2 surfaces (stable-fixes).\n- drm/amd/pm: fix the high voltage issue after unload (stable-fixes).\n- drm/amd/pm: update current_socclk and current_uclk in gpu_metrics on smu v13.0.7 (stable-fixes).\n- drm/amdgpu: add raven1 gfxoff quirk (stable-fixes).\n- drm/amdgpu: add smu 14.0.1 discovery support (stable-fixes).\n- drm/amdgpu: Block MMR_READ IOCTL in reset (stable-fixes).\n- drm/amdgpu: clear RB_OVERFLOW bit when enabling interrupts for vega20_ih (stable-fixes).\n- drm/amdgpu: Dereference the ATCS ACPI buffer (stable-fixes).\n- drm/amdgpu: differentiate external rev id for gfx 11.5.0 (stable-fixes).\n- drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit (stable-fixes).\n- drm/amdgpu: do not access invalid sched (git-fixes).\n- drm/amdgpu: enable gfxoff quirk on HP 705G4 (stable-fixes).\n- drm/amdgpu: fix unchecked return value warning for amdgpu_gfx (stable-fixes).\n- drm/amdgpu: fix usage slab after free (stable-fixes).\n- drm/amdgpu: prevent BO_HANDLES error from being overwritten (git-fixes).\n- drm/amdgpu: refine error handling in amdgpu_ttm_tt_pin_userptr (stable-fixes).\n- drm/amdgpu: set the right AMDGPU sg segment limitation (stable-fixes).\n- drm/amdgpu: skip amdgpu_device_cache_pci_state under sriov (stable-fixes).\n- drm/amdgpu/gfx10: use rlc safe mode for soft recovery (stable-fixes).\n- drm/amdgpu/gfx11: use rlc safe mode for soft recovery (stable-fixes).\n- drm/amdgpu/gfx9: properly handle error ints on all pipes (stable-fixes).\n- drm/amdgpu/gfx9: use rlc safe mode for soft recovery (stable-fixes).\n- drm/amdgpu/hdp5.2: do a posting read when flushing HDP (stable-fixes).\n- drm/amdgpu/pm: Remove gpu_od if it\u0027s an empty directory (stable-fixes).\n- drm/amdgpu/umsch: do not execute umsch test when GPU is in reset/suspend (stable-fixes).\n- drm/amdgpu/umsch: reinitialize write pointer in hw init (stable-fixes).\n- drm/amdgpu/vcn: reset fw_shared when VCPU buffers corrupted on vcn v4.0.3 (stable-fixes).\n- drm/amdkfd: Fix resource leak in criu restore queue (stable-fixes).\n- drm/amdkfd: pause autosuspend when creating pdd (stable-fixes).\n- drm/amdkfd: Use device based logging for errors (stable-fixes).\n- drm/amdkfd: Use the correct wptr size (stable-fixes).\n- drm/bridge: adv7511_audio: Update Audio InfoFrame properly (git-fixes).\n- drm/bridge: it6505: Enable module autoloading (stable-fixes).\n- drm/bridge: it6505: Fix inverted reset polarity (git-fixes).\n- drm/bridge: it6505: update usleep_range for RC circuit charge time (stable-fixes).\n- drm/display: Fix building with GCC 15 (stable-fixes).\n- drm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req() (stable-fixes).\n- drm/dp_mst: Fix MST sideband message body length check (stable-fixes).\n- drm/dp_mst: Fix resetting msg rx state after topology removal (git-fixes).\n- drm/dp_mst: Verify request type in the corresponding down message reply (stable-fixes).\n- drm/etnaviv: flush shader L1 cache after user commandstream (stable-fixes).\n- drm/i915: Fix memory leak by correcting cache object name in error handler (git-fixes).\n- drm/i915: Fix NULL pointer dereference in capture_engine (git-fixes).\n- drm/i915/dg1: Fix power gate sequence (git-fixes).\n- drm/mcde: Enable module autoloading (stable-fixes).\n- drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() (stable-fixes).\n- drm/nouveau/gsp: Use the sg allocator for level 2 of radix3 (stable-fixes).\n- drm/panel: novatek-nt35950: fix return value check in nt35950_probe() (git-fixes).\n- drm/panel: simple: Add Microchip AC69T88A LVDS Display panel (stable-fixes).\n- drm/printer: Allow NULL data in devcoredump printer (stable-fixes).\n- drm/radeon: add helper rdev_to_drm(rdev) (stable-fixes).\n- drm/radeon: change rdev-\u003eddev to rdev_to_drm(rdev) (stable-fixes).\n- drm/radeon: Fix spurious unplug event on radeon HDMI (git-fixes).\n- drm/radeon/r100: Handle unknown family in r100_cp_init_microcode() (stable-fixes).\n- drm/radeon/r600_cs: Fix possible int overflow in r600_packet3_check() (stable-fixes).\n- drm/sched: memset() \u0027job\u0027 in drm_sched_job_init() (stable-fixes).\n- drm/vc4: hdmi: Avoid log spam for audio start failure (stable-fixes).\n- drm/vc4: hvs: Set AXI panic modes for the HVS (stable-fixes).\n- erofs: avoid debugging output for (de)compressed data (git-fixes).\n- exfat: fix uninit-value in __exfat_get_dentry_set (git-fixes).\n- ext4: add a new helper to check if es must be kept (bsc#1234170).\n- ext4: add correct group descriptors and reserved GDT blocks to system zone (bsc#1234164).\n- ext4: add missed brelse in update_backups (bsc#1234171).\n- ext4: allow for the last group to be marked as trimmed (bsc#1234278).\n- ext4: avoid buffer_head leak in ext4_mark_inode_used() (bsc#1234191).\n- ext4: avoid excessive credit estimate in ext4_tmpfile() (bsc#1234180).\n- ext4: avoid negative min_clusters in find_group_orlov() (bsc#1234193).\n- ext4: avoid overlapping preallocations due to overflow (bsc#1234162).\n- ext4: avoid potential buffer_head leak in __ext4_new_inode() (bsc#1234192).\n- ext4: avoid writing unitialized memory to disk in EA inodes (bsc#1234187).\n- ext4: check the extent status again before inserting delalloc block (bsc#1234186).\n- ext4: clear EXT4_GROUP_INFO_WAS_TRIMMED_BIT even mount with discard (bsc#1234190).\n- ext4: convert to exclusive lock while inserting delalloc extents (bsc#1234178).\n- ext4: correct best extent lstart adjustment logic (bsc#1234179).\n- ext4: correct grp validation in ext4_mb_good_group (bsc#1234163).\n- ext4: correct return value of ext4_convert_meta_bg (bsc#1234172).\n- ext4: correct the hole length returned by ext4_map_blocks() (bsc#1234178).\n- ext4: correct the start block of counting reserved clusters (bsc#1234169).\n- ext4: do not let fstrim block system suspend (https://bugzilla.kernel.org/show_bug.cgi?id=216322 bsc#1234166).\n- ext4: do not trim the group with corrupted block bitmap (bsc#1234177).\n- ext4: factor out __es_alloc_extent() and __es_free_extent() (bsc#1234170).\n- ext4: factor out a common helper to query extent map (bsc#1234186).\n- ext4: fix inconsistent between segment fstrim and full fstrim (bsc#1234176).\n- ext4: fix incorrect tid assumption in __jbd2_log_wait_for_space() (bsc#1234188).\n- ext4: fix incorrect tid assumption in ext4_wait_for_tail_page_commit() (bsc#1234188).\n- ext4: fix incorrect tid assumption in jbd2_journal_shrink_checkpoint_list() (bsc#1234188).\n- ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} (bsc#1214954).\n- ext4: fix potential unnitialized variable (bsc#1234183).\n- ext4: fix race between writepages and remount (bsc#1234168).\n- ext4: fix rec_len verify error (bsc#1234167).\n- ext4: fix slab-use-after-free in ext4_es_insert_extent() (bsc#1234170).\n- ext4: fix uninitialized variable in ext4_inlinedir_to_tree (bsc#1234185).\n- ext4: forbid commit inconsistent quota data when errors=remount-ro (bsc#1234178).\n- ext4: make ext4_es_insert_delayed_block() return void (bsc#1234170).\n- ext4: make ext4_es_insert_extent() return void (bsc#1234170).\n- ext4: make ext4_es_remove_extent() return void (bsc#1234170).\n- ext4: make ext4_zeroout_es() return void (bsc#1234170).\n- ext4: make sure allocate pending entry not fail (bsc#1234170).\n- ext4: mark buffer new if it is unwritten to avoid stale data exposure (bsc#1234175).\n- ext4: move \u0027ix\u0027 sanity check to corrent position (bsc#1234174).\n- ext4: move setting of trimmed bit into ext4_try_to_trim_range() (bsc#1234165).\n- ext4: nested locking for xattr inode (bsc#1234189).\n- ext4: propagate errors from ext4_find_extent() in ext4_insert_range() (bsc#1234194).\n- ext4: refactor ext4_da_map_blocks() (bsc#1234178).\n- ext4: remove gdb backup copy for meta bg in setup_new_flex_group_blocks (bsc#1234173).\n- ext4: remove the redundant folio_wait_stable() (bsc#1234184).\n- ext4: set the type of max_zeroout to unsigned int to avoid overflow (bsc#1234182).\n- ext4: set type of ac_groups_linear_remaining to __u32 to avoid overflow (bsc#1234181).\n- ext4: use pre-allocated es in __es_insert_extent() (bsc#1234170).\n- ext4: use pre-allocated es in __es_remove_extent() (bsc#1234170).\n- ext4: using nofail preallocation in ext4_es_insert_delayed_block() (bsc#1234170).\n- ext4: using nofail preallocation in ext4_es_insert_extent() (bsc#1234170).\n- ext4: using nofail preallocation in ext4_es_remove_extent() (bsc#1234170).\n- filemap: add a per-mapping stable writes flag (bsc#1234141).\n- filemap: Fix bounds checking in filemap_read() (bsc#1234209).\n- firmware: arm_scmi: Reject clear channel request on A2P (stable-fixes).\n- fs-writeback: do not requeue a clean inode having skipped pages (bsc#1234200).\n- fs/writeback: bail out if there is no more inodes for IO and queued once (bsc#1234207).\n- fsnotify: fix sending inotify event with unexpected filename (bsc#1234198).\n- genirq/cpuhotplug: Retry with cpu_online_mask when migration fails (git-fixes).\n- genirq/cpuhotplug: Skip suspended interrupts when restoring affinity (git-fixes).\n- genirq/irqdesc: Honor caller provided affinity in alloc_desc() (git-fixes).\n- gpio: grgpio: Add NULL check in grgpio_probe (git-fixes).\n- gpio: grgpio: use a helper variable to store the address of ofdev-\u003edev (stable-fixes).\n- hfsplus: do not query the device logical block size multiple times (git-fixes).\n- HID: magicmouse: Apple Magic Trackpad 2 USB-C driver support (stable-fixes).\n- hvc/xen: fix console unplug (git-fixes).\n- hvc/xen: fix error path in xen_hvc_init() to always register frontend driver (git-fixes).\n- hvc/xen: fix event channel handling for secondary consoles (git-fixes).\n- hwmon: (nct6775) Add 665-ACE/600M-CL to ASUS WMI monitoring list (stable-fixes).\n- hwmon: (pmbus_core) Allow to hook PMBUS_SMBALERT_MASK (stable-fixes).\n- hwmon: (pmbus/core) clear faults after setting smbalert mask (git-fixes).\n- hwmon: (tmp513) Do not use \u0027proxy\u0027 headers (stable-fixes).\n- hwmon: (tmp513) Fix Current Register value interpretation (git-fixes).\n- hwmon: (tmp513) Fix interpretation of values of Shunt Voltage and Limit Registers (git-fixes).\n- hwmon: (tmp513) Fix interpretation of values of Temperature Result and Limit Registers (git-fixes).\n- hwmon: (tmp513) Simplify with dev_err_probe() (stable-fixes).\n- hwmon: (tmp513) Use SI constants from units.h (stable-fixes).\n- i2c: imx: add imx7d compatible string for applying erratum ERR007805 (git-fixes).\n- i2c: microchip-core: actually use repeated sends (git-fixes).\n- i2c: microchip-core: fix \u0027ghost\u0027 detections (git-fixes).\n- i2c: pnx: Fix timeout in wait functions (git-fixes).\n- i2c: riic: Always round-up when calculating bus period (git-fixes).\n- i40e: Fix handling changed priv flags (git-fixes).\n- i915/guc: Accumulate active runtime on gt reset (git-fixes).\n- i915/guc: Ensure busyness counter increases motonically (git-fixes).\n- i915/guc: Reset engine utilization buffer before registration (git-fixes).\n- ice: change q_index variable type to s16 to store -1 value (git-fixes).\n- ice: consistently use q_idx in ice_vc_cfg_qs_msg() (git-fixes).\n- ice: fix PHY Clock Recovery availability check (git-fixes).\n- ice: Unbind the workqueue (bsc#1234989)\n- idpf: add support for SW triggered interrupts (bsc#1235507).\n- idpf: enable WB_ON_ITR (bsc#1235507).\n- idpf: trigger SW interrupt when exiting wb_on_itr mode (bsc#1235507).\n- igb: Fix potential invalid memory access in igb_init_module() (git-fixes).\n- iio: magnetometer: yas530: use signed integer type for clamp limits (git-fixes).\n- instrumentation: Wire up cmpxchg128() (bsc#1220773).\n- io_uring: always lock __io_cqring_overflow_flush (git-fixes).\n- io_uring: check if iowq is killed before queuing (git-fixes).\n- io_uring: Fix registered ring file refcount leak (git-fixes).\n- io_uring/rw: avoid punting to io-wq directly (git-fixes).\n- io_uring/tctx: work around xa_store() allocation error issue (git-fixes).\n- iommu/io-pgtable-arm: Fix stage-2 map/unmap for concatenated tables (git-fixes).\n- irqflags: Explicitly ignore lockdep_hrtimer_exit() argument (git-fixes).\n- isofs: handle CDs with bad root inode but good Joliet root directory (bsc#1234199).\n- ixgbe: downgrade logging of unsupported VF API version to debug (git-fixes).\n- ixgbevf: stop attempting IPSEC offload on Mailbox API 1.5 (git-fixes).\n- jffs2: Fix rtime decompressor (git-fixes).\n- jffs2: fix use of uninitialized variable (git-fixes).\n- jffs2: Prevent rtime decompress memory corruption (git-fixes).\n- jfs: add a check to prevent array-index-out-of-bounds in dbAdjTree (git-fixes).\n- jfs: array-index-out-of-bounds fix in dtReadFirst (git-fixes).\n- jfs: fix array-index-out-of-bounds in jfs_readdir (git-fixes).\n- jfs: fix shift-out-of-bounds in dbSplit (git-fixes).\n- jfs: xattr: check invalid xattr size more strictly (git-fixes).\n- kasan: make report_lock a raw spinlock (git-fixes).\n- kdb: address -Wformat-security warnings (bsc#1234659).\n- kdb: Fix buffer overflow during tab-complete (bsc#1234652).\n- kdb: Fix console handling when editing and tab-completing commands (bsc#1234655).\n- kdb: Merge identical case statements in kdb_read() (bsc#1234657).\n- kdb: Use format-specifiers rather than memset() for padding in kdb_read() (bsc#1234658).\n- kdb: Use format-strings rather than \u0027\\0\u0027 injection in kdb_read() (bsc#1234654).\n- kdb: Use the passed prompt in kdb_position_cursor() (bsc#1234654).\n- kgdb: Flush console before entering kgdb on panic (bsc#1234651).\n- leds: class: Protect brightness_show() with led_cdev-\u003eled_access mutex (stable-fixes).\n- linux/dmaengine.h: fix a few kernel-doc warnings (git-fixes).\n- locking/atomic/x86: Correct the definition of __arch_try_cmpxchg128() (bsc#1220773 git-fix).\n- loop: fix the the direct I/O support check when used on top of block devices (bsc#1234143).\n- mac80211: fix user-power when emulating chanctx (stable-fixes).\n- media: cx231xx: Add support for Dexatek USB Video Grabber 1d19:6108 (stable-fixes).\n- media: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg (git-fixes).\n- media: uvcvideo: Add a quirk for the Kaiweets KTI-W02 infrared camera (stable-fixes).\n- media: uvcvideo: RealSense D421 Depth module metadata (stable-fixes).\n- mfd: da9052-spi: Change read-mask to write-mask (git-fixes).\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices (git-fixes).\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device (git-fixes).\n- mfd: intel_soc_pmic_bxtwc: Use IRQ domain for USB Type-C device (git-fixes).\n- mm/filemap: avoid buffered read/write race to read inconsistent data (bsc#1234204).\n- mm/readahead: do not allow order-1 folio (bsc#1234205).\n- mm/readahead: limit page cache size in page_cache_ra_order() (bsc#1234208).\n- mmc: core: Add SD card quirk for broken poweroff notification (stable-fixes).\n- mmc: mtk-sd: fix devm_clk_get_optional usage (stable-fixes).\n- mmc: mtk-sd: Fix MMC_CAP2_CRYPTO flag setting (git-fixes).\n- mmc: sdhci-esdhc-imx: enable quirks SDHCI_QUIRK_NO_LED (stable-fixes).\n- mmc: sdhci-pci: Add DMI quirk for missing CD GPIO on Vexia Edu Atla 10 tablet (stable-fixes).\n- mmc: sdhci-tegra: Remove SDHCI_QUIRK_BROKEN_ADMA_ZEROLEN_DESC quirk (git-fixes).\n- mtd: diskonchip: Cast an operand to prevent potential overflow (git-fixes).\n- mtd: hyperbus: rpc-if: Add missing MODULE_DEVICE_TABLE (git-fixes).\n- mtd: hyperbus: rpc-if: Convert to platform remove callback returning void (stable-fixes).\n- mtd: rawnand: arasan: Fix double assertion of chip-select (git-fixes).\n- mtd: rawnand: arasan: Fix missing de-registration of NAND (git-fixes).\n- mtd: rawnand: fix double free in atmel_pmecc_create_user() (git-fixes).\n- net :mana :Request a V2 response version for MANA_QUERY_GF_STAT (git-fixes).\n- net: mana: Increase the DEF_RX_BUFFERS_PER_QUEUE to 1024 (bsc#1235246).\n- net: Return error from sk_stream_wait_connect() if sk_wait_event() fails (git-fixes).\n- net: usb: qmi_wwan: add Quectel RG650V (stable-fixes).\n- net/ipv6: release expired exception dst cached in socket (bsc#1216813).\n- net/mlx5e: clear xdp features on non-uplink representors (git-fixes).\n- net/mlx5e: CT: Fix null-ptr-deref in add rule err flow (git-fixes).\n- net/mlx5e: Remove workaround to avoid syndrome for internal port (git-fixes).\n- net/qed: allow old cards not supporting \u0027num_images\u0027 to work (git-fixes).\n- nfs: ignore SB_RDONLY when mounting nfs (git-fixes).\n- NFS/pnfs: Fix a live lock between recalled layouts and layoutget (git-fixes).\n- NFSD: Async COPY result needs to return a write verifier (git-fixes).\n- NFSD: Cap the number of bytes copied by nfs4_reset_recoverydir() (git-fixes).\n- nfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur (git-fixes).\n- NFSD: Fix nfsd4_shutdown_copy() (git-fixes).\n- NFSD: initialize copy-\u003ecp_clp early in nfsd4_copy for use by trace point (git-fixes).\n- nfsd: make sure exp active before svc_export_show (git-fixes).\n- NFSD: Prevent a potential integer overflow (git-fixes).\n- NFSD: Prevent NULL dereference in nfsd4_process_cb_update() (git-fixes).\n- nfsd: release svc_expkey/svc_export with rcu_work (git-fixes).\n- NFSD: Remove a never-true comparison (git-fixes).\n- nfsd: restore callback functionality for NFSv4.0 (git-fixes).\n- NFSv4.0: Fix a use-after-free problem in the asynchronous open() (git-fixes).\n- nilfs2: fix buffer head leaks in calls to truncate_inode_pages() (git-fixes).\n- nilfs2: fix potential out-of-bounds memory access in nilfs_find_entry() (git-fixes).\n- nilfs2: prevent use of deleted inode (git-fixes).\n- nvme-pci: 512 byte aligned dma pool segment quirk (git-fixes).\n- nvme-rdma: unquiesce admin_q before destroy it (git-fixes).\n- nvme-tcp: fix the memleak while create new ctrl failed (git-fixes).\n- nvme: apple: fix device reference counting (git-fixes).\n- nvme: fix metadata handling in nvme-passthrough (git-fixes).\n- nvme/multipath: Fix RCU list traversal to use SRCU primitive (git-fixes).\n- nvmet-loop: avoid using mutex in IO hotpath (git-fixes).\n- ocfs2: fix uninitialized value in ocfs2_file_read_iter() (git-fixes).\n- ocfs2: free inode when ocfs2_get_init_inode() fails (git-fixes).\n- Octeontx2-pf: Free send queue buffers incase of leaf to inner (git-fixes).\n- of: address: Report error on resource bounds overflow (stable-fixes).\n- of: Fix error path in of_parse_phandle_with_args_map() (git-fixes).\n- of: Fix refcount leakage for OF node returned by __of_get_dma_parent() (git-fixes).\n- of/irq: Fix using uninitialized variable @addr_len in API of_irq_parse_one() (git-fixes).\n- parisc: Raise minimal GCC version (bsc#1220773).\n- parisc: Raise minimal GCC version to 12.0.0 (bsc#1220773 git-fix).\n- PCI: Add \u0027reset_subordinate\u0027 to reset hierarchy below bridge (stable-fixes).\n- PCI: Add ACS quirk for Broadcom BCM5760X NIC (stable-fixes).\n- PCI: Add ACS quirk for Wangxun FF5xxx NICs (stable-fixes).\n- PCI: Add T_PERST_CLK_US macro (git-fixes).\n- PCI: cadence: Extract link setup sequence from cdns_pcie_host_setup() (stable-fixes).\n- PCI: cadence: Set cdns_pcie_host_init() global (stable-fixes).\n- PCI: cpqphp: Use PCI_POSSIBLE_ERROR() to check config reads (stable-fixes).\n- PCI: Detect and trust built-in Thunderbolt chips (stable-fixes).\n- PCI: Fix use-after-free of slot-\u003ebus on hot remove (stable-fixes).\n- PCI: j721e: Add PCIe 4x lane selection support (stable-fixes).\n- PCI: j721e: Add per platform maximum lane settings (stable-fixes).\n- PCI: j721e: Add reset GPIO to struct j721e_pcie (stable-fixes).\n- PCI: j721e: Add suspend and resume support (git-fixes).\n- PCI: j721e: Use T_PERST_CLK_US macro (git-fixes).\n- PCI: qcom: Add support for IPQ9574 (stable-fixes).\n- PCI: Use preserve_config in place of pci_flags (stable-fixes).\n- PCI: vmd: Add DID 8086:B06F and 8086:B60B for Intel client SKUs (stable-fixes).\n- PCI: vmd: Set devices to D0 before enabling PM L1 Substates (stable-fixes).\n- PCI/AER: Disable AER service on suspend (stable-fixes).\n- PCI/MSI: Handle lack of irqdomain gracefully (git-fixes).\n- percpu: Add {raw,this}_cpu_try_cmpxchg() (bsc#1220773).\n- percpu: Fix self-assignment of __old in raw_cpu_generic_try_cmpxchg() (bsc#1220773 git-fix).\n- percpu: Wire up cmpxchg128 (bsc#1220773).\n- phy: core: Fix an OF node refcount leakage in _of_phy_get() (git-fixes).\n- phy: core: Fix an OF node refcount leakage in of_phy_provider_lookup() (git-fixes).\n- phy: core: Fix that API devm_of_phy_provider_unregister() fails to unregister the phy provider (git-fixes).\n- phy: core: Fix that API devm_phy_destroy() fails to destroy the phy (git-fixes).\n- phy: core: Fix that API devm_phy_put() fails to release the phy (git-fixes).\n- phy: qcom-qmp: Fix register name in RX Lane config of SC8280XP (git-fixes).\n- phy: rockchip: naneng-combphy: fix phy reset (git-fixes).\n- phy: usb: Toggle the PHY power during init (git-fixes).\n- pinctrl: mcp23s08: Fix sleeping in atomic context due to regmap locking (git-fixes).\n- pinctrl: qcom-pmic-gpio: add support for PM8937 (stable-fixes).\n- pinctrl: qcom: spmi-mpp: Add PM8937 compatible (stable-fixes).\n- pinmux: Use sequential access to access desc-\u003epinmux data (stable-fixes).\n- platform/chrome: cros_ec_proto: Lock device when updating MKBP version (git-fixes).\n- platform/x86: asus-nb-wmi: Ignore unknown event 0xCF (stable-fixes).\n- platform/x86: dell-smbios-base: Extends support to Alienware products (stable-fixes).\n- platform/x86: dell-wmi-base: Handle META key Lock/Unlock events (stable-fixes).\n- platform/x86: thinkpad_acpi: Fix for ThinkPad\u0027s with ECFW showing incorrect fan speed (stable-fixes).\n- power: supply: gpio-charger: Fix set charge current limits (git-fixes).\n- powerpc/book3s64/hugetlb: Fix disabling hugetlb when fadump is active (bsc#1235108).\n- proc/softirqs: replace seq_printf with seq_put_decimal_ull_width (git-fixes).\n- quota: explicitly forbid quota files from being encrypted (bsc#1234196).\n- quota: Fix rcu annotations of inode dquot pointers (bsc#1234197).\n- quota: flush quota_release_work upon quota writeback (bsc#1234195).\n- quota: simplify drop_dquot_ref() (bsc#1234197).\n- RAS/AMD/ATL: Translate normalized to system physical addresses using PRM (jsc#PED-10467).\n- RDMA/bnxt_re: Add check for path mtu in modify_qp (git-fixes)\n- RDMA/bnxt_re: Avoid initializing the software queue for user queues (git-fixes)\n- RDMA/bnxt_re: Avoid sending the modify QP workaround for latest adapters (git-fixes)\n- RDMA/bnxt_re: Disable use of reserved wqes (git-fixes)\n- RDMA/bnxt_re: Fix max_qp_wrs reported (git-fixes)\n- RDMA/bnxt_re: Fix reporting hw_ver in query_device (git-fixes)\n- RDMA/bnxt_re: Fix the check for 9060 condition (git-fixes)\n- RDMA/bnxt_re: Fix the locking while accessing the QP table (git-fixes)\n- RDMA/bnxt_re: Remove always true dattr validity check (git-fixes)\n- RDMA/core: Fix ENODEV error for iWARP test over vlan (git-fixes)\n- RDMA/hns: Fix accessing invalid dip_ctx during destroying QP (git-fixes)\n- RDMA/hns: Fix mapping error of zero-hop WQE buffer (git-fixes)\n- RDMA/hns: Fix missing flush CQE for DWQE (git-fixes)\n- RDMA/hns: Fix warning storm caused by invalid input in IO path (git-fixes)\n- RDMA/mlx5: Enforce same type port association for multiport RoCE (git-fixes)\n- RDMA/rtrs: Ensure \u0027ib_sge list\u0027 is accessible (git-fixes)\n- RDMA/uverbs: Prevent integer overflow issue (git-fixes)\n- readahead: use ilog2 instead of a while loop in page_cache_ra_order() (bsc#1234208).\n- regmap: Use correct format specifier for logging range errors (stable-fixes).\n- regulator: rk808: Add apply_bit for BUCK3 on RK809 (stable-fixes).\n- rtc: cmos: avoid taking rtc_lock for extended period of time (stable-fixes).\n- s390/cio: Do not unregister the subchannel based on DNV (git-fixes).\n- s390/cpum_sf: Convert to cmpxchg128() (bsc#1220773).\n- s390/cpum_sf: Handle CPU hotplug remove during sampling (git-fixes).\n- s390/cpum_sf: Remove WARN_ON_ONCE statements (git-fixes).\n- s390/facility: Disable compile time optimization for decompressor code (git-fixes).\n- s390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct() (git-fixes).\n- s390/pageattr: Implement missing kernel_page_present() (git-fixes).\n- scatterlist: fix incorrect func name in kernel-doc (git-fixes).\n- sched/numa: fix memory leak due to the overwritten vma-\u003enumab_state (git fixes (sched/numa)).\n- scsi: lpfc: Add handling for LS_RJT reason explanation authentication required (bsc#1235409).\n- scsi: lpfc: Add support for large fw object application layer reads (bsc#1235409).\n- scsi: lpfc: Change lpfc_nodelist save_flags member into a bitmask (bsc#1235409).\n- scsi: lpfc: Copyright updates for 14.4.0.7 patches (bsc#1235409).\n- scsi: lpfc: Delete NLP_TARGET_REMOVE flag due to obsolete usage (bsc#1235409).\n- scsi: lpfc: Modify handling of ADISC based on ndlp state and RPI registration (bsc#1235409).\n- scsi: lpfc: Redefine incorrect type in lpfc_create_device_data() (bsc#1235409).\n- scsi: lpfc: Restrict the REG_FCFI MAM field to FCoE adapters only (bsc#1235409).\n- scsi: lpfc: Update definition of firmware configuration mbox cmds (bsc#1235409).\n- scsi: lpfc: Update lpfc version to 14.4.0.7 (bsc#1235409).\n- scsi: qla2xxx: Fix abort in bsg timeout (bsc#1235406).\n- scsi: qla2xxx: Fix NVMe and NPIV connect issue (bsc#1235406).\n- scsi: qla2xxx: Fix use after free on unload (bsc#1235406).\n- scsi: qla2xxx: Remove check req_sg_cnt should be equal to rsp_sg_cnt (bsc#1235406).\n- scsi: qla2xxx: Remove the unused \u0027del_list_entry\u0027 field in struct fc_port (bsc#1235406).\n- scsi: qla2xxx: Supported speed displayed incorrectly for VPorts (bsc#1235406).\n- scsi: qla2xxx: Update version to 10.02.09.400-k (bsc#1235406).\n- scsi: storvsc: Do not flag MAINTENANCE_IN return of SRB_STATUS_DATA_OVERRUN as an error (git-fixes).\n- selftests/bpf: Test PROBE_MEM of VSYSCALL_ADDR on x86-64 (git-fixes).\n- serial: 8250_dw: Add Sophgo SG2044 quirk (stable-fixes).\n- serial: 8250_dw: Do not use struct dw8250_data outside of 8250_dw (git-fixes).\n- serial: 8250_dw: Replace ACPI device check by a quirk (git-fixes).\n- serial: 8250_fintek: Add support for F81216E (stable-fixes).\n- serial: amba-pl011: fix build regression (git-fixes).\n- serial: amba-pl011: Fix RX stall when DMA is used (git-fixes).\n- serial: amba-pl011: Use port lock wrappers (stable-fixes).\n- serial: Do not hold the port lock when setting rx-during-tx GPIO (git-fixes).\n- serial: do not use uninitialized value in uart_poll_init() (git-fixes).\n- serial: imx: only set receiver level if it is zero (git-fixes).\n- serial: imx: set receiver level before starting uart (git-fixes).\n- serial: qcom-geni: disable interrupts during console writes (git-fixes).\n- serial: qcom-geni: Do not cancel/abort if we can\u0027t get the port lock (git-fixes).\n- serial: qcom-geni: fix arg types for qcom_geni_serial_poll_bit() (git-fixes).\n- serial: qcom-geni: fix console corruption (git-fixes).\n- serial: qcom-geni: fix dma rx cancellation (git-fixes).\n- serial: qcom-geni: fix false console tx restart (git-fixes).\n- serial: qcom-geni: fix fifo polling timeout (git-fixes).\n- serial: qcom-geni: fix hard lockup on buffer flush (git-fixes).\n- serial: qcom-geni: fix polled console corruption (git-fixes).\n- serial: qcom-geni: fix polled console initialisation (git-fixes).\n- serial: qcom-geni: fix receiver enable (git-fixes).\n- serial: qcom-geni: fix shutdown race (git-fixes).\n- serial: qcom-geni: fix soft lockup on sw flow control and suspend (git-fixes).\n- serial: qcom-geni: introduce qcom_geni_serial_poll_bitfield() (git-fixes).\n- serial: qcom-geni: revert broken hibernation support (git-fixes).\n- serial: stm32: do not always set SER_RS485_RX_DURING_TX if RS485 is enabled (git-fixes).\n- serial: stm32: Return IRQ_NONE in the ISR if no handling happend (git-fixes).\n- slub: Replace cmpxchg_double() - KABI fix (bsc#1220773).\n- slub: Replace cmpxchg_double() (bsc#1220773).\n- smb: client: fix TCP timers deadlock after rmmod (git-fixes) [hcarvalho: fix issue described in bsc#1233642]\n- soc: fsl: cpm1: qmc: Fix blank line and spaces (stable-fixes).\n- soc: fsl: cpm1: qmc: Introduce qmc_{init,exit}_xcc() and their CPM1 version (stable-fixes).\n- soc: fsl: cpm1: qmc: Introduce qmc_init_resource() and its CPM1 version (stable-fixes).\n- soc: fsl: cpm1: qmc: Re-order probe() operations (stable-fixes).\n- soc: fsl: cpm1: qmc: Set the ret error code on platform_get_irq() failure (git-fixes).\n- soc: imx8m: Probe the SoC driver as platform driver (stable-fixes).\n- soc: qcom: Add check devm_kasprintf() returned value (stable-fixes).\n- soc: qcom: geni-se: add GP_LENGTH/IRQ_EN_SET/IRQ_EN_CLEAR registers (git-fixes).\n- soc: qcom: geni-se: Add M_TX_FIFO_NOT_EMPTY bit definition (git-fixes).\n- soc: qcom: socinfo: fix revision check in qcom_socinfo_probe() (git-fixes).\n- soc/fsl: cpm: qmc: Convert to platform remove callback returning void (stable-fixes).\n- spi: aspeed: Fix an error handling path in aspeed_spi_[read|write]_user() (git-fixes).\n- sunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport (git-fixes).\n- sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket (git-fixes).\n- sunrpc: handle -ENOTCONN in xs_tcp_setup_socket() (git-fixes).\n- SUNRPC: make sure cache entry active before cache_show (git-fixes).\n- SUNRPC: timeout and cancel TLS handshake with -ETIMEDOUT (git-fixes).\n- svcrdma: Address an integer overflow (git-fixes).\n- svcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init() (git-fixes).\n- swiotlb: Enforce page alignment in swiotlb_alloc() (git-fixes).\n- swiotlb: Reinstate page-alignment for mappings \u003e= PAGE_SIZE (git-fixes).\n- thermal/drivers/qcom/tsens-v1: Add support for MSM8937 tsens (stable-fixes).\n- tools: hv: change permissions of NetworkManager configuration file (git-fixes).\n- tpm_tis_spi: Release chip select when flow control fails (bsc#1234338)\n- tpm/eventlog: Limit memory allocations for event logs with excessive size (bsc#1233260 bsc#1233259 bsc#1232421).\n- tty: serial: kgdboc: Fix 8250_* kgdb over serial (git-fixes).\n- types: Introduce [us]128 (bsc#1220773).\n- ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit (git-fixes).\n- ubifs: Correct the total block count by deducting journal reservation (git-fixes).\n- udf: Fix lock ordering in udf_evict_inode() (bsc#1234238).\n- udf: fix uninit-value use in udf_get_fileshortad (bsc#1234243).\n- udf: prevent integer overflow in udf_bitmap_free_blocks() (bsc#1234239).\n- udf: refactor inode_bmap() to handle error (bsc#1234242).\n- udf: refactor udf_current_aext() to handle error (bsc#1234240).\n- udf: refactor udf_next_aext() to handle error (bsc#1234241).\n- udf: udftime: prevent overflow in udf_disk_stamp_to_time() (bsc#1234237).\n- usb: add support for new USB device ID 0x17EF:0x3098 for the r8152 driver (stable-fixes).\n- usb: cdns3-ti: Add workaround for Errata i2409 (stable-fixes).\n- usb: cdns3: Add quirk flag to enable suspend residency (stable-fixes).\n- usb: chipidea: udc: handle USB Error Interrupt if IOC not set (stable-fixes).\n- usb: dwc2: Fix HCD port connection race (git-fixes).\n- usb: dwc2: Fix HCD resume (git-fixes).\n- usb: dwc2: gadget: Do not write invalid mapped sg entries into dma_desc with iommu enabled (stable-fixes).\n- usb: dwc2: hcd: Fix GetPortStatus \u0026 SetPortFeature (git-fixes).\n- usb: dwc3: ep0: Do not clear ep0 DWC3_EP_TRANSFER_STARTED (git-fixes).\n- usb: dwc3: ep0: Do not reset resource alloc flag (git-fixes).\n- usb: dwc3: ep0: Do not reset resource alloc flag (including ep0) (git-fixes).\n- usb: dwc3: gadget: Rewrite endpoint allocation flow (stable-fixes).\n- usb: dwc3: xilinx: make sure pipe clock is deselected in usb2 only mode (git-fixes).\n- usb: ehci-hcd: fix call balance of clocks handling routines (git-fixes).\n- usb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer (git-fixes).\n- usb: host: max3421-hcd: Correctly abort a USB request (git-fixes).\n- USB: serial: option: add MediaTek T7XX compositions (stable-fixes).\n- USB: serial: option: add MeiG Smart SLM770A (stable-fixes).\n- USB: serial: option: add Netprisma LCUK54 modules for WWAN Ready (stable-fixes).\n- USB: serial: option: add TCL IK512 MBIM \u0026 ECM (stable-fixes).\n- USB: serial: option: add Telit FE910C04 rmnet compositions (stable-fixes).\n- usb: typec: anx7411: fix fwnode_handle reference leak (git-fixes).\n- usb: typec: anx7411: fix OF node reference leaks in anx7411_typec_switch_probe() (git-fixes).\n- usb: typec: use cleanup facility for \u0027altmodes_node\u0027 (stable-fixes).\n- vdpa: solidrun: Fix UB bug with devres (git-fixes).\n- vDPA/ifcvf: Fix pci_read_config_byte() return code handling (git-fixes).\n- vdpa/mlx5: Fix PA offset with unaligned starting iotlb map (git-fixes).\n- vdpa/mlx5: Fix suboptimal range on iotlb iteration (git-fixes).\n- vfs: fix readahead(2) on block devices (bsc#1234201).\n- wifi: ath5k: add PCI ID for Arcadyan devices (git-fixes).\n- wifi: ath5k: add PCI ID for SX76X (git-fixes).\n- wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() (stable-fixes).\n- wifi: cfg80211: sme: init n_channels before channels[] access (git-fixes).\n- wifi: cw1200: Fix potential NULL dereference (git-fixes).\n- wifi: ipw2x00: libipw_rx_any(): fix bad alignment (stable-fixes).\n- wifi: iwlwifi: mvm: Use the sync timepoint API in suspend (stable-fixes).\n- wifi: mac80211: clean up \u0027ret\u0027 in sta_link_apply_parameters() (stable-fixes).\n- wifi: mac80211: fix station NSS capability initialization order (git-fixes).\n- wifi: mac80211: init cnt before accessing elem in ieee80211_copy_mbssid_beacon (git-fixes).\n- wifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one (git-fixes).\n- wifi: rtlwifi: Drastically reduce the attempts to read efuse in case of failures (stable-fixes).\n- wifi: rtw89: check return value of ieee80211_probereq_get() for RNR (stable-fixes).\n- workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_RECLAIM worker (bsc#1235416).\n- writeback, cgroup: switch inodes with dirty timestamps to release dying cgwbs (bsc#1234203).\n- x86,amd_iommu: Replace cmpxchg_double() (bsc#1220773).\n- x86,intel_iommu: Replace cmpxchg_double() (bsc#1220773).\n- x86/hyperv: Fix hv tsc page based sched_clock for hibernation (git-fixes).\n- xfs: do not allocate COW extents when unsharing a hole (git-fixes).\n- xfs: fix sb_spino_align checks for large fsblock sizes (git-fixes).\n- xfs: remove unknown compat feature check in superblock write validation (git-fixes).\n- xfs: return from xfs_symlink_verify early on V4 filesystems (git-fixes).\n- xfs: sb_spino_align is not verified (git-fixes).\n- xhci: Add usb cold attach (CAS) as a reason to resume root hub (git-fixes).\n- xhci: Allow RPM on the USB controller (1022:43f7) by default (stable-fixes).\n- xhci: fix possible null pointer deref during xhci urb enqueue (git-fixes).\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2025-117,SUSE-SLE-Module-Public-Cloud-15-SP6-2025-117,openSUSE-SLE-15.6-2025-117", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2025_0117-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2025:0117-1", "url": "https://www.suse.com/support/update/announcement/2025/suse-su-20250117-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2025:0117-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2025-January/020131.html" }, { "category": "self", "summary": "SUSE Bug 1214954", "url": "https://bugzilla.suse.com/1214954" }, { "category": "self", "summary": "SUSE Bug 1216813", "url": "https://bugzilla.suse.com/1216813" }, { "category": "self", "summary": "SUSE Bug 1220773", "url": "https://bugzilla.suse.com/1220773" }, { "category": "self", "summary": "SUSE Bug 1224095", "url": "https://bugzilla.suse.com/1224095" }, { "category": "self", "summary": "SUSE Bug 1224726", "url": "https://bugzilla.suse.com/1224726" }, { "category": "self", "summary": "SUSE Bug 1225743", "url": "https://bugzilla.suse.com/1225743" }, { "category": "self", "summary": "SUSE Bug 1225758", "url": "https://bugzilla.suse.com/1225758" }, { "category": "self", "summary": "SUSE Bug 1225820", "url": "https://bugzilla.suse.com/1225820" }, { "category": "self", "summary": "SUSE Bug 1227445", "url": "https://bugzilla.suse.com/1227445" }, { "category": "self", "summary": "SUSE Bug 1228526", "url": "https://bugzilla.suse.com/1228526" }, { "category": "self", "summary": "SUSE Bug 1229809", "url": "https://bugzilla.suse.com/1229809" }, { "category": "self", "summary": "SUSE Bug 1230205", "url": "https://bugzilla.suse.com/1230205" }, { "category": "self", "summary": "SUSE Bug 1230413", "url": "https://bugzilla.suse.com/1230413" }, { "category": "self", "summary": "SUSE Bug 1230697", "url": "https://bugzilla.suse.com/1230697" }, { "category": "self", "summary": "SUSE Bug 1231854", "url": "https://bugzilla.suse.com/1231854" }, { "category": "self", "summary": "SUSE Bug 1231909", "url": "https://bugzilla.suse.com/1231909" }, { "category": "self", "summary": "SUSE Bug 1231963", "url": "https://bugzilla.suse.com/1231963" }, { "category": "self", "summary": "SUSE Bug 1232193", "url": "https://bugzilla.suse.com/1232193" }, { "category": "self", "summary": "SUSE Bug 1232198", "url": "https://bugzilla.suse.com/1232198" }, { "category": "self", "summary": "SUSE Bug 1232201", "url": "https://bugzilla.suse.com/1232201" }, { "category": "self", "summary": "SUSE Bug 1232418", "url": "https://bugzilla.suse.com/1232418" }, { "category": "self", "summary": "SUSE Bug 1232419", "url": "https://bugzilla.suse.com/1232419" }, { "category": "self", "summary": "SUSE Bug 1232420", "url": "https://bugzilla.suse.com/1232420" }, { "category": "self", "summary": "SUSE Bug 1232421", "url": "https://bugzilla.suse.com/1232421" }, { "category": "self", "summary": "SUSE Bug 1232436", "url": "https://bugzilla.suse.com/1232436" }, { "category": "self", "summary": "SUSE Bug 1233038", "url": "https://bugzilla.suse.com/1233038" }, { "category": "self", "summary": "SUSE Bug 1233070", "url": "https://bugzilla.suse.com/1233070" }, { "category": "self", "summary": "SUSE Bug 1233096", "url": "https://bugzilla.suse.com/1233096" }, { "category": "self", "summary": "SUSE Bug 1233200", "url": "https://bugzilla.suse.com/1233200" }, { "category": "self", "summary": "SUSE Bug 1233204", "url": "https://bugzilla.suse.com/1233204" }, { "category": "self", "summary": "SUSE Bug 1233239", "url": "https://bugzilla.suse.com/1233239" }, { "category": "self", "summary": "SUSE Bug 1233259", "url": "https://bugzilla.suse.com/1233259" }, { "category": "self", "summary": "SUSE Bug 1233260", "url": "https://bugzilla.suse.com/1233260" }, { "category": "self", "summary": "SUSE Bug 1233324", "url": "https://bugzilla.suse.com/1233324" }, { "category": "self", "summary": "SUSE Bug 1233328", "url": "https://bugzilla.suse.com/1233328" }, { "category": "self", "summary": "SUSE Bug 1233461", "url": "https://bugzilla.suse.com/1233461" }, { "category": "self", "summary": "SUSE Bug 1233467", "url": "https://bugzilla.suse.com/1233467" }, { "category": "self", "summary": "SUSE Bug 1233468", "url": "https://bugzilla.suse.com/1233468" }, { "category": "self", "summary": "SUSE Bug 1233469", "url": "https://bugzilla.suse.com/1233469" }, { "category": "self", "summary": "SUSE Bug 1233546", "url": "https://bugzilla.suse.com/1233546" }, { "category": "self", "summary": "SUSE Bug 1233558", "url": "https://bugzilla.suse.com/1233558" }, { "category": "self", "summary": "SUSE Bug 1233637", "url": "https://bugzilla.suse.com/1233637" }, { "category": "self", "summary": "SUSE Bug 1233642", "url": "https://bugzilla.suse.com/1233642" }, { "category": "self", "summary": "SUSE Bug 1233772", "url": "https://bugzilla.suse.com/1233772" }, { "category": "self", "summary": "SUSE Bug 1233837", "url": "https://bugzilla.suse.com/1233837" }, { "category": "self", "summary": "SUSE Bug 1234024", "url": "https://bugzilla.suse.com/1234024" }, { "category": "self", "summary": "SUSE Bug 1234069", "url": "https://bugzilla.suse.com/1234069" }, { "category": "self", "summary": "SUSE Bug 1234071", "url": "https://bugzilla.suse.com/1234071" }, { "category": "self", "summary": "SUSE Bug 1234073", "url": "https://bugzilla.suse.com/1234073" }, { "category": "self", "summary": "SUSE Bug 1234075", "url": "https://bugzilla.suse.com/1234075" }, { "category": "self", "summary": "SUSE Bug 1234076", "url": "https://bugzilla.suse.com/1234076" }, { "category": "self", "summary": "SUSE Bug 1234077", "url": "https://bugzilla.suse.com/1234077" }, { "category": "self", "summary": "SUSE Bug 1234079", "url": "https://bugzilla.suse.com/1234079" }, { "category": "self", "summary": "SUSE Bug 1234086", "url": "https://bugzilla.suse.com/1234086" }, { "category": "self", "summary": "SUSE Bug 1234139", "url": "https://bugzilla.suse.com/1234139" }, { "category": "self", "summary": "SUSE Bug 1234140", "url": "https://bugzilla.suse.com/1234140" }, { "category": "self", "summary": "SUSE Bug 1234141", "url": "https://bugzilla.suse.com/1234141" }, { "category": "self", "summary": "SUSE Bug 1234142", "url": "https://bugzilla.suse.com/1234142" }, { "category": "self", "summary": "SUSE Bug 1234143", "url": "https://bugzilla.suse.com/1234143" }, { "category": "self", "summary": "SUSE Bug 1234144", "url": "https://bugzilla.suse.com/1234144" }, { "category": "self", "summary": "SUSE Bug 1234145", "url": "https://bugzilla.suse.com/1234145" }, { "category": "self", "summary": "SUSE Bug 1234146", "url": "https://bugzilla.suse.com/1234146" }, { "category": "self", "summary": "SUSE Bug 1234147", "url": "https://bugzilla.suse.com/1234147" }, { "category": "self", "summary": "SUSE Bug 1234148", "url": "https://bugzilla.suse.com/1234148" }, { "category": "self", "summary": "SUSE Bug 1234149", "url": "https://bugzilla.suse.com/1234149" }, { "category": "self", "summary": "SUSE Bug 1234150", "url": "https://bugzilla.suse.com/1234150" }, { "category": "self", "summary": "SUSE Bug 1234153", "url": "https://bugzilla.suse.com/1234153" }, { "category": "self", "summary": "SUSE Bug 1234155", "url": "https://bugzilla.suse.com/1234155" }, { "category": "self", "summary": "SUSE Bug 1234156", "url": "https://bugzilla.suse.com/1234156" }, { "category": "self", "summary": "SUSE Bug 1234158", "url": "https://bugzilla.suse.com/1234158" }, { "category": "self", "summary": "SUSE Bug 1234159", "url": "https://bugzilla.suse.com/1234159" }, { "category": "self", "summary": "SUSE Bug 1234160", "url": "https://bugzilla.suse.com/1234160" }, { "category": "self", "summary": "SUSE Bug 1234161", "url": "https://bugzilla.suse.com/1234161" }, { "category": "self", "summary": "SUSE Bug 1234162", "url": "https://bugzilla.suse.com/1234162" }, { "category": "self", "summary": "SUSE Bug 1234163", "url": "https://bugzilla.suse.com/1234163" }, { "category": "self", "summary": "SUSE Bug 1234164", "url": "https://bugzilla.suse.com/1234164" }, { "category": "self", "summary": "SUSE Bug 1234165", "url": "https://bugzilla.suse.com/1234165" }, { "category": "self", "summary": "SUSE Bug 1234166", "url": "https://bugzilla.suse.com/1234166" }, { "category": "self", "summary": "SUSE Bug 1234167", "url": "https://bugzilla.suse.com/1234167" }, { "category": "self", "summary": "SUSE Bug 1234168", "url": "https://bugzilla.suse.com/1234168" }, { "category": "self", "summary": "SUSE Bug 1234169", "url": "https://bugzilla.suse.com/1234169" }, { "category": "self", "summary": "SUSE Bug 1234170", "url": "https://bugzilla.suse.com/1234170" }, { "category": "self", "summary": "SUSE Bug 1234171", "url": "https://bugzilla.suse.com/1234171" }, { "category": "self", "summary": "SUSE Bug 1234172", "url": "https://bugzilla.suse.com/1234172" }, { "category": "self", "summary": "SUSE Bug 1234173", "url": "https://bugzilla.suse.com/1234173" }, { "category": "self", "summary": "SUSE Bug 1234174", "url": "https://bugzilla.suse.com/1234174" }, { "category": "self", "summary": "SUSE Bug 1234175", "url": "https://bugzilla.suse.com/1234175" }, { "category": "self", "summary": "SUSE Bug 1234176", "url": "https://bugzilla.suse.com/1234176" }, { "category": "self", "summary": "SUSE Bug 1234177", "url": "https://bugzilla.suse.com/1234177" }, { "category": "self", "summary": "SUSE Bug 1234178", "url": "https://bugzilla.suse.com/1234178" }, { "category": "self", "summary": "SUSE Bug 1234179", "url": "https://bugzilla.suse.com/1234179" }, { "category": "self", "summary": "SUSE Bug 1234180", "url": "https://bugzilla.suse.com/1234180" }, { "category": "self", "summary": "SUSE Bug 1234181", "url": "https://bugzilla.suse.com/1234181" }, { "category": "self", "summary": "SUSE Bug 1234182", "url": "https://bugzilla.suse.com/1234182" }, { "category": "self", "summary": "SUSE Bug 1234183", "url": "https://bugzilla.suse.com/1234183" }, { "category": "self", "summary": "SUSE Bug 1234184", "url": "https://bugzilla.suse.com/1234184" }, { "category": "self", "summary": "SUSE Bug 1234185", "url": "https://bugzilla.suse.com/1234185" }, { "category": "self", "summary": "SUSE Bug 1234186", "url": "https://bugzilla.suse.com/1234186" }, { "category": "self", "summary": "SUSE Bug 1234187", "url": "https://bugzilla.suse.com/1234187" }, { "category": "self", "summary": "SUSE Bug 1234188", "url": "https://bugzilla.suse.com/1234188" }, { "category": "self", "summary": "SUSE Bug 1234189", "url": "https://bugzilla.suse.com/1234189" }, { "category": "self", "summary": "SUSE Bug 1234190", "url": "https://bugzilla.suse.com/1234190" }, { "category": "self", "summary": "SUSE Bug 1234191", "url": "https://bugzilla.suse.com/1234191" }, { "category": "self", "summary": "SUSE Bug 1234192", "url": "https://bugzilla.suse.com/1234192" }, { "category": "self", "summary": "SUSE Bug 1234193", "url": "https://bugzilla.suse.com/1234193" }, { "category": "self", "summary": "SUSE Bug 1234194", "url": "https://bugzilla.suse.com/1234194" }, { "category": "self", "summary": "SUSE Bug 1234195", "url": "https://bugzilla.suse.com/1234195" }, { "category": "self", "summary": "SUSE Bug 1234196", "url": "https://bugzilla.suse.com/1234196" }, { "category": "self", "summary": "SUSE Bug 1234197", "url": "https://bugzilla.suse.com/1234197" }, { "category": "self", "summary": "SUSE Bug 1234198", "url": "https://bugzilla.suse.com/1234198" }, { "category": "self", "summary": "SUSE Bug 1234199", "url": "https://bugzilla.suse.com/1234199" }, { "category": "self", "summary": "SUSE Bug 1234200", "url": "https://bugzilla.suse.com/1234200" }, { "category": "self", "summary": "SUSE Bug 1234201", "url": "https://bugzilla.suse.com/1234201" }, { "category": "self", "summary": "SUSE Bug 1234203", "url": "https://bugzilla.suse.com/1234203" }, { "category": "self", "summary": "SUSE Bug 1234204", "url": "https://bugzilla.suse.com/1234204" }, { "category": "self", "summary": "SUSE Bug 1234205", "url": "https://bugzilla.suse.com/1234205" }, { "category": "self", "summary": "SUSE Bug 1234207", "url": "https://bugzilla.suse.com/1234207" }, { "category": "self", "summary": "SUSE Bug 1234208", "url": "https://bugzilla.suse.com/1234208" }, { "category": "self", "summary": "SUSE Bug 1234209", "url": "https://bugzilla.suse.com/1234209" }, { "category": "self", "summary": "SUSE Bug 1234219", "url": "https://bugzilla.suse.com/1234219" }, { "category": "self", "summary": "SUSE Bug 1234220", "url": "https://bugzilla.suse.com/1234220" }, { "category": "self", "summary": "SUSE Bug 1234221", "url": "https://bugzilla.suse.com/1234221" }, { "category": "self", "summary": "SUSE Bug 1234237", "url": "https://bugzilla.suse.com/1234237" }, { "category": "self", "summary": "SUSE Bug 1234238", "url": "https://bugzilla.suse.com/1234238" }, { "category": "self", "summary": "SUSE Bug 1234239", "url": "https://bugzilla.suse.com/1234239" }, { "category": "self", "summary": "SUSE Bug 1234240", "url": "https://bugzilla.suse.com/1234240" }, { "category": "self", "summary": "SUSE Bug 1234241", "url": "https://bugzilla.suse.com/1234241" }, { "category": "self", "summary": "SUSE Bug 1234242", "url": "https://bugzilla.suse.com/1234242" }, { "category": "self", "summary": "SUSE Bug 1234243", "url": "https://bugzilla.suse.com/1234243" }, { "category": "self", "summary": "SUSE Bug 1234278", "url": "https://bugzilla.suse.com/1234278" }, { "category": "self", "summary": "SUSE Bug 1234279", "url": "https://bugzilla.suse.com/1234279" }, { "category": "self", "summary": "SUSE Bug 1234280", "url": "https://bugzilla.suse.com/1234280" }, { "category": "self", "summary": "SUSE Bug 1234281", "url": "https://bugzilla.suse.com/1234281" }, { "category": "self", "summary": "SUSE Bug 1234282", "url": "https://bugzilla.suse.com/1234282" }, { "category": "self", "summary": "SUSE Bug 1234294", "url": "https://bugzilla.suse.com/1234294" }, { "category": "self", "summary": "SUSE Bug 1234338", "url": "https://bugzilla.suse.com/1234338" }, { "category": "self", "summary": "SUSE Bug 1234357", "url": "https://bugzilla.suse.com/1234357" }, { "category": "self", "summary": "SUSE Bug 1234381", "url": "https://bugzilla.suse.com/1234381" }, { "category": "self", "summary": "SUSE Bug 1234454", "url": "https://bugzilla.suse.com/1234454" }, { "category": "self", "summary": "SUSE Bug 1234464", "url": "https://bugzilla.suse.com/1234464" }, { "category": "self", "summary": "SUSE Bug 1234605", "url": "https://bugzilla.suse.com/1234605" }, { "category": "self", "summary": "SUSE Bug 1234651", "url": "https://bugzilla.suse.com/1234651" }, { "category": "self", "summary": "SUSE Bug 1234652", "url": "https://bugzilla.suse.com/1234652" }, { "category": "self", "summary": "SUSE Bug 1234654", "url": "https://bugzilla.suse.com/1234654" }, { "category": "self", "summary": "SUSE Bug 1234655", "url": "https://bugzilla.suse.com/1234655" }, { "category": "self", "summary": "SUSE Bug 1234657", "url": "https://bugzilla.suse.com/1234657" }, { "category": "self", "summary": "SUSE Bug 1234658", "url": "https://bugzilla.suse.com/1234658" }, { "category": "self", "summary": "SUSE Bug 1234659", "url": "https://bugzilla.suse.com/1234659" }, { "category": "self", "summary": "SUSE Bug 1234668", "url": "https://bugzilla.suse.com/1234668" }, { "category": "self", "summary": "SUSE Bug 1234690", "url": "https://bugzilla.suse.com/1234690" }, { "category": "self", "summary": "SUSE Bug 1234725", "url": "https://bugzilla.suse.com/1234725" }, { "category": "self", "summary": "SUSE Bug 1234726", "url": "https://bugzilla.suse.com/1234726" }, { "category": "self", "summary": "SUSE Bug 1234810", "url": "https://bugzilla.suse.com/1234810" }, { "category": "self", "summary": "SUSE Bug 1234811", "url": "https://bugzilla.suse.com/1234811" }, { "category": "self", "summary": "SUSE Bug 1234826", "url": "https://bugzilla.suse.com/1234826" }, { "category": "self", "summary": "SUSE Bug 1234827", "url": "https://bugzilla.suse.com/1234827" }, { "category": "self", "summary": "SUSE Bug 1234829", "url": "https://bugzilla.suse.com/1234829" }, { "category": "self", "summary": "SUSE Bug 1234832", "url": "https://bugzilla.suse.com/1234832" }, { "category": "self", "summary": "SUSE Bug 1234834", "url": "https://bugzilla.suse.com/1234834" }, { "category": "self", "summary": "SUSE Bug 1234843", "url": "https://bugzilla.suse.com/1234843" }, { "category": "self", "summary": "SUSE Bug 1234846", "url": "https://bugzilla.suse.com/1234846" }, { "category": "self", "summary": "SUSE Bug 1234848", "url": "https://bugzilla.suse.com/1234848" }, { "category": "self", "summary": "SUSE Bug 1234853", "url": "https://bugzilla.suse.com/1234853" }, { "category": "self", "summary": "SUSE Bug 1234855", "url": "https://bugzilla.suse.com/1234855" }, { "category": "self", "summary": "SUSE Bug 1234856", "url": "https://bugzilla.suse.com/1234856" }, { "category": "self", "summary": "SUSE Bug 1234884", "url": "https://bugzilla.suse.com/1234884" }, { "category": "self", "summary": "SUSE Bug 1234889", "url": "https://bugzilla.suse.com/1234889" }, { "category": "self", "summary": "SUSE Bug 1234891", "url": "https://bugzilla.suse.com/1234891" }, { "category": "self", "summary": "SUSE Bug 1234899", "url": "https://bugzilla.suse.com/1234899" }, { "category": "self", "summary": "SUSE Bug 1234900", "url": "https://bugzilla.suse.com/1234900" }, { "category": "self", "summary": "SUSE Bug 1234905", "url": "https://bugzilla.suse.com/1234905" }, { "category": "self", "summary": "SUSE Bug 1234907", "url": "https://bugzilla.suse.com/1234907" }, { "category": "self", "summary": "SUSE Bug 1234909", "url": "https://bugzilla.suse.com/1234909" }, { "category": "self", "summary": "SUSE Bug 1234911", "url": "https://bugzilla.suse.com/1234911" }, { "category": "self", "summary": "SUSE Bug 1234912", "url": "https://bugzilla.suse.com/1234912" }, { "category": "self", "summary": "SUSE Bug 1234916", "url": "https://bugzilla.suse.com/1234916" }, { "category": "self", "summary": "SUSE Bug 1234918", "url": "https://bugzilla.suse.com/1234918" }, { "category": "self", "summary": "SUSE Bug 1234920", "url": "https://bugzilla.suse.com/1234920" }, { "category": "self", "summary": "SUSE Bug 1234921", "url": "https://bugzilla.suse.com/1234921" }, { "category": "self", "summary": "SUSE Bug 1234922", "url": "https://bugzilla.suse.com/1234922" }, { "category": "self", "summary": "SUSE Bug 1234929", "url": "https://bugzilla.suse.com/1234929" }, { "category": "self", "summary": "SUSE Bug 1234930", "url": "https://bugzilla.suse.com/1234930" }, { "category": "self", "summary": "SUSE Bug 1234937", "url": "https://bugzilla.suse.com/1234937" }, { "category": "self", "summary": "SUSE Bug 1234948", "url": "https://bugzilla.suse.com/1234948" }, { "category": "self", "summary": "SUSE Bug 1234950", "url": "https://bugzilla.suse.com/1234950" }, { "category": "self", "summary": "SUSE Bug 1234952", "url": "https://bugzilla.suse.com/1234952" }, { "category": "self", "summary": "SUSE Bug 1234960", "url": "https://bugzilla.suse.com/1234960" }, { "category": "self", "summary": "SUSE Bug 1234962", "url": "https://bugzilla.suse.com/1234962" }, { "category": "self", "summary": "SUSE Bug 1234963", "url": "https://bugzilla.suse.com/1234963" }, { "category": "self", "summary": "SUSE Bug 1234968", "url": "https://bugzilla.suse.com/1234968" }, { "category": "self", "summary": "SUSE Bug 1234969", "url": "https://bugzilla.suse.com/1234969" }, { "category": "self", "summary": "SUSE Bug 1234970", "url": "https://bugzilla.suse.com/1234970" }, { "category": "self", "summary": "SUSE Bug 1234971", "url": "https://bugzilla.suse.com/1234971" }, { "category": "self", "summary": "SUSE Bug 1234973", "url": "https://bugzilla.suse.com/1234973" }, { "category": "self", "summary": "SUSE Bug 1234974", "url": "https://bugzilla.suse.com/1234974" }, { "category": "self", "summary": "SUSE Bug 1234989", "url": "https://bugzilla.suse.com/1234989" }, { "category": "self", "summary": "SUSE Bug 1234999", "url": "https://bugzilla.suse.com/1234999" }, { "category": "self", "summary": "SUSE Bug 1235002", "url": "https://bugzilla.suse.com/1235002" }, { "category": "self", "summary": "SUSE Bug 1235003", "url": "https://bugzilla.suse.com/1235003" }, { "category": "self", "summary": "SUSE Bug 1235004", "url": "https://bugzilla.suse.com/1235004" }, { "category": "self", "summary": "SUSE Bug 1235007", "url": "https://bugzilla.suse.com/1235007" }, { "category": "self", "summary": "SUSE Bug 1235009", "url": "https://bugzilla.suse.com/1235009" }, { "category": "self", "summary": "SUSE Bug 1235016", "url": "https://bugzilla.suse.com/1235016" }, { "category": "self", "summary": "SUSE Bug 1235019", "url": "https://bugzilla.suse.com/1235019" }, { "category": "self", "summary": "SUSE Bug 1235033", "url": "https://bugzilla.suse.com/1235033" }, { "category": "self", "summary": "SUSE Bug 1235045", "url": "https://bugzilla.suse.com/1235045" }, { "category": "self", "summary": "SUSE Bug 1235056", "url": "https://bugzilla.suse.com/1235056" }, { "category": "self", "summary": "SUSE Bug 1235061", "url": "https://bugzilla.suse.com/1235061" }, { "category": "self", "summary": "SUSE Bug 1235075", "url": "https://bugzilla.suse.com/1235075" }, { "category": "self", "summary": "SUSE Bug 1235108", "url": "https://bugzilla.suse.com/1235108" }, { "category": "self", "summary": "SUSE Bug 1235128", "url": "https://bugzilla.suse.com/1235128" }, { "category": "self", "summary": "SUSE Bug 1235134", "url": "https://bugzilla.suse.com/1235134" }, { "category": "self", "summary": "SUSE Bug 1235138", "url": "https://bugzilla.suse.com/1235138" }, { "category": "self", "summary": "SUSE Bug 1235246", "url": "https://bugzilla.suse.com/1235246" }, { "category": "self", "summary": "SUSE Bug 1235406", "url": "https://bugzilla.suse.com/1235406" }, { "category": "self", "summary": "SUSE Bug 1235409", "url": "https://bugzilla.suse.com/1235409" }, { "category": "self", "summary": "SUSE Bug 1235416", "url": "https://bugzilla.suse.com/1235416" }, { "category": "self", "summary": "SUSE Bug 1235507", "url": "https://bugzilla.suse.com/1235507" }, { "category": "self", "summary": "SUSE Bug 1235550", "url": "https://bugzilla.suse.com/1235550" }, { "category": "self", "summary": "SUSE CVE CVE-2024-26924 page", "url": "https://www.suse.com/security/cve/CVE-2024-26924/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-27397 page", "url": "https://www.suse.com/security/cve/CVE-2024-27397/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-35839 page", "url": "https://www.suse.com/security/cve/CVE-2024-35839/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36908 page", "url": "https://www.suse.com/security/cve/CVE-2024-36908/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-36915 page", "url": "https://www.suse.com/security/cve/CVE-2024-36915/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-39480 page", "url": "https://www.suse.com/security/cve/CVE-2024-39480/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-41042 page", "url": "https://www.suse.com/security/cve/CVE-2024-41042/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-44934 page", "url": "https://www.suse.com/security/cve/CVE-2024-44934/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-44996 page", "url": "https://www.suse.com/security/cve/CVE-2024-44996/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-47678 page", "url": "https://www.suse.com/security/cve/CVE-2024-47678/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49854 page", "url": "https://www.suse.com/security/cve/CVE-2024-49854/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49884 page", "url": "https://www.suse.com/security/cve/CVE-2024-49884/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-49915 page", "url": "https://www.suse.com/security/cve/CVE-2024-49915/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50016 page", "url": "https://www.suse.com/security/cve/CVE-2024-50016/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50018 page", "url": "https://www.suse.com/security/cve/CVE-2024-50018/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50039 page", "url": "https://www.suse.com/security/cve/CVE-2024-50039/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50047 page", "url": "https://www.suse.com/security/cve/CVE-2024-50047/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50143 page", "url": "https://www.suse.com/security/cve/CVE-2024-50143/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50154 page", "url": "https://www.suse.com/security/cve/CVE-2024-50154/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50202 page", "url": "https://www.suse.com/security/cve/CVE-2024-50202/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50203 page", "url": "https://www.suse.com/security/cve/CVE-2024-50203/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50211 page", "url": "https://www.suse.com/security/cve/CVE-2024-50211/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50228 page", "url": "https://www.suse.com/security/cve/CVE-2024-50228/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50256 page", "url": "https://www.suse.com/security/cve/CVE-2024-50256/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50262 page", "url": "https://www.suse.com/security/cve/CVE-2024-50262/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50272 page", "url": "https://www.suse.com/security/cve/CVE-2024-50272/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50278 page", "url": "https://www.suse.com/security/cve/CVE-2024-50278/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50279 page", "url": "https://www.suse.com/security/cve/CVE-2024-50279/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-50280 page", "url": "https://www.suse.com/security/cve/CVE-2024-50280/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53050 page", "url": "https://www.suse.com/security/cve/CVE-2024-53050/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53064 page", "url": "https://www.suse.com/security/cve/CVE-2024-53064/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53090 page", "url": "https://www.suse.com/security/cve/CVE-2024-53090/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53099 page", "url": "https://www.suse.com/security/cve/CVE-2024-53099/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53103 page", "url": "https://www.suse.com/security/cve/CVE-2024-53103/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53105 page", "url": "https://www.suse.com/security/cve/CVE-2024-53105/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53111 page", "url": "https://www.suse.com/security/cve/CVE-2024-53111/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53113 page", "url": "https://www.suse.com/security/cve/CVE-2024-53113/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53117 page", "url": "https://www.suse.com/security/cve/CVE-2024-53117/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53118 page", "url": "https://www.suse.com/security/cve/CVE-2024-53118/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53119 page", "url": "https://www.suse.com/security/cve/CVE-2024-53119/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53120 page", "url": "https://www.suse.com/security/cve/CVE-2024-53120/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53122 page", "url": "https://www.suse.com/security/cve/CVE-2024-53122/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53125 page", "url": "https://www.suse.com/security/cve/CVE-2024-53125/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53126 page", "url": "https://www.suse.com/security/cve/CVE-2024-53126/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53127 page", "url": "https://www.suse.com/security/cve/CVE-2024-53127/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53129 page", "url": "https://www.suse.com/security/cve/CVE-2024-53129/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53130 page", "url": "https://www.suse.com/security/cve/CVE-2024-53130/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53131 page", "url": "https://www.suse.com/security/cve/CVE-2024-53131/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53133 page", "url": "https://www.suse.com/security/cve/CVE-2024-53133/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53134 page", "url": "https://www.suse.com/security/cve/CVE-2024-53134/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53136 page", "url": "https://www.suse.com/security/cve/CVE-2024-53136/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53141 page", "url": "https://www.suse.com/security/cve/CVE-2024-53141/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53142 page", "url": "https://www.suse.com/security/cve/CVE-2024-53142/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53144 page", "url": "https://www.suse.com/security/cve/CVE-2024-53144/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53146 page", "url": "https://www.suse.com/security/cve/CVE-2024-53146/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53148 page", "url": "https://www.suse.com/security/cve/CVE-2024-53148/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53150 page", "url": "https://www.suse.com/security/cve/CVE-2024-53150/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53151 page", "url": "https://www.suse.com/security/cve/CVE-2024-53151/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53154 page", "url": "https://www.suse.com/security/cve/CVE-2024-53154/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53155 page", "url": "https://www.suse.com/security/cve/CVE-2024-53155/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53156 page", "url": "https://www.suse.com/security/cve/CVE-2024-53156/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53157 page", "url": "https://www.suse.com/security/cve/CVE-2024-53157/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53158 page", "url": "https://www.suse.com/security/cve/CVE-2024-53158/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53159 page", "url": "https://www.suse.com/security/cve/CVE-2024-53159/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53160 page", "url": "https://www.suse.com/security/cve/CVE-2024-53160/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53161 page", "url": "https://www.suse.com/security/cve/CVE-2024-53161/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53162 page", "url": "https://www.suse.com/security/cve/CVE-2024-53162/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53166 page", "url": "https://www.suse.com/security/cve/CVE-2024-53166/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53169 page", "url": "https://www.suse.com/security/cve/CVE-2024-53169/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53171 page", "url": "https://www.suse.com/security/cve/CVE-2024-53171/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53173 page", "url": "https://www.suse.com/security/cve/CVE-2024-53173/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53174 page", "url": "https://www.suse.com/security/cve/CVE-2024-53174/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53179 page", "url": "https://www.suse.com/security/cve/CVE-2024-53179/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53180 page", "url": "https://www.suse.com/security/cve/CVE-2024-53180/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53188 page", "url": "https://www.suse.com/security/cve/CVE-2024-53188/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53190 page", "url": "https://www.suse.com/security/cve/CVE-2024-53190/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53191 page", "url": "https://www.suse.com/security/cve/CVE-2024-53191/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53200 page", "url": "https://www.suse.com/security/cve/CVE-2024-53200/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53201 page", "url": "https://www.suse.com/security/cve/CVE-2024-53201/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53202 page", "url": "https://www.suse.com/security/cve/CVE-2024-53202/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53206 page", "url": "https://www.suse.com/security/cve/CVE-2024-53206/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53207 page", "url": "https://www.suse.com/security/cve/CVE-2024-53207/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53208 page", "url": "https://www.suse.com/security/cve/CVE-2024-53208/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53209 page", "url": "https://www.suse.com/security/cve/CVE-2024-53209/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53210 page", "url": "https://www.suse.com/security/cve/CVE-2024-53210/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53213 page", "url": "https://www.suse.com/security/cve/CVE-2024-53213/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53214 page", "url": "https://www.suse.com/security/cve/CVE-2024-53214/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53215 page", "url": "https://www.suse.com/security/cve/CVE-2024-53215/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53216 page", "url": "https://www.suse.com/security/cve/CVE-2024-53216/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53217 page", "url": "https://www.suse.com/security/cve/CVE-2024-53217/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53222 page", "url": "https://www.suse.com/security/cve/CVE-2024-53222/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53224 page", "url": "https://www.suse.com/security/cve/CVE-2024-53224/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53229 page", "url": "https://www.suse.com/security/cve/CVE-2024-53229/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53234 page", "url": "https://www.suse.com/security/cve/CVE-2024-53234/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53237 page", "url": "https://www.suse.com/security/cve/CVE-2024-53237/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53240 page", "url": "https://www.suse.com/security/cve/CVE-2024-53240/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-53241 page", "url": "https://www.suse.com/security/cve/CVE-2024-53241/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56536 page", "url": "https://www.suse.com/security/cve/CVE-2024-56536/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56539 page", "url": "https://www.suse.com/security/cve/CVE-2024-56539/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56549 page", "url": "https://www.suse.com/security/cve/CVE-2024-56549/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56551 page", "url": "https://www.suse.com/security/cve/CVE-2024-56551/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56562 page", "url": "https://www.suse.com/security/cve/CVE-2024-56562/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56566 page", "url": "https://www.suse.com/security/cve/CVE-2024-56566/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56567 page", "url": "https://www.suse.com/security/cve/CVE-2024-56567/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56576 page", "url": "https://www.suse.com/security/cve/CVE-2024-56576/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56582 page", "url": "https://www.suse.com/security/cve/CVE-2024-56582/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56599 page", "url": "https://www.suse.com/security/cve/CVE-2024-56599/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56604 page", "url": "https://www.suse.com/security/cve/CVE-2024-56604/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56605 page", "url": "https://www.suse.com/security/cve/CVE-2024-56605/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56645 page", "url": "https://www.suse.com/security/cve/CVE-2024-56645/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56667 page", "url": "https://www.suse.com/security/cve/CVE-2024-56667/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56752 page", "url": "https://www.suse.com/security/cve/CVE-2024-56752/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56754 page", "url": "https://www.suse.com/security/cve/CVE-2024-56754/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56755 page", "url": "https://www.suse.com/security/cve/CVE-2024-56755/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-56756 page", "url": "https://www.suse.com/security/cve/CVE-2024-56756/" }, { "category": "self", "summary": "SUSE CVE CVE-2024-8805 page", "url": "https://www.suse.com/security/cve/CVE-2024-8805/" } ], "title": "Security update for the Linux Kernel", "tracking": { "current_release_date": "2025-01-15T09:07:49Z", "generator": { "date": "2025-01-15T09:07:49Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2025:0117-1", "initial_release_date": "2025-01-15T09:07:49Z", "revision_history": [ { "date": "2025-01-15T09:07:49Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kernel-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "kernel-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "product_id": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "product_id": "kernel-azure-extra-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "product_id": "kernel-azure-optional-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64" } }, { "category": "product_version", "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "product_id": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "product": { "name": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "product_id": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch" } }, { "category": "product_version", "name": "kernel-source-azure-6.4.0-150600.8.23.1.noarch", "product": { "name": "kernel-source-azure-6.4.0-150600.8.23.1.noarch", "product_id": "kernel-source-azure-6.4.0-150600.8.23.1.noarch" } } ], "category": "architecture", "name": "noarch" }, { "branches": [ { "category": "product_version", "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-azure-extra-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-azure-optional-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64" } }, { "category": "product_version", "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64", "product_id": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product": { "name": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-public-cloud:15:sp6" } } }, { "category": "product_name", "name": "openSUSE Leap 15.6", "product": { "name": "openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.6" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.23.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.23.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch" }, "product_reference": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-source-azure-6.4.0-150600.8.23.1.noarch as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch" }, "product_reference": "kernel-source-azure-6.4.0-150600.8.23.1.noarch", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64 as component of SUSE Linux Enterprise Module for Public Cloud 15 SP6", "product_id": "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for Public Cloud 15 SP6" }, { "category": "default_component_of", "full_product_name": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-extra-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-extra-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-optional-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-optional-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch" }, "product_reference": "kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-source-azure-6.4.0-150600.8.23.1.noarch as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch" }, "product_reference": "kernel-source-azure-6.4.0-150600.8.23.1.noarch", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64" }, "product_reference": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.6" }, { "category": "default_component_of", "full_product_name": { "name": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64 as component of openSUSE Leap 15.6", "product_id": "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" }, "product_reference": "reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.6" } ] }, "vulnerabilities": [ { "cve": "CVE-2024-26924", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-26924" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo: do not free live element\n\nPablo reports a crash with large batches of elements with a\nback-to-back add/remove pattern. Quoting Pablo:\n\n add_elem(\"00000000\") timeout 100 ms\n ...\n add_elem(\"0000000X\") timeout 100 ms\n del_elem(\"0000000X\") \u003c---------------- delete one that was just added\n ...\n add_elem(\"00005000\") timeout 100 ms\n\n 1) nft_pipapo_remove() removes element 0000000X\n Then, KASAN shows a splat.\n\nLooking at the remove function there is a chance that we will drop a\nrule that maps to a non-deactivated element.\n\nRemoval happens in two steps, first we do a lookup for key k and return the\nto-be-removed element and mark it as inactive in the next generation.\nThen, in a second step, the element gets removed from the set/map.\n\nThe _remove function does not work correctly if we have more than one\nelement that share the same key.\n\nThis can happen if we insert an element into a set when the set already\nholds an element with same key, but the element mapping to the existing\nkey has timed out or is not active in the next generation.\n\nIn such case its possible that removal will unmap the wrong element.\nIf this happens, we will leak the non-deactivated element, it becomes\nunreachable.\n\nThe element that got deactivated (and will be freed later) will\nremain reachable in the set data structure, this can result in\na crash when such an element is retrieved during lookup (stale\npointer).\n\nAdd a check that the fully matching key does in fact map to the element\nthat we have marked as inactive in the deactivation step.\nIf not, we need to continue searching.\n\nAdd a bug/warn trap at the end of the function as well, the remove\nfunction must not ever be called with an invisible/unreachable/non-existent\nelement.\n\nv2: avoid uneeded temporary variable (Stefano)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-26924", "url": "https://www.suse.com/security/cve/CVE-2024-26924" }, { "category": "external", "summary": "SUSE Bug 1223387 for CVE-2024-26924", "url": "https://bugzilla.suse.com/1223387" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-26924" }, { "cve": "CVE-2024-27397", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-27397" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: use timestamp to check for set element timeout\n\nAdd a timestamp field at the beginning of the transaction, store it\nin the nftables per-netns area.\n\nUpdate set backend .insert, .deactivate and sync gc path to use the\ntimestamp, this avoids that an element expires while control plane\ntransaction is still unfinished.\n\n.lookup and .update, which are used from packet path, still use the\ncurrent time to check if the element has expired. And .get path and dump\nalso since this runs lockless under rcu read size lock. Then, there is\nasync gc which also needs to check the current time since it runs\nasynchronously from a workqueue.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-27397", "url": "https://www.suse.com/security/cve/CVE-2024-27397" }, { "category": "external", "summary": "SUSE Bug 1224095 for CVE-2024-27397", "url": "https://bugzilla.suse.com/1224095" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-27397" }, { "cve": "CVE-2024-35839", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-35839" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: replace physindev with physinif in nf_bridge_info\n\nAn skb can be added to a neigh-\u003earp_queue while waiting for an arp\nreply. Where original skb\u0027s skb-\u003edev can be different to neigh\u0027s\nneigh-\u003edev. For instance in case of bridging dnated skb from one veth to\nanother, the skb would be added to a neigh-\u003earp_queue of the bridge.\n\nAs skb-\u003edev can be reset back to nf_bridge-\u003ephysindev and used, and as\nthere is no explicit mechanism that prevents this physindev from been\nfreed under us (for instance neigh_flush_dev doesn\u0027t cleanup skbs from\ndifferent device\u0027s neigh queue) we can crash on e.g. this stack:\n\narp_process\n neigh_update\n skb = __skb_dequeue(\u0026neigh-\u003earp_queue)\n neigh_resolve_output(..., skb)\n ...\n br_nf_dev_xmit\n br_nf_pre_routing_finish_bridge_slow\n skb-\u003edev = nf_bridge-\u003ephysindev\n br_handle_frame_finish\n\nLet\u0027s use plain ifindex instead of net_device link. To peek into the\noriginal net_device we will use dev_get_by_index_rcu(). Thus either we\nget device and are safe to use it or we don\u0027t get it and drop skb.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-35839", "url": "https://www.suse.com/security/cve/CVE-2024-35839" }, { "category": "external", "summary": "SUSE Bug 1224726 for CVE-2024-35839", "url": "https://bugzilla.suse.com/1224726" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-35839" }, { "cve": "CVE-2024-36908", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36908" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-iocost: do not WARN if iocg was already offlined\n\nIn iocg_pay_debt(), warn is triggered if \u0027active_list\u0027 is empty, which\nis intended to confirm iocg is active when it has debt. However, warn\ncan be triggered during a blkcg or disk removal, if iocg_waitq_timer_fn()\nis run at that time:\n\n WARNING: CPU: 0 PID: 2344971 at block/blk-iocost.c:1402 iocg_pay_debt+0x14c/0x190\n Call trace:\n iocg_pay_debt+0x14c/0x190\n iocg_kick_waitq+0x438/0x4c0\n iocg_waitq_timer_fn+0xd8/0x130\n __run_hrtimer+0x144/0x45c\n __hrtimer_run_queues+0x16c/0x244\n hrtimer_interrupt+0x2cc/0x7b0\n\nThe warn in this situation is meaningless. Since this iocg is being\nremoved, the state of the \u0027active_list\u0027 is irrelevant, and \u0027waitq_timer\u0027\nis canceled after removing \u0027active_list\u0027 in ioc_pd_free(), which ensures\niocg is freed after iocg_waitq_timer_fn() returns.\n\nTherefore, add the check if iocg was already offlined to avoid warn\nwhen removing a blkcg or disk.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36908", "url": "https://www.suse.com/security/cve/CVE-2024-36908" }, { "category": "external", "summary": "SUSE Bug 1225743 for CVE-2024-36908", "url": "https://bugzilla.suse.com/1225743" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-36908" }, { "cve": "CVE-2024-36915", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-36915" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: fix nfc_llcp_setsockopt() unsafe copies\n\nsyzbot reported unsafe calls to copy_from_sockptr() [1]\n\nUse copy_safe_from_sockptr() instead.\n\n[1]\n\nBUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]\n BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline]\n BUG: KASAN: slab-out-of-bounds in nfc_llcp_setsockopt+0x6c2/0x850 net/nfc/llcp_sock.c:255\nRead of size 4 at addr ffff88801caa1ec3 by task syz-executor459/5078\n\nCPU: 0 PID: 5078 Comm: syz-executor459 Not tainted 6.8.0-syzkaller-08951-gfe46a7dd189e #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n copy_from_sockptr_offset include/linux/sockptr.h:49 [inline]\n copy_from_sockptr include/linux/sockptr.h:55 [inline]\n nfc_llcp_setsockopt+0x6c2/0x850 net/nfc/llcp_sock.c:255\n do_sock_setsockopt+0x3b1/0x720 net/socket.c:2311\n __sys_setsockopt+0x1ae/0x250 net/socket.c:2334\n __do_sys_setsockopt net/socket.c:2343 [inline]\n __se_sys_setsockopt net/socket.c:2340 [inline]\n __x64_sys_setsockopt+0xb5/0xd0 net/socket.c:2340\n do_syscall_64+0xfd/0x240\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\nRIP: 0033:0x7f7fac07fd89\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 91 18 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 \u003c48\u003e 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fff660eb788 EFLAGS: 00000246 ORIG_RAX: 0000000000000036\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007f7fac07fd89\nRDX: 0000000000000000 RSI: 0000000000000118 RDI: 0000000000000004\nRBP: 0000000000000000 R08: 0000000000000002 R09: 0000000000000000\nR10: 0000000020000a80 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-36915", "url": "https://www.suse.com/security/cve/CVE-2024-36915" }, { "category": "external", "summary": "SUSE Bug 1225758 for CVE-2024-36915", "url": "https://bugzilla.suse.com/1225758" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-36915" }, { "cve": "CVE-2024-39480", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-39480" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nkdb: Fix buffer overflow during tab-complete\n\nCurrently, when the user attempts symbol completion with the Tab key, kdb\nwill use strncpy() to insert the completed symbol into the command buffer.\nUnfortunately it passes the size of the source buffer rather than the\ndestination to strncpy() with predictably horrible results. Most obviously\nif the command buffer is already full but cp, the cursor position, is in\nthe middle of the buffer, then we will write past the end of the supplied\nbuffer.\n\nFix this by replacing the dubious strncpy() calls with memmove()/memcpy()\ncalls plus explicit boundary checks to make sure we have enough space\nbefore we start moving characters around.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-39480", "url": "https://www.suse.com/security/cve/CVE-2024-39480" }, { "category": "external", "summary": "SUSE Bug 1227445 for CVE-2024-39480", "url": "https://bugzilla.suse.com/1227445" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-39480" }, { "cve": "CVE-2024-41042", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-41042" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: prefer nft_chain_validate\n\nnft_chain_validate already performs loop detection because a cycle will\nresult in a call stack overflow (ctx-\u003elevel \u003e= NFT_JUMP_STACK_SIZE).\n\nIt also follows maps via -\u003evalidate callback in nft_lookup, so there\nappears no reason to iterate the maps again.\n\nnf_tables_check_loops() and all its helper functions can be removed.\nThis improves ruleset load time significantly, from 23s down to 12s.\n\nThis also fixes a crash bug. Old loop detection code can result in\nunbounded recursion:\n\nBUG: TASK stack guard page was hit at ....\nOops: stack guard page: 0000 [#1] PREEMPT SMP KASAN\nCPU: 4 PID: 1539 Comm: nft Not tainted 6.10.0-rc5+ #1\n[..]\n\nwith a suitable ruleset during validation of register stores.\n\nI can\u0027t see any actual reason to attempt to check for this from\nnft_validate_register_store(), at this point the transaction is still in\nprogress, so we don\u0027t have a full picture of the rule graph.\n\nFor nf-next it might make sense to either remove it or make this depend\non table-\u003evalidate_state in case we could catch an error earlier\n(for improved error reporting to userspace).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-41042", "url": "https://www.suse.com/security/cve/CVE-2024-41042" }, { "category": "external", "summary": "SUSE Bug 1228526 for CVE-2024-41042", "url": "https://bugzilla.suse.com/1228526" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-41042" }, { "cve": "CVE-2024-44934", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-44934" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: mcast: wait for previous gc cycles when removing port\n\nsyzbot hit a use-after-free[1] which is caused because the bridge doesn\u0027t\nmake sure that all previous garbage has been collected when removing a\nport. What happens is:\n CPU 1 CPU 2\n start gc cycle remove port\n acquire gc lock first\n wait for lock\n call br_multicasg_gc() directly\n acquire lock now but free port\n the port can be freed\n while grp timers still\n running\n\nMake sure all previous gc cycles have finished by using flush_work before\nfreeing the port.\n\n[1]\n BUG: KASAN: slab-use-after-free in br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n Read of size 8 at addr ffff888071d6d000 by task syz.5.1232/9699\n\n CPU: 1 PID: 9699 Comm: syz.5.1232 Not tainted 6.10.0-rc5-syzkaller-00021-g24ca36a562d6 #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/07/2024\n Call Trace:\n \u003cIRQ\u003e\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n br_multicast_port_group_expired+0x4c0/0x550 net/bridge/br_multicast.c:861\n call_timer_fn+0x1a3/0x610 kernel/time/timer.c:1792\n expire_timers kernel/time/timer.c:1843 [inline]\n __run_timers+0x74b/0xaf0 kernel/time/timer.c:2417\n __run_timer_base kernel/time/timer.c:2428 [inline]\n __run_timer_base kernel/time/timer.c:2421 [inline]\n run_timer_base+0x111/0x190 kernel/time/timer.c:2437", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-44934", "url": "https://www.suse.com/security/cve/CVE-2024-44934" }, { "category": "external", "summary": "SUSE Bug 1229809 for CVE-2024-44934", "url": "https://bugzilla.suse.com/1229809" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-44934" }, { "cve": "CVE-2024-44996", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-44996" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: fix recursive -\u003erecvmsg calls\n\nAfter a vsock socket has been added to a BPF sockmap, its prot-\u003erecvmsg\nhas been replaced with vsock_bpf_recvmsg(). Thus the following\nrecursiion could happen:\n\nvsock_bpf_recvmsg()\n -\u003e __vsock_recvmsg()\n -\u003e vsock_connectible_recvmsg()\n -\u003e prot-\u003erecvmsg()\n -\u003e vsock_bpf_recvmsg() again\n\nWe need to fix it by calling the original -\u003erecvmsg() without any BPF\nsockmap logic in __vsock_recvmsg().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-44996", "url": "https://www.suse.com/security/cve/CVE-2024-44996" }, { "category": "external", "summary": "SUSE Bug 1230205 for CVE-2024-44996", "url": "https://bugzilla.suse.com/1230205" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-44996" }, { "cve": "CVE-2024-47678", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-47678" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nicmp: change the order of rate limits\n\nICMP messages are ratelimited :\n\nAfter the blamed commits, the two rate limiters are applied in this order:\n\n1) host wide ratelimit (icmp_global_allow())\n\n2) Per destination ratelimit (inetpeer based)\n\nIn order to avoid side-channels attacks, we need to apply\nthe per destination check first.\n\nThis patch makes the following change :\n\n1) icmp_global_allow() checks if the host wide limit is reached.\n But credits are not yet consumed. This is deferred to 3)\n\n2) The per destination limit is checked/updated.\n This might add a new node in inetpeer tree.\n\n3) icmp_global_consume() consumes tokens if prior operations succeeded.\n\nThis means that host wide ratelimit is still effective\nin keeping inetpeer tree small even under DDOS.\n\nAs a bonus, I removed icmp_global.lock as the fast path\ncan use a lock-free operation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-47678", "url": "https://www.suse.com/security/cve/CVE-2024-47678" }, { "category": "external", "summary": "SUSE Bug 1231854 for CVE-2024-47678", "url": "https://bugzilla.suse.com/1231854" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-47678" }, { "cve": "CVE-2024-49854", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49854" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix uaf for accessing waker_bfqq after splitting\n\nAfter commit 42c306ed7233 (\"block, bfq: don\u0027t break merge chain in\nbfq_split_bfqq()\"), if the current procress is the last holder of bfqq,\nthe bfqq can be freed after bfq_split_bfqq(). Hence recored the bfqq and\nthen access bfqq-\u003ewaker_bfqq may trigger UAF. What\u0027s more, the waker_bfqq\nmay in the merge chain of bfqq, hence just recored waker_bfqq is still\nnot safe.\n\nFix the problem by adding a helper bfq_waker_bfqq() to check if\nbfqq-\u003ewaker_bfqq is in the merge chain, and current procress is the only\nholder.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49854", "url": "https://www.suse.com/security/cve/CVE-2024-49854" }, { "category": "external", "summary": "SUSE Bug 1232193 for CVE-2024-49854", "url": "https://bugzilla.suse.com/1232193" }, { "category": "external", "summary": "SUSE Bug 1236571 for CVE-2024-49854", "url": "https://bugzilla.suse.com/1236571" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-49854" }, { "cve": "CVE-2024-49884", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49884" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix slab-use-after-free in ext4_split_extent_at()\n\nWe hit the following use-after-free:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_split_extent_at+0xba8/0xcc0\nRead of size 2 at addr ffff88810548ed08 by task kworker/u20:0/40\nCPU: 0 PID: 40 Comm: kworker/u20:0 Not tainted 6.9.0-dirty #724\nCall Trace:\n \u003cTASK\u003e\n kasan_report+0x93/0xc0\n ext4_split_extent_at+0xba8/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nAllocated by task 40:\n __kmalloc_noprof+0x1ac/0x480\n ext4_find_extent+0xf3b/0x1e70\n ext4_ext_map_blocks+0x188/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nFreed by task 40:\n kfree+0xf1/0x2b0\n ext4_find_extent+0xa71/0x1e70\n ext4_ext_insert_extent+0xa22/0x3260\n ext4_split_extent_at+0x3ef/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n==================================================================\n\nThe flow of issue triggering is as follows:\n\next4_split_extent_at\n path = *ppath\n ext4_ext_insert_extent(ppath)\n ext4_ext_create_new_leaf(ppath)\n ext4_find_extent(orig_path)\n path = *orig_path\n read_extent_tree_block\n // return -ENOMEM or -EIO\n ext4_free_ext_path(path)\n kfree(path)\n *orig_path = NULL\n a. If err is -ENOMEM:\n ext4_ext_dirty(path + path-\u003ep_depth)\n // path use-after-free !!!\n b. If err is -EIO and we have EXT_DEBUG defined:\n ext4_ext_show_leaf(path)\n eh = path[depth].p_hdr\n // path also use-after-free !!!\n\nSo when trying to zeroout or fix the extent length, call ext4_find_extent()\nto update the path.\n\nIn addition we use *ppath directly as an ext4_ext_show_leaf() input to\navoid possible use-after-free when EXT_DEBUG is defined, and to avoid\nunnecessary path updates.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49884", "url": "https://www.suse.com/security/cve/CVE-2024-49884" }, { "category": "external", "summary": "SUSE Bug 1225742 for CVE-2024-49884", "url": "https://bugzilla.suse.com/1225742" }, { "category": "external", "summary": "SUSE Bug 1232198 for CVE-2024-49884", "url": "https://bugzilla.suse.com/1232198" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-49884" }, { "cve": "CVE-2024-49915", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-49915" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn32_init_hw` function. The issue could occur when `dc-\u003eclk_mgr` is\nnull.\n\nThe fix adds a check to ensure `dc-\u003eclk_mgr` is not null before\naccessing its functions. This prevents a potential null pointer\ndereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn32/dcn32_hwseq.c:961 dcn32_init_hw() error: we previously assumed \u0027dc-\u003eclk_mgr\u0027 could be null (see line 782)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-49915", "url": "https://www.suse.com/security/cve/CVE-2024-49915" }, { "category": "external", "summary": "SUSE Bug 1231963 for CVE-2024-49915", "url": "https://bugzilla.suse.com/1231963" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-49915" }, { "cve": "CVE-2024-50016", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50016" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50016", "url": "https://www.suse.com/security/cve/CVE-2024-50016" }, { "category": "external", "summary": "SUSE Bug 1232420 for CVE-2024-50016", "url": "https://bugzilla.suse.com/1232420" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50016" }, { "cve": "CVE-2024-50018", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50018" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50018", "url": "https://www.suse.com/security/cve/CVE-2024-50018" }, { "category": "external", "summary": "SUSE Bug 1232419 for CVE-2024-50018", "url": "https://bugzilla.suse.com/1232419" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50018" }, { "cve": "CVE-2024-50039", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50039" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: accept TCA_STAB only for root qdisc\n\nMost qdiscs maintain their backlog using qdisc_pkt_len(skb)\non the assumption it is invariant between the enqueue()\nand dequeue() handlers.\n\nUnfortunately syzbot can crash a host rather easily using\na TBF + SFQ combination, with an STAB on SFQ [1]\n\nWe can\u0027t support TCA_STAB on arbitrary level, this would\nrequire to maintain per-qdisc storage.\n\n[1]\n[ 88.796496] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 88.798611] #PF: supervisor read access in kernel mode\n[ 88.799014] #PF: error_code(0x0000) - not-present page\n[ 88.799506] PGD 0 P4D 0\n[ 88.799829] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 88.800569] CPU: 14 UID: 0 PID: 2053 Comm: b371744477 Not tainted 6.12.0-rc1-virtme #1117\n[ 88.801107] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 88.801779] RIP: 0010:sfq_dequeue (net/sched/sch_sfq.c:272 net/sched/sch_sfq.c:499) sch_sfq\n[ 88.802544] Code: 0f b7 50 12 48 8d 04 d5 00 00 00 00 48 89 d6 48 29 d0 48 8b 91 c0 01 00 00 48 c1 e0 03 48 01 c2 66 83 7a 1a 00 7e c0 48 8b 3a \u003c4c\u003e 8b 07 4c 89 02 49 89 50 08 48 c7 47 08 00 00 00 00 48 c7 07 00\nAll code\n========\n 0:\t0f b7 50 12 \tmovzwl 0x12(%rax),%edx\n 4:\t48 8d 04 d5 00 00 00 \tlea 0x0(,%rdx,8),%rax\n b:\t00\n c:\t48 89 d6 \tmov %rdx,%rsi\n f:\t48 29 d0 \tsub %rdx,%rax\n 12:\t48 8b 91 c0 01 00 00 \tmov 0x1c0(%rcx),%rdx\n 19:\t48 c1 e0 03 \tshl $0x3,%rax\n 1d:\t48 01 c2 \tadd %rax,%rdx\n 20:\t66 83 7a 1a 00 \tcmpw $0x0,0x1a(%rdx)\n 25:\t7e c0 \tjle 0xffffffffffffffe7\n 27:\t48 8b 3a \tmov (%rdx),%rdi\n 2a:*\t4c 8b 07 \tmov (%rdi),%r8\t\t\u003c-- trapping instruction\n 2d:\t4c 89 02 \tmov %r8,(%rdx)\n 30:\t49 89 50 08 \tmov %rdx,0x8(%r8)\n 34:\t48 c7 47 08 00 00 00 \tmovq $0x0,0x8(%rdi)\n 3b:\t00\n 3c:\t48 \trex.W\n 3d:\tc7 \t.byte 0xc7\n 3e:\t07 \t(bad)\n\t...\n\nCode starting with the faulting instruction\n===========================================\n 0:\t4c 8b 07 \tmov (%rdi),%r8\n 3:\t4c 89 02 \tmov %r8,(%rdx)\n 6:\t49 89 50 08 \tmov %rdx,0x8(%r8)\n a:\t48 c7 47 08 00 00 00 \tmovq $0x0,0x8(%rdi)\n 11:\t00\n 12:\t48 \trex.W\n 13:\tc7 \t.byte 0xc7\n 14:\t07 \t(bad)\n\t...\n[ 88.803721] RSP: 0018:ffff9a1f892b7d58 EFLAGS: 00000206\n[ 88.804032] RAX: 0000000000000000 RBX: ffff9a1f8420c800 RCX: ffff9a1f8420c800\n[ 88.804560] RDX: ffff9a1f81bc1440 RSI: 0000000000000000 RDI: 0000000000000000\n[ 88.805056] RBP: ffffffffc04bb0e0 R08: 0000000000000001 R09: 00000000ff7f9a1f\n[ 88.805473] R10: 000000000001001b R11: 0000000000009a1f R12: 0000000000000140\n[ 88.806194] R13: 0000000000000001 R14: ffff9a1f886df400 R15: ffff9a1f886df4ac\n[ 88.806734] FS: 00007f445601a740(0000) GS:ffff9a2e7fd80000(0000) knlGS:0000000000000000\n[ 88.807225] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 88.807672] CR2: 0000000000000000 CR3: 000000050cc46000 CR4: 00000000000006f0\n[ 88.808165] Call Trace:\n[ 88.808459] \u003cTASK\u003e\n[ 88.808710] ? __die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434)\n[ 88.809261] ? page_fault_oops (arch/x86/mm/fault.c:715)\n[ 88.809561] ? exc_page_fault (./arch/x86/include/asm/irqflags.h:26 ./arch/x86/include/asm/irqflags.h:87 ./arch/x86/include/asm/irqflags.h:147 arch/x86/mm/fault.c:1489 arch/x86/mm/fault.c:1539)\n[ 88.809806] ? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:623)\n[ 88.810074] ? sfq_dequeue (net/sched/sch_sfq.c:272 net/sched/sch_sfq.c:499) sch_sfq\n[ 88.810411] sfq_reset (net/sched/sch_sfq.c:525) sch_sfq\n[ 88.810671] qdisc_reset (./include/linux/skbuff.h:2135 ./include/linux/skbuff.h:2441 ./include/linux/skbuff.h:3304 ./include/linux/skbuff.h:3310 net/sched/sch_g\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50039", "url": "https://www.suse.com/security/cve/CVE-2024-50039" }, { "category": "external", "summary": "SUSE Bug 1231909 for CVE-2024-50039", "url": "https://bugzilla.suse.com/1231909" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50039" }, { "cve": "CVE-2024-50047", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50047" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in async decryption\n\nDoing an async decryption (large read) crashes with a\nslab-use-after-free way down in the crypto API.\n\nReproducer:\n # mount.cifs -o ...,seal,esize=1 //srv/share /mnt\n # dd if=/mnt/largefile of=/dev/null\n ...\n [ 194.196391] ==================================================================\n [ 194.196844] BUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xc1/0x110\n [ 194.197269] Read of size 8 at addr ffff888112bd0448 by task kworker/u77:2/899\n [ 194.197707]\n [ 194.197818] CPU: 12 UID: 0 PID: 899 Comm: kworker/u77:2 Not tainted 6.11.0-lku-00028-gfca3ca14a17a-dirty #43\n [ 194.198400] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.2-3-gd478f380-prebuilt.qemu.org 04/01/2014\n [ 194.199046] Workqueue: smb3decryptd smb2_decrypt_offload [cifs]\n [ 194.200032] Call Trace:\n [ 194.200191] \u003cTASK\u003e\n [ 194.200327] dump_stack_lvl+0x4e/0x70\n [ 194.200558] ? gf128mul_4k_lle+0xc1/0x110\n [ 194.200809] print_report+0x174/0x505\n [ 194.201040] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n [ 194.201352] ? srso_return_thunk+0x5/0x5f\n [ 194.201604] ? __virt_addr_valid+0xdf/0x1c0\n [ 194.201868] ? gf128mul_4k_lle+0xc1/0x110\n [ 194.202128] kasan_report+0xc8/0x150\n [ 194.202361] ? gf128mul_4k_lle+0xc1/0x110\n [ 194.202616] gf128mul_4k_lle+0xc1/0x110\n [ 194.202863] ghash_update+0x184/0x210\n [ 194.203103] shash_ahash_update+0x184/0x2a0\n [ 194.203377] ? __pfx_shash_ahash_update+0x10/0x10\n [ 194.203651] ? srso_return_thunk+0x5/0x5f\n [ 194.203877] ? crypto_gcm_init_common+0x1ba/0x340\n [ 194.204142] gcm_hash_assoc_remain_continue+0x10a/0x140\n [ 194.204434] crypt_message+0xec1/0x10a0 [cifs]\n [ 194.206489] ? __pfx_crypt_message+0x10/0x10 [cifs]\n [ 194.208507] ? srso_return_thunk+0x5/0x5f\n [ 194.209205] ? srso_return_thunk+0x5/0x5f\n [ 194.209925] ? srso_return_thunk+0x5/0x5f\n [ 194.210443] ? srso_return_thunk+0x5/0x5f\n [ 194.211037] decrypt_raw_data+0x15f/0x250 [cifs]\n [ 194.212906] ? __pfx_decrypt_raw_data+0x10/0x10 [cifs]\n [ 194.214670] ? srso_return_thunk+0x5/0x5f\n [ 194.215193] smb2_decrypt_offload+0x12a/0x6c0 [cifs]\n\nThis is because TFM is being used in parallel.\n\nFix this by allocating a new AEAD TFM for async decryption, but keep\nthe existing one for synchronous READ cases (similar to what is done\nin smb3_calc_signature()).\n\nAlso remove the calls to aead_request_set_callback() and\ncrypto_wait_req() since it\u0027s always going to be a synchronous operation.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50047", "url": "https://www.suse.com/security/cve/CVE-2024-50047" }, { "category": "external", "summary": "SUSE Bug 1232418 for CVE-2024-50047", "url": "https://bugzilla.suse.com/1232418" }, { "category": "external", "summary": "SUSE Bug 1232576 for CVE-2024-50047", "url": "https://bugzilla.suse.com/1232576" }, { "category": "external", "summary": "SUSE Bug 1232638 for CVE-2024-50047", "url": "https://bugzilla.suse.com/1232638" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-50047" }, { "cve": "CVE-2024-50143", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50143" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: fix uninit-value use in udf_get_fileshortad\n\nCheck for overflow when computing alen in udf_current_aext to mitigate\nlater uninit-value use in udf_get_fileshortad KMSAN bug[1].\nAfter applying the patch reproducer did not trigger any issue[2].\n\n[1] https://syzkaller.appspot.com/bug?extid=8901c4560b7ab5c2f9df\n[2] https://syzkaller.appspot.com/x/log.txt?x=10242227980000", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50143", "url": "https://www.suse.com/security/cve/CVE-2024-50143" }, { "category": "external", "summary": "SUSE Bug 1233038 for CVE-2024-50143", "url": "https://bugzilla.suse.com/1233038" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50143" }, { "cve": "CVE-2024-50154", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50154" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp/dccp: Don\u0027t use timer_pending() in reqsk_queue_unlink().\n\nMartin KaFai Lau reported use-after-free [0] in reqsk_timer_handler().\n\n \"\"\"\n We are seeing a use-after-free from a bpf prog attached to\n trace_tcp_retransmit_synack. The program passes the req-\u003esk to the\n bpf_sk_storage_get_tracing kernel helper which does check for null\n before using it.\n \"\"\"\n\nThe commit 83fccfc3940c (\"inet: fix potential deadlock in\nreqsk_queue_unlink()\") added timer_pending() in reqsk_queue_unlink() not\nto call del_timer_sync() from reqsk_timer_handler(), but it introduced a\nsmall race window.\n\nBefore the timer is called, expire_timers() calls detach_timer(timer, true)\nto clear timer-\u003eentry.pprev and marks it as not pending.\n\nIf reqsk_queue_unlink() checks timer_pending() just after expire_timers()\ncalls detach_timer(), TCP will miss del_timer_sync(); the reqsk timer will\ncontinue running and send multiple SYN+ACKs until it expires.\n\nThe reported UAF could happen if req-\u003esk is close()d earlier than the timer\nexpiration, which is 63s by default.\n\nThe scenario would be\n\n 1. inet_csk_complete_hashdance() calls inet_csk_reqsk_queue_drop(),\n but del_timer_sync() is missed\n\n 2. reqsk timer is executed and scheduled again\n\n 3. req-\u003esk is accept()ed and reqsk_put() decrements rsk_refcnt, but\n reqsk timer still has another one, and inet_csk_accept() does not\n clear req-\u003esk for non-TFO sockets\n\n 4. sk is close()d\n\n 5. reqsk timer is executed again, and BPF touches req-\u003esk\n\nLet\u0027s not use timer_pending() by passing the caller context to\n__inet_csk_reqsk_queue_drop().\n\nNote that reqsk timer is pinned, so the issue does not happen in most\nuse cases. [1]\n\n[0]\nBUG: KFENCE: use-after-free read in bpf_sk_storage_get_tracing+0x2e/0x1b0\n\nUse-after-free read at 0x00000000a891fb3a (in kfence-#1):\nbpf_sk_storage_get_tracing+0x2e/0x1b0\nbpf_prog_5ea3e95db6da0438_tcp_retransmit_synack+0x1d20/0x1dda\nbpf_trace_run2+0x4c/0xc0\ntcp_rtx_synack+0xf9/0x100\nreqsk_timer_handler+0xda/0x3d0\nrun_timer_softirq+0x292/0x8a0\nirq_exit_rcu+0xf5/0x320\nsysvec_apic_timer_interrupt+0x6d/0x80\nasm_sysvec_apic_timer_interrupt+0x16/0x20\nintel_idle_irq+0x5a/0xa0\ncpuidle_enter_state+0x94/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb\n\nkfence-#1: 0x00000000a72cc7b6-0x00000000d97616d9, size=2376, cache=TCPv6\n\nallocated by task 0 on cpu 9 at 260507.901592s:\nsk_prot_alloc+0x35/0x140\nsk_clone_lock+0x1f/0x3f0\ninet_csk_clone_lock+0x15/0x160\ntcp_create_openreq_child+0x1f/0x410\ntcp_v6_syn_recv_sock+0x1da/0x700\ntcp_check_req+0x1fb/0x510\ntcp_v6_rcv+0x98b/0x1420\nipv6_list_rcv+0x2258/0x26e0\nnapi_complete_done+0x5b1/0x2990\nmlx5e_napi_poll+0x2ae/0x8d0\nnet_rx_action+0x13e/0x590\nirq_exit_rcu+0xf5/0x320\ncommon_interrupt+0x80/0x90\nasm_common_interrupt+0x22/0x40\ncpuidle_enter_state+0xfb/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb\n\nfreed by task 0 on cpu 9 at 260507.927527s:\nrcu_core_si+0x4ff/0xf10\nirq_exit_rcu+0xf5/0x320\nsysvec_apic_timer_interrupt+0x6d/0x80\nasm_sysvec_apic_timer_interrupt+0x16/0x20\ncpuidle_enter_state+0xfb/0x273\ncpu_startup_entry+0x15e/0x260\nstart_secondary+0x8a/0x90\nsecondary_startup_64_no_verify+0xfa/0xfb", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50154", "url": "https://www.suse.com/security/cve/CVE-2024-50154" }, { "category": "external", "summary": "SUSE Bug 1233070 for CVE-2024-50154", "url": "https://bugzilla.suse.com/1233070" }, { "category": "external", "summary": "SUSE Bug 1233072 for CVE-2024-50154", "url": "https://bugzilla.suse.com/1233072" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-50154" }, { "cve": "CVE-2024-50202", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50202" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: propagate directory read errors from nilfs_find_entry()\n\nSyzbot reported that a task hang occurs in vcs_open() during a fuzzing\ntest for nilfs2.\n\nThe root cause of this problem is that in nilfs_find_entry(), which\nsearches for directory entries, ignores errors when loading a directory\npage/folio via nilfs_get_folio() fails.\n\nIf the filesystem images is corrupted, and the i_size of the directory\ninode is large, and the directory page/folio is successfully read but\nfails the sanity check, for example when it is zero-filled,\nnilfs_check_folio() may continue to spit out error messages in bursts.\n\nFix this issue by propagating the error to the callers when loading a\npage/folio fails in nilfs_find_entry().\n\nThe current interface of nilfs_find_entry() and its callers is outdated\nand cannot propagate error codes such as -EIO and -ENOMEM returned via\nnilfs_find_entry(), so fix it together.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50202", "url": "https://www.suse.com/security/cve/CVE-2024-50202" }, { "category": "external", "summary": "SUSE Bug 1233324 for CVE-2024-50202", "url": "https://bugzilla.suse.com/1233324" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50202" }, { "cve": "CVE-2024-50203", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50203" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, arm64: Fix address emission with tag-based KASAN enabled\n\nWhen BPF_TRAMP_F_CALL_ORIG is enabled, the address of a bpf_tramp_image\nstruct on the stack is passed during the size calculation pass and\nan address on the heap is passed during code generation. This may\ncause a heap buffer overflow if the heap address is tagged because\nemit_a64_mov_i64() will emit longer code than it did during the size\ncalculation pass. The same problem could occur without tag-based\nKASAN if one of the 16-bit words of the stack address happened to\nbe all-ones during the size calculation pass. Fix the problem by\nassuming the worst case (4 instructions) when calculating the size\nof the bpf_tramp_image address emission.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50203", "url": "https://www.suse.com/security/cve/CVE-2024-50203" }, { "category": "external", "summary": "SUSE Bug 1233328 for CVE-2024-50203", "url": "https://bugzilla.suse.com/1233328" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50203" }, { "cve": "CVE-2024-50211", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50211" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: refactor inode_bmap() to handle error\n\nRefactor inode_bmap() to handle error since udf_next_aext() can return\nerror now. On situations like ftruncate, udf_extend_file() can now\ndetect errors and bail out early without resorting to checking for\nparticular offsets and assuming internal behavior of these functions.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50211", "url": "https://www.suse.com/security/cve/CVE-2024-50211" }, { "category": "external", "summary": "SUSE Bug 1233096 for CVE-2024-50211", "url": "https://bugzilla.suse.com/1233096" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50211" }, { "cve": "CVE-2024-50228", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50228" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50228", "url": "https://www.suse.com/security/cve/CVE-2024-50228" }, { "category": "external", "summary": "SUSE Bug 1233204 for CVE-2024-50228", "url": "https://bugzilla.suse.com/1233204" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50228" }, { "cve": "CVE-2024-50256", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50256" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()\n\nI got a syzbot report without a repro [1] crashing in nf_send_reset6()\n\nI think the issue is that dev-\u003ehard_header_len is zero, and we attempt\nlater to push an Ethernet header.\n\nUse LL_MAX_HEADER, as other functions in net/ipv6/netfilter/nf_reject_ipv6.c.\n\n[1]\n\nskbuff: skb_under_panic: text:ffffffff89b1d008 len:74 put:14 head:ffff88803123aa00 data:ffff88803123a9f2 tail:0x3c end:0x140 dev:syz_tun\n kernel BUG at net/core/skbuff.c:206 !\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 0 UID: 0 PID: 7373 Comm: syz.1.568 Not tainted 6.12.0-rc2-syzkaller-00631-g6d858708d465 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n RIP: 0010:skb_panic net/core/skbuff.c:206 [inline]\n RIP: 0010:skb_under_panic+0x14b/0x150 net/core/skbuff.c:216\nCode: 0d 8d 48 c7 c6 60 a6 29 8e 48 8b 54 24 08 8b 0c 24 44 8b 44 24 04 4d 89 e9 50 41 54 41 57 41 56 e8 ba 30 38 02 48 83 c4 20 90 \u003c0f\u003e 0b 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3\nRSP: 0018:ffffc900045269b0 EFLAGS: 00010282\nRAX: 0000000000000088 RBX: dffffc0000000000 RCX: cd66dacdc5d8e800\nRDX: 0000000000000000 RSI: 0000000000000200 RDI: 0000000000000000\nRBP: ffff88802d39a3d0 R08: ffffffff8174afec R09: 1ffff920008a4ccc\nR10: dffffc0000000000 R11: fffff520008a4ccd R12: 0000000000000140\nR13: ffff88803123aa00 R14: ffff88803123a9f2 R15: 000000000000003c\nFS: 00007fdbee5ff6c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000005d322000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \u003cTASK\u003e\n skb_push+0xe5/0x100 net/core/skbuff.c:2636\n eth_header+0x38/0x1f0 net/ethernet/eth.c:83\n dev_hard_header include/linux/netdevice.h:3208 [inline]\n nf_send_reset6+0xce6/0x1270 net/ipv6/netfilter/nf_reject_ipv6.c:358\n nft_reject_inet_eval+0x3b9/0x690 net/netfilter/nft_reject_inet.c:48\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x4ad/0x1da0 net/netfilter/nf_tables_core.c:288\n nft_do_chain_inet+0x418/0x6b0 net/netfilter/nft_chain_filter.c:161\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook include/linux/netfilter.h:269 [inline]\n NF_HOOK include/linux/netfilter.h:312 [inline]\n br_nf_pre_routing_ipv6+0x63e/0x770 net/bridge/br_netfilter_ipv6.c:184\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_bridge_pre net/bridge/br_input.c:277 [inline]\n br_handle_frame+0x9fd/0x1530 net/bridge/br_input.c:424\n __netif_receive_skb_core+0x13e8/0x4570 net/core/dev.c:5562\n __netif_receive_skb_one_core net/core/dev.c:5666 [inline]\n __netif_receive_skb+0x12f/0x650 net/core/dev.c:5781\n netif_receive_skb_internal net/core/dev.c:5867 [inline]\n netif_receive_skb+0x1e8/0x890 net/core/dev.c:5926\n tun_rx_batched+0x1b7/0x8f0 drivers/net/tun.c:1550\n tun_get_user+0x3056/0x47e0 drivers/net/tun.c:2007\n tun_chr_write_iter+0x10d/0x1f0 drivers/net/tun.c:2053\n new_sync_write fs/read_write.c:590 [inline]\n vfs_write+0xa6d/0xc90 fs/read_write.c:683\n ksys_write+0x183/0x2b0 fs/read_write.c:736\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fdbeeb7d1ff\nCode: 89 54 24 18 48 89 74 24 10 89 7c 24 08 e8 c9 8d 02 00 48 8b 54 24 18 48 8b 74 24 10 41 89 c0 8b 7c 24 08 b8 01 00 00 00 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 31 44 89 c7 48 89 44 24 08 e8 1c 8e 02 00 48\nRSP: 002b:00007fdbee5ff000 EFLAGS: 00000293 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007fdbeed36058 RCX: 00007fdbeeb7d1ff\nRDX: 000000000000008e RSI: 0000000020000040 RDI: 00000000000000c8\nRBP: 00007fdbeebf12be R08: 0000000\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50256", "url": "https://www.suse.com/security/cve/CVE-2024-50256" }, { "category": "external", "summary": "SUSE Bug 1233200 for CVE-2024-50256", "url": "https://bugzilla.suse.com/1233200" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50256" }, { "cve": "CVE-2024-50262", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50262" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix out-of-bounds write in trie_get_next_key()\n\ntrie_get_next_key() allocates a node stack with size trie-\u003emax_prefixlen,\nwhile it writes (trie-\u003emax_prefixlen + 1) nodes to the stack when it has\nfull paths from the root to leaves. For example, consider a trie with\nmax_prefixlen is 8, and the nodes with key 0x00/0, 0x00/1, 0x00/2, ...\n0x00/8 inserted. Subsequent calls to trie_get_next_key with _key with\n.prefixlen = 8 make 9 nodes be written on the node stack with size 8.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50262", "url": "https://www.suse.com/security/cve/CVE-2024-50262" }, { "category": "external", "summary": "SUSE Bug 1233239 for CVE-2024-50262", "url": "https://bugzilla.suse.com/1233239" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50262" }, { "cve": "CVE-2024-50272", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50272" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilemap: Fix bounds checking in filemap_read()\n\nIf the caller supplies an iocb-\u003eki_pos value that is close to the\nfilesystem upper limit, and an iterator with a count that causes us to\noverflow that limit, then filemap_read() enters an infinite loop.\n\nThis behaviour was discovered when testing xfstests generic/525 with the\n\"localio\" optimisation for loopback NFS mounts.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50272", "url": "https://www.suse.com/security/cve/CVE-2024-50272" }, { "category": "external", "summary": "SUSE Bug 1233461 for CVE-2024-50272", "url": "https://bugzilla.suse.com/1233461" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50272" }, { "cve": "CVE-2024-50278", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50278" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix potential out-of-bounds access on the first resume\n\nOut-of-bounds access occurs if the fast device is expanded unexpectedly\nbefore the first-time resume of the cache table. This happens because\nexpanding the fast device requires reloading the cache table for\ncache_create to allocate new in-core data structures that fit the new\nsize, and the check in cache_preresume is not performed during the\nfirst resume, leading to the issue.\n\nReproduce steps:\n\n1. prepare component devices:\n\ndmsetup create cmeta --table \"0 8192 linear /dev/sdc 0\"\ndmsetup create cdata --table \"0 65536 linear /dev/sdc 8192\"\ndmsetup create corig --table \"0 524288 linear /dev/sdc 262144\"\ndd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct\n\n2. load a cache table of 512 cache blocks, and deliberately expand the\n fast device before resuming the cache, making the in-core data\n structures inadequate.\n\ndmsetup create cache --notable\ndmsetup reload cache --table \"0 524288 cache /dev/mapper/cmeta \\\n/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0\"\ndmsetup reload cdata --table \"0 131072 linear /dev/sdc 8192\"\ndmsetup resume cdata\ndmsetup resume cache\n\n3. suspend the cache to write out the in-core dirty bitset and hint\n array, leading to out-of-bounds access to the dirty bitset at offset\n 0x40:\n\ndmsetup suspend cache\n\nKASAN reports:\n\n BUG: KASAN: vmalloc-out-of-bounds in is_dirty_callback+0x2b/0x80\n Read of size 8 at addr ffffc90000085040 by task dmsetup/90\n\n (...snip...)\n The buggy address belongs to the virtual mapping at\n [ffffc90000085000, ffffc90000087000) created by:\n cache_ctr+0x176a/0x35f0\n\n (...snip...)\n Memory state around the buggy address:\n ffffc90000084f00: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc90000084f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n \u003effffc90000085000: 00 00 00 00 00 00 00 00 f8 f8 f8 f8 f8 f8 f8 f8\n ^\n ffffc90000085080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc90000085100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n\nFix by checking the size change on the first resume.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50278", "url": "https://www.suse.com/security/cve/CVE-2024-50278" }, { "category": "external", "summary": "SUSE Bug 1233467 for CVE-2024-50278", "url": "https://bugzilla.suse.com/1233467" }, { "category": "external", "summary": "SUSE Bug 1233709 for CVE-2024-50278", "url": "https://bugzilla.suse.com/1233709" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50278" }, { "cve": "CVE-2024-50279", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50279" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix out-of-bounds access to the dirty bitset when resizing\n\ndm-cache checks the dirty bits of the cache blocks to be dropped when\nshrinking the fast device, but an index bug in bitset iteration causes\nout-of-bounds access.\n\nReproduce steps:\n\n1. create a cache device of 1024 cache blocks (128 bytes dirty bitset)\n\ndmsetup create cmeta --table \"0 8192 linear /dev/sdc 0\"\ndmsetup create cdata --table \"0 131072 linear /dev/sdc 8192\"\ndmsetup create corig --table \"0 524288 linear /dev/sdc 262144\"\ndd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct\ndmsetup create cache --table \"0 524288 cache /dev/mapper/cmeta \\\n/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0\"\n\n2. shrink the fast device to 512 cache blocks, triggering out-of-bounds\n access to the dirty bitset (offset 0x80)\n\ndmsetup suspend cache\ndmsetup reload cdata --table \"0 65536 linear /dev/sdc 8192\"\ndmsetup resume cdata\ndmsetup resume cache\n\nKASAN reports:\n\n BUG: KASAN: vmalloc-out-of-bounds in cache_preresume+0x269/0x7b0\n Read of size 8 at addr ffffc900000f3080 by task dmsetup/131\n\n (...snip...)\n The buggy address belongs to the virtual mapping at\n [ffffc900000f3000, ffffc900000f5000) created by:\n cache_ctr+0x176a/0x35f0\n\n (...snip...)\n Memory state around the buggy address:\n ffffc900000f2f80: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc900000f3000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n \u003effffc900000f3080: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ^\n ffffc900000f3100: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n ffffc900000f3180: f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8 f8\n\nFix by making the index post-incremented.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50279", "url": "https://www.suse.com/security/cve/CVE-2024-50279" }, { "category": "external", "summary": "SUSE Bug 1233468 for CVE-2024-50279", "url": "https://bugzilla.suse.com/1233468" }, { "category": "external", "summary": "SUSE Bug 1233708 for CVE-2024-50279", "url": "https://bugzilla.suse.com/1233708" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.1, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-50279" }, { "cve": "CVE-2024-50280", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-50280" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix flushing uninitialized delayed_work on cache_ctr error\n\nAn unexpected WARN_ON from flush_work() may occur when cache creation\nfails, caused by destroying the uninitialized delayed_work waker in the\nerror path of cache_create(). For example, the warning appears on the\nsuperblock checksum error.\n\nReproduce steps:\n\ndmsetup create cmeta --table \"0 8192 linear /dev/sdc 0\"\ndmsetup create cdata --table \"0 65536 linear /dev/sdc 8192\"\ndmsetup create corig --table \"0 524288 linear /dev/sdc 262144\"\ndd if=/dev/urandom of=/dev/mapper/cmeta bs=4k count=1 oflag=direct\ndmsetup create cache --table \"0 524288 cache /dev/mapper/cmeta \\\n/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0\"\n\nKernel logs:\n\n(snip)\nWARNING: CPU: 0 PID: 84 at kernel/workqueue.c:4178 __flush_work+0x5d4/0x890\n\nFix by pulling out the cancel_delayed_work_sync() from the constructor\u0027s\nerror path. This patch doesn\u0027t affect the use-after-free fix for\nconcurrent dm_resume and dm_destroy (commit 6a459d8edbdb (\"dm cache: Fix\nUAF in destroy()\")) as cache_dtr is not changed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-50280", "url": "https://www.suse.com/security/cve/CVE-2024-50280" }, { "category": "external", "summary": "SUSE Bug 1233469 for CVE-2024-50280", "url": "https://bugzilla.suse.com/1233469" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-50280" }, { "cve": "CVE-2024-53050", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53050" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/hdcp: Add encoder check in hdcp2_get_capability\n\nAdd encoder check in intel_hdcp2_get_capability to avoid\nnull pointer error.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53050", "url": "https://www.suse.com/security/cve/CVE-2024-53050" }, { "category": "external", "summary": "SUSE Bug 1233546 for CVE-2024-53050", "url": "https://bugzilla.suse.com/1233546" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53050" }, { "cve": "CVE-2024-53064", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53064" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nidpf: fix idpf_vc_core_init error path\n\nIn an event where the platform running the device control plane\nis rebooted, reset is detected on the driver. It releases\nall the resources and waits for the reset to complete. Once the\nreset is done, it tries to build the resources back. At this\ntime if the device control plane is not yet started, then\nthe driver timeouts on the virtchnl message and retries to\nestablish the mailbox again.\n\nIn the retry flow, mailbox is deinitialized but the mailbox\nworkqueue is still alive and polling for the mailbox message.\nThis results in accessing the released control queue leading to\nnull-ptr-deref. Fix it by unrolling the work queue cancellation\nand mailbox deinitialization in the reverse order which they got\ninitialized.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53064", "url": "https://www.suse.com/security/cve/CVE-2024-53064" }, { "category": "external", "summary": "SUSE Bug 1233558 for CVE-2024-53064", "url": "https://bugzilla.suse.com/1233558" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53064" }, { "cve": "CVE-2024-53090", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53090" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix lock recursion\n\nafs_wake_up_async_call() can incur lock recursion. The problem is that it\nis called from AF_RXRPC whilst holding the -\u003enotify_lock, but it tries to\ntake a ref on the afs_call struct in order to pass it to a work queue - but\nif the afs_call is already queued, we then have an extraneous ref that must\nbe put... calling afs_put_call() may call back down into AF_RXRPC through\nrxrpc_kernel_shutdown_call(), however, which might try taking the\n-\u003enotify_lock again.\n\nThis case isn\u0027t very common, however, so defer it to a workqueue. The oops\nlooks something like:\n\n BUG: spinlock recursion on CPU#0, krxrpcio/7001/1646\n lock: 0xffff888141399b30, .magic: dead4ead, .owner: krxrpcio/7001/1646, .owner_cpu: 0\n CPU: 0 UID: 0 PID: 1646 Comm: krxrpcio/7001 Not tainted 6.12.0-rc2-build3+ #4351\n Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x47/0x70\n do_raw_spin_lock+0x3c/0x90\n rxrpc_kernel_shutdown_call+0x83/0xb0\n afs_put_call+0xd7/0x180\n rxrpc_notify_socket+0xa0/0x190\n rxrpc_input_split_jumbo+0x198/0x1d0\n rxrpc_input_data+0x14b/0x1e0\n ? rxrpc_input_call_packet+0xc2/0x1f0\n rxrpc_input_call_event+0xad/0x6b0\n rxrpc_input_packet_on_conn+0x1e1/0x210\n rxrpc_input_packet+0x3f2/0x4d0\n rxrpc_io_thread+0x243/0x410\n ? __pfx_rxrpc_io_thread+0x10/0x10\n kthread+0xcf/0xe0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x24/0x40\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53090", "url": "https://www.suse.com/security/cve/CVE-2024-53090" }, { "category": "external", "summary": "SUSE Bug 1233637 for CVE-2024-53090", "url": "https://bugzilla.suse.com/1233637" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53090" }, { "cve": "CVE-2024-53099", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53099" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check validity of link-\u003etype in bpf_link_show_fdinfo()\n\nIf a newly-added link type doesn\u0027t invoke BPF_LINK_TYPE(), accessing\nbpf_link_type_strs[link-\u003etype] may result in an out-of-bounds access.\n\nTo spot such missed invocations early in the future, checking the\nvalidity of link-\u003etype in bpf_link_show_fdinfo() and emitting a warning\nwhen such invocations are missed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53099", "url": "https://www.suse.com/security/cve/CVE-2024-53099" }, { "category": "external", "summary": "SUSE Bug 1233772 for CVE-2024-53099", "url": "https://bugzilla.suse.com/1233772" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53099" }, { "cve": "CVE-2024-53103", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53103" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_sock: Initializing vsk-\u003etrans to NULL to prevent a dangling pointer\n\nWhen hvs is released, there is a possibility that vsk-\u003etrans may not\nbe initialized to NULL, which could lead to a dangling pointer.\nThis issue is resolved by initializing vsk-\u003etrans to NULL.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53103", "url": "https://www.suse.com/security/cve/CVE-2024-53103" }, { "category": "external", "summary": "SUSE Bug 1234024 for CVE-2024-53103", "url": "https://bugzilla.suse.com/1234024" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53103" }, { "cve": "CVE-2024-53105", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53105" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: page_alloc: move mlocked flag clearance into free_pages_prepare()\n\nSyzbot reported a bad page state problem caused by a page being freed\nusing free_page() still having a mlocked flag at free_pages_prepare()\nstage:\n\n BUG: Bad page state in process syz.5.504 pfn:61f45\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x61f45\n flags: 0xfff00000080204(referenced|workingset|mlocked|node=0|zone=1|lastcpupid=0x7ff)\n raw: 00fff00000080204 0000000000000000 dead000000000122 0000000000000000\n raw: 0000000000000000 0000000000000000 00000000ffffffff 0000000000000000\n page dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set\n page_owner tracks the page as allocated\n page last allocated via order 0, migratetype Unmovable, gfp_mask 0x400dc0(GFP_KERNEL_ACCOUNT|__GFP_ZERO), pid 8443, tgid 8442 (syz.5.504), ts 201884660643, free_ts 201499827394\n set_page_owner include/linux/page_owner.h:32 [inline]\n post_alloc_hook+0x1f3/0x230 mm/page_alloc.c:1537\n prep_new_page mm/page_alloc.c:1545 [inline]\n get_page_from_freelist+0x303f/0x3190 mm/page_alloc.c:3457\n __alloc_pages_noprof+0x292/0x710 mm/page_alloc.c:4733\n alloc_pages_mpol_noprof+0x3e8/0x680 mm/mempolicy.c:2265\n kvm_coalesced_mmio_init+0x1f/0xf0 virt/kvm/coalesced_mmio.c:99\n kvm_create_vm virt/kvm/kvm_main.c:1235 [inline]\n kvm_dev_ioctl_create_vm virt/kvm/kvm_main.c:5488 [inline]\n kvm_dev_ioctl+0x12dc/0x2240 virt/kvm/kvm_main.c:5530\n __do_compat_sys_ioctl fs/ioctl.c:1007 [inline]\n __se_compat_sys_ioctl+0x510/0xc90 fs/ioctl.c:950\n do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline]\n __do_fast_syscall_32+0xb4/0x110 arch/x86/entry/common.c:386\n do_fast_syscall_32+0x34/0x80 arch/x86/entry/common.c:411\n entry_SYSENTER_compat_after_hwframe+0x84/0x8e\n page last free pid 8399 tgid 8399 stack trace:\n reset_page_owner include/linux/page_owner.h:25 [inline]\n free_pages_prepare mm/page_alloc.c:1108 [inline]\n free_unref_folios+0xf12/0x18d0 mm/page_alloc.c:2686\n folios_put_refs+0x76c/0x860 mm/swap.c:1007\n free_pages_and_swap_cache+0x5c8/0x690 mm/swap_state.c:335\n __tlb_batch_free_encoded_pages mm/mmu_gather.c:136 [inline]\n tlb_batch_pages_flush mm/mmu_gather.c:149 [inline]\n tlb_flush_mmu_free mm/mmu_gather.c:366 [inline]\n tlb_flush_mmu+0x3a3/0x680 mm/mmu_gather.c:373\n tlb_finish_mmu+0xd4/0x200 mm/mmu_gather.c:465\n exit_mmap+0x496/0xc40 mm/mmap.c:1926\n __mmput+0x115/0x390 kernel/fork.c:1348\n exit_mm+0x220/0x310 kernel/exit.c:571\n do_exit+0x9b2/0x28e0 kernel/exit.c:926\n do_group_exit+0x207/0x2c0 kernel/exit.c:1088\n __do_sys_exit_group kernel/exit.c:1099 [inline]\n __se_sys_exit_group kernel/exit.c:1097 [inline]\n __x64_sys_exit_group+0x3f/0x40 kernel/exit.c:1097\n x64_sys_call+0x2634/0x2640 arch/x86/include/generated/asm/syscalls_64.h:232\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n Modules linked in:\n CPU: 0 UID: 0 PID: 8442 Comm: syz.5.504 Not tainted 6.12.0-rc6-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n Call Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n bad_page+0x176/0x1d0 mm/page_alloc.c:501\n free_page_is_bad mm/page_alloc.c:918 [inline]\n free_pages_prepare mm/page_alloc.c:1100 [inline]\n free_unref_page+0xed0/0xf20 mm/page_alloc.c:2638\n kvm_destroy_vm virt/kvm/kvm_main.c:1327 [inline]\n kvm_put_kvm+0xc75/0x1350 virt/kvm/kvm_main.c:1386\n kvm_vcpu_release+0x54/0x60 virt/kvm/kvm_main.c:4143\n __fput+0x23f/0x880 fs/file_table.c:431\n task_work_run+0x24f/0x310 kernel/task_work.c:239\n exit_task_work include/linux/task_work.h:43 [inline]\n do_exit+0xa2f/0x28e0 kernel/exit.c:939\n do_group_exit+0x207/0x2c0 kernel/exit.c:1088\n __do_sys_exit_group kernel/exit.c:1099 [in\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53105", "url": "https://www.suse.com/security/cve/CVE-2024-53105" }, { "category": "external", "summary": "SUSE Bug 1234069 for CVE-2024-53105", "url": "https://bugzilla.suse.com/1234069" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53105" }, { "cve": "CVE-2024-53111", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53111" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mremap: fix address wraparound in move_page_tables()\n\nOn 32-bit platforms, it is possible for the expression `len + old_addr \u003c\nold_end` to be false-positive if `len + old_addr` wraps around. \n`old_addr` is the cursor in the old range up to which page table entries\nhave been moved; so if the operation succeeded, `old_addr` is the *end* of\nthe old region, and adding `len` to it can wrap.\n\nThe overflow causes mremap() to mistakenly believe that PTEs have been\ncopied; the consequence is that mremap() bails out, but doesn\u0027t move the\nPTEs back before the new VMA is unmapped, causing anonymous pages in the\nregion to be lost. So basically if userspace tries to mremap() a\nprivate-anon region and hits this bug, mremap() will return an error and\nthe private-anon region\u0027s contents appear to have been zeroed.\n\nThe idea of this check is that `old_end - len` is the original start\naddress, and writing the check that way also makes it easier to read; so\nfix the check by rearranging the comparison accordingly.\n\n(An alternate fix would be to refactor this function by introducing an\n\"orig_old_start\" variable or such.)\n\n\nTested in a VM with a 32-bit X86 kernel; without the patch:\n\n```\nuser@horn:~/big_mremap$ cat test.c\n#define _GNU_SOURCE\n#include \u003cstdlib.h\u003e\n#include \u003cstdio.h\u003e\n#include \u003cerr.h\u003e\n#include \u003csys/mman.h\u003e\n\n#define ADDR1 ((void*)0x60000000)\n#define ADDR2 ((void*)0x10000000)\n#define SIZE 0x50000000uL\n\nint main(void) {\n unsigned char *p1 = mmap(ADDR1, SIZE, PROT_READ|PROT_WRITE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p1 == MAP_FAILED)\n err(1, \"mmap 1\");\n unsigned char *p2 = mmap(ADDR2, SIZE, PROT_NONE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p2 == MAP_FAILED)\n err(1, \"mmap 2\");\n *p1 = 0x41;\n printf(\"first char is 0x%02hhx\\n\", *p1);\n unsigned char *p3 = mremap(p1, SIZE, SIZE,\n MREMAP_MAYMOVE|MREMAP_FIXED, p2);\n if (p3 == MAP_FAILED) {\n printf(\"mremap() failed; first char is 0x%02hhx\\n\", *p1);\n } else {\n printf(\"mremap() succeeded; first char is 0x%02hhx\\n\", *p3);\n }\n}\nuser@horn:~/big_mremap$ gcc -static -o test test.c\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() failed; first char is 0x00\n```\n\nWith the patch:\n\n```\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() succeeded; first char is 0x41\n```", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53111", "url": "https://www.suse.com/security/cve/CVE-2024-53111" }, { "category": "external", "summary": "SUSE Bug 1234086 for CVE-2024-53111", "url": "https://bugzilla.suse.com/1234086" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53111" }, { "cve": "CVE-2024-53113", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53113" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix NULL pointer dereference in alloc_pages_bulk_noprof\n\nWe triggered a NULL pointer dereference for ac.preferred_zoneref-\u003ezone in\nalloc_pages_bulk_noprof() when the task is migrated between cpusets.\n\nWhen cpuset is enabled, in prepare_alloc_pages(), ac-\u003enodemask may be\n\u0026current-\u003emems_allowed. when first_zones_zonelist() is called to find\npreferred_zoneref, the ac-\u003enodemask may be modified concurrently if the\ntask is migrated between different cpusets. Assuming we have 2 NUMA Node,\nwhen traversing Node1 in ac-\u003ezonelist, the nodemask is 2, and when\ntraversing Node2 in ac-\u003ezonelist, the nodemask is 1. As a result, the\nac-\u003epreferred_zoneref points to NULL zone.\n\nIn alloc_pages_bulk_noprof(), for_each_zone_zonelist_nodemask() finds a\nallowable zone and calls zonelist_node_idx(ac.preferred_zoneref), leading\nto NULL pointer dereference.\n\n__alloc_pages_noprof() fixes this issue by checking NULL pointer in commit\nea57485af8f4 (\"mm, page_alloc: fix check for NULL preferred_zone\") and\ncommit df76cee6bbeb (\"mm, page_alloc: remove redundant checks from alloc\nfastpath\").\n\nTo fix it, check NULL pointer for preferred_zoneref-\u003ezone.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53113", "url": "https://www.suse.com/security/cve/CVE-2024-53113" }, { "category": "external", "summary": "SUSE Bug 1234077 for CVE-2024-53113", "url": "https://bugzilla.suse.com/1234077" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53113" }, { "cve": "CVE-2024-53117", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53117" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Improve MSG_ZEROCOPY error handling\n\nAdd a missing kfree_skb() to prevent memory leaks.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53117", "url": "https://www.suse.com/security/cve/CVE-2024-53117" }, { "category": "external", "summary": "SUSE Bug 1234079 for CVE-2024-53117", "url": "https://bugzilla.suse.com/1234079" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53117" }, { "cve": "CVE-2024-53118", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53118" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix sk_error_queue memory leak\n\nKernel queues MSG_ZEROCOPY completion notifications on the error queue.\nWhere they remain, until explicitly recv()ed. To prevent memory leaks,\nclean up the queue when the socket is destroyed.\n\nunreferenced object 0xffff8881028beb00 (size 224):\n comm \"vsock_test\", pid 1218, jiffies 4294694897\n hex dump (first 32 bytes):\n 90 b0 21 17 81 88 ff ff 90 b0 21 17 81 88 ff ff ..!.......!.....\n 00 00 00 00 00 00 00 00 00 b0 21 17 81 88 ff ff ..........!.....\n backtrace (crc 6c7031ca):\n [\u003cffffffff81418ef7\u003e] kmem_cache_alloc_node_noprof+0x2f7/0x370\n [\u003cffffffff81d35882\u003e] __alloc_skb+0x132/0x180\n [\u003cffffffff81d2d32b\u003e] sock_omalloc+0x4b/0x80\n [\u003cffffffff81d3a8ae\u003e] msg_zerocopy_realloc+0x9e/0x240\n [\u003cffffffff81fe5cb2\u003e] virtio_transport_send_pkt_info+0x412/0x4c0\n [\u003cffffffff81fe6183\u003e] virtio_transport_stream_enqueue+0x43/0x50\n [\u003cffffffff81fe0813\u003e] vsock_connectible_sendmsg+0x373/0x450\n [\u003cffffffff81d233d5\u003e] ____sys_sendmsg+0x365/0x3a0\n [\u003cffffffff81d246f4\u003e] ___sys_sendmsg+0x84/0xd0\n [\u003cffffffff81d26f47\u003e] __sys_sendmsg+0x47/0x80\n [\u003cffffffff820d3df3\u003e] do_syscall_64+0x93/0x180\n [\u003cffffffff8220012b\u003e] entry_SYSCALL_64_after_hwframe+0x76/0x7e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53118", "url": "https://www.suse.com/security/cve/CVE-2024-53118" }, { "category": "external", "summary": "SUSE Bug 1234071 for CVE-2024-53118", "url": "https://bugzilla.suse.com/1234071" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53118" }, { "cve": "CVE-2024-53119", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53119" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Fix accept_queue memory leak\n\nAs the final stages of socket destruction may be delayed, it is possible\nthat virtio_transport_recv_listen() will be called after the accept_queue\nhas been flushed, but before the SOCK_DONE flag has been set. As a result,\nsockets enqueued after the flush would remain unremoved, leading to a\nmemory leak.\n\nvsock_release\n __vsock_release\n lock\n virtio_transport_release\n virtio_transport_close\n schedule_delayed_work(close_work)\n sk_shutdown = SHUTDOWN_MASK\n(!) flush accept_queue\n release\n virtio_transport_recv_pkt\n vsock_find_bound_socket\n lock\n if flag(SOCK_DONE) return\n virtio_transport_recv_listen\n child = vsock_create_connected\n (!) vsock_enqueue_accept(child)\n release\nclose_work\n lock\n virtio_transport_do_close\n set_flag(SOCK_DONE)\n virtio_transport_remove_sock\n vsock_remove_sock\n vsock_remove_bound\n release\n\nIntroduce a sk_shutdown check to disallow vsock_enqueue_accept() during\nsocket destruction.\n\nunreferenced object 0xffff888109e3f800 (size 2040):\n comm \"kworker/5:2\", pid 371, jiffies 4294940105\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 28 00 0b 40 00 00 00 00 00 00 00 00 00 00 00 00 (..@............\n backtrace (crc 9e5f4e84):\n [\u003cffffffff81418ff1\u003e] kmem_cache_alloc_noprof+0x2c1/0x360\n [\u003cffffffff81d27aa0\u003e] sk_prot_alloc+0x30/0x120\n [\u003cffffffff81d2b54c\u003e] sk_alloc+0x2c/0x4b0\n [\u003cffffffff81fe049a\u003e] __vsock_create.constprop.0+0x2a/0x310\n [\u003cffffffff81fe6d6c\u003e] virtio_transport_recv_pkt+0x4dc/0x9a0\n [\u003cffffffff81fe745d\u003e] vsock_loopback_work+0xfd/0x140\n [\u003cffffffff810fc6ac\u003e] process_one_work+0x20c/0x570\n [\u003cffffffff810fce3f\u003e] worker_thread+0x1bf/0x3a0\n [\u003cffffffff811070dd\u003e] kthread+0xdd/0x110\n [\u003cffffffff81044fdd\u003e] ret_from_fork+0x2d/0x50\n [\u003cffffffff8100785a\u003e] ret_from_fork_asm+0x1a/0x30", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53119", "url": "https://www.suse.com/security/cve/CVE-2024-53119" }, { "category": "external", "summary": "SUSE Bug 1234073 for CVE-2024-53119", "url": "https://bugzilla.suse.com/1234073" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53119" }, { "cve": "CVE-2024-53120", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53120" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: CT: Fix null-ptr-deref in add rule err flow\n\nIn error flow of mlx5_tc_ct_entry_add_rule(), in case ct_rule_add()\ncallback returns error, zone_rule-\u003eattr is used uninitiated. Fix it to\nuse attr which has the needed pointer value.\n\nKernel log:\n BUG: kernel NULL pointer dereference, address: 0000000000000110\n RIP: 0010:mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n\u2026\n Call Trace:\n \u003cTASK\u003e\n ? __die+0x20/0x70\n ? page_fault_oops+0x150/0x3e0\n ? exc_page_fault+0x74/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n ? mlx5_tc_ct_entry_add_rule+0x1d5/0x2f0 [mlx5_core]\n mlx5_tc_ct_block_flow_offload+0xc6a/0xf90 [mlx5_core]\n ? nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n flow_offload_work_handler+0x142/0x320 [nf_flow_table]\n ? finish_task_switch.isra.0+0x15b/0x2b0\n process_one_work+0x16c/0x320\n worker_thread+0x28c/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xb8/0xf0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53120", "url": "https://www.suse.com/security/cve/CVE-2024-53120" }, { "category": "external", "summary": "SUSE Bug 1234075 for CVE-2024-53120", "url": "https://bugzilla.suse.com/1234075" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53120" }, { "cve": "CVE-2024-53122", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53122" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: cope racing subflow creation in mptcp_rcv_space_adjust\n\nAdditional active subflows - i.e. created by the in kernel path\nmanager - are included into the subflow list before starting the\n3whs.\n\nA racing recvmsg() spooling data received on an already established\nsubflow would unconditionally call tcp_cleanup_rbuf() on all the\ncurrent subflows, potentially hitting a divide by zero error on\nthe newly created ones.\n\nExplicitly check that the subflow is in a suitable state before\ninvoking tcp_cleanup_rbuf().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53122", "url": "https://www.suse.com/security/cve/CVE-2024-53122" }, { "category": "external", "summary": "SUSE Bug 1234076 for CVE-2024-53122", "url": "https://bugzilla.suse.com/1234076" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53122" }, { "cve": "CVE-2024-53125", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53125" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sync_linked_regs() must preserve subreg_def\n\nRange propagation must not affect subreg_def marks, otherwise the\nfollowing example is rewritten by verifier incorrectly when\nBPF_F_TEST_RND_HI32 flag is set:\n\n 0: call bpf_ktime_get_ns call bpf_ktime_get_ns\n 1: r0 \u0026= 0x7fffffff after verifier r0 \u0026= 0x7fffffff\n 2: w1 = w0 rewrites w1 = w0\n 3: if w0 \u003c 10 goto +0 --------------\u003e r11 = 0x2f5674a6 (r)\n 4: r1 \u003e\u003e= 32 r11 \u003c\u003c= 32 (r)\n 5: r0 = r1 r1 |= r11 (r)\n 6: exit; if w0 \u003c 0xa goto pc+0\n r1 \u003e\u003e= 32\n r0 = r1\n exit\n\n(or zero extension of w1 at (2) is missing for architectures that\n require zero extension for upper register half).\n\nThe following happens w/o this patch:\n- r0 is marked as not a subreg at (0);\n- w1 is marked as subreg at (2);\n- w1 subreg_def is overridden at (3) by copy_register_state();\n- w1 is read at (5) but mark_insn_zext() does not mark (2)\n for zero extension, because w1 subreg_def is not set;\n- because of BPF_F_TEST_RND_HI32 flag verifier inserts random\n value for hi32 bits of (2) (marked (r));\n- this random value is read at (5).", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53125", "url": "https://www.suse.com/security/cve/CVE-2024-53125" }, { "category": "external", "summary": "SUSE Bug 1234156 for CVE-2024-53125", "url": "https://bugzilla.suse.com/1234156" }, { "category": "external", "summary": "SUSE Bug 1245804 for CVE-2024-53125", "url": "https://bugzilla.suse.com/1245804" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53125" }, { "cve": "CVE-2024-53126", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53126" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: solidrun: Fix UB bug with devres\n\nIn psnet_open_pf_bar() and snet_open_vf_bar() a string later passed to\npcim_iomap_regions() is placed on the stack. Neither\npcim_iomap_regions() nor the functions it calls copy that string.\n\nShould the string later ever be used, this, consequently, causes\nundefined behavior since the stack frame will by then have disappeared.\n\nFix the bug by allocating the strings on the heap through\ndevm_kasprintf().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53126", "url": "https://www.suse.com/security/cve/CVE-2024-53126" }, { "category": "external", "summary": "SUSE Bug 1234158 for CVE-2024-53126", "url": "https://bugzilla.suse.com/1234158" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53126" }, { "cve": "CVE-2024-53127", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53127" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"mmc: dw_mmc: Fix IDMAC operation with pages bigger than 4K\"\n\nThe commit 8396c793ffdf (\"mmc: dw_mmc: Fix IDMAC operation with pages\nbigger than 4K\") increased the max_req_size, even for 4K pages, causing\nvarious issues:\n- Panic booting the kernel/rootfs from an SD card on Rockchip RK3566\n- Panic booting the kernel/rootfs from an SD card on StarFive JH7100\n- \"swiotlb buffer is full\" and data corruption on StarFive JH7110\n\nAt this stage no fix have been found, so it\u0027s probably better to just\nrevert the change.\n\nThis reverts commit 8396c793ffdf28bb8aee7cfe0891080f8cab7890.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53127", "url": "https://www.suse.com/security/cve/CVE-2024-53127" }, { "category": "external", "summary": "SUSE Bug 1234153 for CVE-2024-53127", "url": "https://bugzilla.suse.com/1234153" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53127" }, { "cve": "CVE-2024-53129", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53129" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: vop: Fix a dereferenced before check warning\n\nThe \u0027state\u0027 can\u0027t be NULL, we should check crtc_state.\n\nFix warning:\ndrivers/gpu/drm/rockchip/rockchip_drm_vop.c:1096\nvop_plane_atomic_async_check() warn: variable dereferenced before check\n\u0027state\u0027 (see line 1077)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53129", "url": "https://www.suse.com/security/cve/CVE-2024-53129" }, { "category": "external", "summary": "SUSE Bug 1234155 for CVE-2024-53129", "url": "https://bugzilla.suse.com/1234155" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53129" }, { "cve": "CVE-2024-53130", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53130" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint\n\nWhen using the \"block:block_dirty_buffer\" tracepoint, mark_buffer_dirty()\nmay cause a NULL pointer dereference, or a general protection fault when\nKASAN is enabled.\n\nThis happens because, since the tracepoint was added in\nmark_buffer_dirty(), it references the dev_t member bh-\u003eb_bdev-\u003ebd_dev\nregardless of whether the buffer head has a pointer to a block_device\nstructure.\n\nIn the current implementation, nilfs_grab_buffer(), which grabs a buffer\nto read (or create) a block of metadata, including b-tree node blocks,\ndoes not set the block device, but instead does so only if the buffer is\nnot in the \"uptodate\" state for each of its caller block reading\nfunctions. However, if the uptodate flag is set on a folio/page, and the\nbuffer heads are detached from it by try_to_free_buffers(), and new buffer\nheads are then attached by create_empty_buffers(), the uptodate flag may\nbe restored to each buffer without the block device being set to\nbh-\u003eb_bdev, and mark_buffer_dirty() may be called later in that state,\nresulting in the bug mentioned above.\n\nFix this issue by making nilfs_grab_buffer() always set the block device\nof the super block structure to the buffer head, regardless of the state\nof the buffer\u0027s uptodate flag.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53130", "url": "https://www.suse.com/security/cve/CVE-2024-53130" }, { "category": "external", "summary": "SUSE Bug 1234219 for CVE-2024-53130", "url": "https://bugzilla.suse.com/1234219" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53130" }, { "cve": "CVE-2024-53131", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53131" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix null-ptr-deref in block_touch_buffer tracepoint\n\nPatch series \"nilfs2: fix null-ptr-deref bugs on block tracepoints\".\n\nThis series fixes null pointer dereference bugs that occur when using\nnilfs2 and two block-related tracepoints.\n\n\nThis patch (of 2):\n\nIt has been reported that when using \"block:block_touch_buffer\"\ntracepoint, touch_buffer() called from __nilfs_get_folio_block() causes a\nNULL pointer dereference, or a general protection fault when KASAN is\nenabled.\n\nThis happens because since the tracepoint was added in touch_buffer(), it\nreferences the dev_t member bh-\u003eb_bdev-\u003ebd_dev regardless of whether the\nbuffer head has a pointer to a block_device structure. In the current\nimplementation, the block_device structure is set after the function\nreturns to the caller.\n\nHere, touch_buffer() is used to mark the folio/page that owns the buffer\nhead as accessed, but the common search helper for folio/page used by the\ncaller function was optimized to mark the folio/page as accessed when it\nwas reimplemented a long time ago, eliminating the need to call\ntouch_buffer() here in the first place.\n\nSo this solves the issue by eliminating the touch_buffer() call itself.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53131", "url": "https://www.suse.com/security/cve/CVE-2024-53131" }, { "category": "external", "summary": "SUSE Bug 1234220 for CVE-2024-53131", "url": "https://bugzilla.suse.com/1234220" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53131" }, { "cve": "CVE-2024-53133", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53133" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Handle dml allocation failure to avoid crash\n\n[Why]\nIn the case where a dml allocation fails for any reason, the\ncurrent state\u0027s dml contexts would no longer be valid. Then\nsubsequent calls dc_state_copy_internal would shallow copy\ninvalid memory and if the new state was released, a double\nfree would occur.\n\n[How]\nReset dml pointers in new_state to NULL and avoid invalid\npointer\n\n(cherry picked from commit bcafdc61529a48f6f06355d78eb41b3aeda5296c)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53133", "url": "https://www.suse.com/security/cve/CVE-2024-53133" }, { "category": "external", "summary": "SUSE Bug 1234221 for CVE-2024-53133", "url": "https://bugzilla.suse.com/1234221" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53133" }, { "cve": "CVE-2024-53134", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53134" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx93-blk-ctrl: correct remove path\n\nThe check condition should be \u0027i \u003c bc-\u003eonecell_data.num_domains\u0027, not\n\u0027bc-\u003eonecell_data.num_domains\u0027 which will make the look never finish\nand cause kernel panic.\n\nAlso disable runtime to address\n\"imx93-blk-ctrl 4ac10000.system-controller: Unbalanced pm_runtime_enable!\"", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53134", "url": "https://www.suse.com/security/cve/CVE-2024-53134" }, { "category": "external", "summary": "SUSE Bug 1234159 for CVE-2024-53134", "url": "https://bugzilla.suse.com/1234159" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53134" }, { "cve": "CVE-2024-53136", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53136" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: revert \"mm: shmem: fix data-race in shmem_getattr()\"\n\nRevert d949d1d14fa2 (\"mm: shmem: fix data-race in shmem_getattr()\") as\nsuggested by Chuck [1]. It is causing deadlocks when accessing tmpfs over\nNFS.\n\nAs Hugh commented, \"added just to silence a syzbot sanitizer splat: added\nwhere there has never been any practical problem\".", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53136", "url": "https://www.suse.com/security/cve/CVE-2024-53136" }, { "category": "external", "summary": "SUSE Bug 1234161 for CVE-2024-53136", "url": "https://bugzilla.suse.com/1234161" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53136" }, { "cve": "CVE-2024-53141", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53141" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: add missing range check in bitmap_ip_uadt\n\nWhen tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists,\nthe values of ip and ip_to are slightly swapped. Therefore, the range check\nfor ip should be done later, but this part is missing and it seems that the\nvulnerability occurs.\n\nSo we should add missing range checks and remove unnecessary range checks.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53141", "url": "https://www.suse.com/security/cve/CVE-2024-53141" }, { "category": "external", "summary": "SUSE Bug 1234381 for CVE-2024-53141", "url": "https://bugzilla.suse.com/1234381" }, { "category": "external", "summary": "SUSE Bug 1245778 for CVE-2024-53141", "url": "https://bugzilla.suse.com/1245778" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53141" }, { "cve": "CVE-2024-53142", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53142" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ninitramfs: avoid filename buffer overrun\n\nThe initramfs filename field is defined in\nDocumentation/driver-api/early-userspace/buffer-format.rst as:\n\n 37 cpio_file := ALGN(4) + cpio_header + filename + \"\\0\" + ALGN(4) + data\n...\n 55 ============= ================== =========================\n 56 Field name Field size Meaning\n 57 ============= ================== =========================\n...\n 70 c_namesize 8 bytes Length of filename, including final \\0\n\nWhen extracting an initramfs cpio archive, the kernel\u0027s do_name() path\nhandler assumes a zero-terminated path at @collected, passing it\ndirectly to filp_open() / init_mkdir() / init_mknod().\n\nIf a specially crafted cpio entry carries a non-zero-terminated filename\nand is followed by uninitialized memory, then a file may be created with\ntrailing characters that represent the uninitialized memory. The ability\nto create an initramfs entry would imply already having full control of\nthe system, so the buffer overrun shouldn\u0027t be considered a security\nvulnerability.\n\nAppend the output of the following bash script to an existing initramfs\nand observe any created /initramfs_test_fname_overrunAA* path. E.g.\n ./reproducer.sh | gzip \u003e\u003e /myinitramfs\n\nIt\u0027s easiest to observe non-zero uninitialized memory when the output is\ngzipped, as it\u0027ll overflow the heap allocated @out_buf in __gunzip(),\nrather than the initrd_start+initrd_size block.\n\n---- reproducer.sh ----\nnilchar=\"A\"\t# change to \"\\0\" to properly zero terminate / pad\nmagic=\"070701\"\nino=1\nmode=$(( 0100777 ))\nuid=0\ngid=0\nnlink=1\nmtime=1\nfilesize=0\ndevmajor=0\ndevminor=1\nrdevmajor=0\nrdevminor=0\ncsum=0\nfname=\"initramfs_test_fname_overrun\"\nnamelen=$(( ${#fname} + 1 ))\t# plus one to account for terminator\n\nprintf \"%s%08x%08x%08x%08x%08x%08x%08x%08x%08x%08x%08x%08x%08x%s\" \\\n\t$magic $ino $mode $uid $gid $nlink $mtime $filesize \\\n\t$devmajor $devminor $rdevmajor $rdevminor $namelen $csum $fname\n\ntermpadlen=$(( 1 + ((4 - ((110 + $namelen) \u0026 3)) % 4) ))\nprintf \"%.s${nilchar}\" $(seq 1 $termpadlen)\n---- reproducer.sh ----\n\nSymlink filename fields handled in do_symlink() won\u0027t overrun past the\ndata segment, due to the explicit zero-termination of the symlink\ntarget.\n\nFix filename buffer overrun by aborting the initramfs FSM if any cpio\nentry doesn\u0027t carry a zero-terminator at the expected (name_len - 1)\noffset.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53142", "url": "https://www.suse.com/security/cve/CVE-2024-53142" }, { "category": "external", "summary": "SUSE Bug 1232436 for CVE-2024-53142", "url": "https://bugzilla.suse.com/1232436" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53142" }, { "cve": "CVE-2024-53144", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53144" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE\n\nThis aligned BR/EDR JUST_WORKS method with LE which since 92516cd97fd4\n(\"Bluetooth: Always request for user confirmation for Just Works\")\nalways request user confirmation with confirm_hint set since the\nlikes of bluetoothd have dedicated policy around JUST_WORKS method\n(e.g. main.conf:JustWorksRepairing).\n\nCVE: CVE-2024-8805", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53144", "url": "https://www.suse.com/security/cve/CVE-2024-53144" }, { "category": "external", "summary": "SUSE Bug 1234690 for CVE-2024-53144", "url": "https://bugzilla.suse.com/1234690" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53144" }, { "cve": "CVE-2024-53146", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53146" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent a potential integer overflow\n\nIf the tag length is \u003e= U32_MAX - 3 then the \"length + 4\" addition\ncan result in an integer overflow. Address this by splitting the\ndecoding into several steps so that decode_cb_compound4res() does\nnot have to perform arithmetic on the unsafe length value.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53146", "url": "https://www.suse.com/security/cve/CVE-2024-53146" }, { "category": "external", "summary": "SUSE Bug 1234853 for CVE-2024-53146", "url": "https://bugzilla.suse.com/1234853" }, { "category": "external", "summary": "SUSE Bug 1234854 for CVE-2024-53146", "url": "https://bugzilla.suse.com/1234854" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53146" }, { "cve": "CVE-2024-53148", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53148" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: Flush partial mappings in error case\n\nIf some remap_pfn_range() calls succeeded before one failed, we still have\nbuffer pages mapped into the userspace page tables when we drop the buffer\nreference with comedi_buf_map_put(bm). The userspace mappings are only\ncleaned up later in the mmap error path.\n\nFix it by explicitly flushing all mappings in our VMA on the error path.\n\nSee commit 79a61cc3fc04 (\"mm: avoid leaving partial pfn mappings around in\nerror case\").", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53148", "url": "https://www.suse.com/security/cve/CVE-2024-53148" }, { "category": "external", "summary": "SUSE Bug 1234832 for CVE-2024-53148", "url": "https://bugzilla.suse.com/1234832" }, { "category": "external", "summary": "SUSE Bug 1234833 for CVE-2024-53148", "url": "https://bugzilla.suse.com/1234833" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53148" }, { "cve": "CVE-2024-53150", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53150" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Fix out of bounds reads when finding clock sources\n\nThe current USB-audio driver code doesn\u0027t check bLength of each\ndescriptor at traversing for clock descriptors. That is, when a\ndevice provides a bogus descriptor with a shorter bLength, the driver\nmight hit out-of-bounds reads.\n\nFor addressing it, this patch adds sanity checks to the validator\nfunctions for the clock descriptor traversal. When the descriptor\nlength is shorter than expected, it\u0027s skipped in the loop.\n\nFor the clock source and clock multiplier descriptors, we can just\ncheck bLength against the sizeof() of each descriptor type.\nOTOH, the clock selector descriptor of UAC2 and UAC3 has an array\nof bNrInPins elements and two more fields at its tail, hence those\nhave to be checked in addition to the sizeof() check.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53150", "url": "https://www.suse.com/security/cve/CVE-2024-53150" }, { "category": "external", "summary": "SUSE Bug 1234834 for CVE-2024-53150", "url": "https://bugzilla.suse.com/1234834" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53150" }, { "cve": "CVE-2024-53151", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53151" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Address an integer overflow\n\nDan Carpenter reports:\n\u003e Commit 78147ca8b4a9 (\"svcrdma: Add a \"parsed chunk list\" data\n\u003e structure\") from Jun 22, 2020 (linux-next), leads to the following\n\u003e Smatch static checker warning:\n\u003e\n\u003e\tnet/sunrpc/xprtrdma/svc_rdma_recvfrom.c:498 xdr_check_write_chunk()\n\u003e\twarn: potential user controlled sizeof overflow \u0027segcount * 4 * 4\u0027\n\u003e\n\u003e net/sunrpc/xprtrdma/svc_rdma_recvfrom.c\n\u003e 488 static bool xdr_check_write_chunk(struct svc_rdma_recv_ctxt *rctxt)\n\u003e 489 {\n\u003e 490 u32 segcount;\n\u003e 491 __be32 *p;\n\u003e 492\n\u003e 493 if (xdr_stream_decode_u32(\u0026rctxt-\u003erc_stream, \u0026segcount))\n\u003e ^^^^^^^^\n\u003e\n\u003e 494 return false;\n\u003e 495\n\u003e 496 /* A bogus segcount causes this buffer overflow check to fail. */\n\u003e 497 p = xdr_inline_decode(\u0026rctxt-\u003erc_stream,\n\u003e --\u003e 498 segcount * rpcrdma_segment_maxsz * sizeof(*p));\n\u003e\n\u003e\n\u003e segcount is an untrusted u32. On 32bit systems anything \u003e= SIZE_MAX / 16 will\n\u003e have an integer overflow and some those values will be accepted by\n\u003e xdr_inline_decode().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53151", "url": "https://www.suse.com/security/cve/CVE-2024-53151" }, { "category": "external", "summary": "SUSE Bug 1234829 for CVE-2024-53151", "url": "https://bugzilla.suse.com/1234829" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53151" }, { "cve": "CVE-2024-53154", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53154" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: clk-apple-nco: Add NULL check in applnco_probe\n\nAdd NULL check in applnco_probe, to handle kernel NULL pointer\ndereference error.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53154", "url": "https://www.suse.com/security/cve/CVE-2024-53154" }, { "category": "external", "summary": "SUSE Bug 1234826 for CVE-2024-53154", "url": "https://bugzilla.suse.com/1234826" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53154" }, { "cve": "CVE-2024-53155", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53155" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix uninitialized value in ocfs2_file_read_iter()\n\nSyzbot has reported the following KMSAN splat:\n\nBUG: KMSAN: uninit-value in ocfs2_file_read_iter+0x9a4/0xf80\n ocfs2_file_read_iter+0x9a4/0xf80\n __io_read+0x8d4/0x20f0\n io_read+0x3e/0xf0\n io_issue_sqe+0x42b/0x22c0\n io_wq_submit_work+0xaf9/0xdc0\n io_worker_handle_work+0xd13/0x2110\n io_wq_worker+0x447/0x1410\n ret_from_fork+0x6f/0x90\n ret_from_fork_asm+0x1a/0x30\n\nUninit was created at:\n __alloc_pages_noprof+0x9a7/0xe00\n alloc_pages_mpol_noprof+0x299/0x990\n alloc_pages_noprof+0x1bf/0x1e0\n allocate_slab+0x33a/0x1250\n ___slab_alloc+0x12ef/0x35e0\n kmem_cache_alloc_bulk_noprof+0x486/0x1330\n __io_alloc_req_refill+0x84/0x560\n io_submit_sqes+0x172f/0x2f30\n __se_sys_io_uring_enter+0x406/0x41c0\n __x64_sys_io_uring_enter+0x11f/0x1a0\n x64_sys_call+0x2b54/0x3ba0\n do_syscall_64+0xcd/0x1e0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nSince an instance of \u0027struct kiocb\u0027 may be passed from the block layer\nwith \u0027private\u0027 field uninitialized, introduce \u0027ocfs2_iocb_init_rw_locked()\u0027\nand use it from where \u0027ocfs2_dio_end_io()\u0027 might take care, i.e. in\n\u0027ocfs2_file_read_iter()\u0027 and \u0027ocfs2_file_write_iter()\u0027.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53155", "url": "https://www.suse.com/security/cve/CVE-2024-53155" }, { "category": "external", "summary": "SUSE Bug 1234855 for CVE-2024-53155", "url": "https://bugzilla.suse.com/1234855" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53155" }, { "cve": "CVE-2024-53156", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53156" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k: add range check for conn_rsp_epid in htc_connect_service()\n\nI found the following bug in my fuzzer:\n\n UBSAN: array-index-out-of-bounds in drivers/net/wireless/ath/ath9k/htc_hst.c:26:51\n index 255 is out of range for type \u0027htc_endpoint [22]\u0027\n CPU: 0 UID: 0 PID: 8 Comm: kworker/0:0 Not tainted 6.11.0-rc6-dirty #14\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Workqueue: events request_firmware_work_func\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x180/0x1b0\n __ubsan_handle_out_of_bounds+0xd4/0x130\n htc_issue_send.constprop.0+0x20c/0x230\n ? _raw_spin_unlock_irqrestore+0x3c/0x70\n ath9k_wmi_cmd+0x41d/0x610\n ? mark_held_locks+0x9f/0xe0\n ...\n\nSince this bug has been confirmed to be caused by insufficient verification\nof conn_rsp_epid, I think it would be appropriate to add a range check for\nconn_rsp_epid to htc_connect_service() to prevent the bug from occurring.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53156", "url": "https://www.suse.com/security/cve/CVE-2024-53156" }, { "category": "external", "summary": "SUSE Bug 1234846 for CVE-2024-53156", "url": "https://bugzilla.suse.com/1234846" }, { "category": "external", "summary": "SUSE Bug 1234847 for CVE-2024-53156", "url": "https://bugzilla.suse.com/1234847" }, { "category": "external", "summary": "SUSE Bug 1234853 for CVE-2024-53156", "url": "https://bugzilla.suse.com/1234853" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53156" }, { "cve": "CVE-2024-53157", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53157" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scpi: Check the DVFS OPP count returned by the firmware\n\nFix a kernel crash with the below call trace when the SCPI firmware\nreturns OPP count of zero.\n\ndvfs_info.opp_count may be zero on some platforms during the reboot\ntest, and the kernel will crash after dereferencing the pointer to\nkcalloc(info-\u003ecount, sizeof(*opp), GFP_KERNEL).\n\n | Unable to handle kernel NULL pointer dereference at virtual address 0000000000000028\n | Mem abort info:\n | ESR = 0x96000004\n | Exception class = DABT (current EL), IL = 32 bits\n | SET = 0, FnV = 0\n | EA = 0, S1PTW = 0\n | Data abort info:\n | ISV = 0, ISS = 0x00000004\n | CM = 0, WnR = 0\n | user pgtable: 4k pages, 48-bit VAs, pgdp = 00000000faefa08c\n | [0000000000000028] pgd=0000000000000000\n | Internal error: Oops: 96000004 [#1] SMP\n | scpi-hwmon: probe of PHYT000D:00 failed with error -110\n | Process systemd-udevd (pid: 1701, stack limit = 0x00000000aaede86c)\n | CPU: 2 PID: 1701 Comm: systemd-udevd Not tainted 4.19.90+ #1\n | Hardware name: PHYTIUM LTD Phytium FT2000/4/Phytium FT2000/4, BIOS\n | pstate: 60000005 (nZCv daif -PAN -UAO)\n | pc : scpi_dvfs_recalc_rate+0x40/0x58 [clk_scpi]\n | lr : clk_register+0x438/0x720\n | Call trace:\n | scpi_dvfs_recalc_rate+0x40/0x58 [clk_scpi]\n | devm_clk_hw_register+0x50/0xa0\n | scpi_clk_ops_init.isra.2+0xa0/0x138 [clk_scpi]\n | scpi_clocks_probe+0x528/0x70c [clk_scpi]\n | platform_drv_probe+0x58/0xa8\n | really_probe+0x260/0x3d0\n | driver_probe_device+0x12c/0x148\n | device_driver_attach+0x74/0x98\n | __driver_attach+0xb4/0xe8\n | bus_for_each_dev+0x88/0xe0\n | driver_attach+0x30/0x40\n | bus_add_driver+0x178/0x2b0\n | driver_register+0x64/0x118\n | __platform_driver_register+0x54/0x60\n | scpi_clocks_driver_init+0x24/0x1000 [clk_scpi]\n | do_one_initcall+0x54/0x220\n | do_init_module+0x54/0x1c8\n | load_module+0x14a4/0x1668\n | __se_sys_finit_module+0xf8/0x110\n | __arm64_sys_finit_module+0x24/0x30\n | el0_svc_common+0x78/0x170\n | el0_svc_handler+0x38/0x78\n | el0_svc+0x8/0x340\n | Code: 937d7c00 a94153f3 a8c27bfd f9400421 (b8606820)\n | ---[ end trace 06feb22469d89fa8 ]---\n | Kernel panic - not syncing: Fatal exception\n | SMP: stopping secondary CPUs\n | Kernel Offset: disabled\n | CPU features: 0x10,a0002008\n | Memory Limit: none", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53157", "url": "https://www.suse.com/security/cve/CVE-2024-53157" }, { "category": "external", "summary": "SUSE Bug 1234827 for CVE-2024-53157", "url": "https://bugzilla.suse.com/1234827" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53157" }, { "cve": "CVE-2024-53158", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53158" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: qcom: geni-se: fix array underflow in geni_se_clk_tbl_get()\n\nThis loop is supposed to break if the frequency returned from\nclk_round_rate() is the same as on the previous iteration. However,\nthat check doesn\u0027t make sense on the first iteration through the loop.\nIt leads to reading before the start of these-\u003eclk_perf_tbl[] array.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53158", "url": "https://www.suse.com/security/cve/CVE-2024-53158" }, { "category": "external", "summary": "SUSE Bug 1234811 for CVE-2024-53158", "url": "https://bugzilla.suse.com/1234811" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53158" }, { "cve": "CVE-2024-53159", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53159" } ], "notes": [ { "category": "general", "text": "This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53159", "url": "https://www.suse.com/security/cve/CVE-2024-53159" }, { "category": "external", "summary": "SUSE Bug 1234848 for CVE-2024-53159", "url": "https://bugzilla.suse.com/1234848" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 0, "baseSeverity": "NONE", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53159" }, { "cve": "CVE-2024-53160", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53160" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nrcu/kvfree: Fix data-race in __mod_timer / kvfree_call_rcu\n\nKCSAN reports a data race when access the krcp-\u003emonitor_work.timer.expires\nvariable in the schedule_delayed_monitor_work() function:\n\n\u003csnip\u003e\nBUG: KCSAN: data-race in __mod_timer / kvfree_call_rcu\n\nread to 0xffff888237d1cce8 of 8 bytes by task 10149 on cpu 1:\n schedule_delayed_monitor_work kernel/rcu/tree.c:3520 [inline]\n kvfree_call_rcu+0x3b8/0x510 kernel/rcu/tree.c:3839\n trie_update_elem+0x47c/0x620 kernel/bpf/lpm_trie.c:441\n bpf_map_update_value+0x324/0x350 kernel/bpf/syscall.c:203\n generic_map_update_batch+0x401/0x520 kernel/bpf/syscall.c:1849\n bpf_map_do_batch+0x28c/0x3f0 kernel/bpf/syscall.c:5143\n __sys_bpf+0x2e5/0x7a0\n __do_sys_bpf kernel/bpf/syscall.c:5741 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5739 [inline]\n __x64_sys_bpf+0x43/0x50 kernel/bpf/syscall.c:5739\n x64_sys_call+0x2625/0x2d60 arch/x86/include/generated/asm/syscalls_64.h:322\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xc9/0x1c0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nwrite to 0xffff888237d1cce8 of 8 bytes by task 56 on cpu 0:\n __mod_timer+0x578/0x7f0 kernel/time/timer.c:1173\n add_timer_global+0x51/0x70 kernel/time/timer.c:1330\n __queue_delayed_work+0x127/0x1a0 kernel/workqueue.c:2523\n queue_delayed_work_on+0xdf/0x190 kernel/workqueue.c:2552\n queue_delayed_work include/linux/workqueue.h:677 [inline]\n schedule_delayed_monitor_work kernel/rcu/tree.c:3525 [inline]\n kfree_rcu_monitor+0x5e8/0x660 kernel/rcu/tree.c:3643\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0x483/0x9a0 kernel/workqueue.c:3310\n worker_thread+0x51d/0x6f0 kernel/workqueue.c:3391\n kthread+0x1d1/0x210 kernel/kthread.c:389\n ret_from_fork+0x4b/0x60 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 0 UID: 0 PID: 56 Comm: kworker/u8:4 Not tainted 6.12.0-rc2-syzkaller-00050-g5b7c893ed5ed #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: events_unbound kfree_rcu_monitor\n\u003csnip\u003e\n\nkfree_rcu_monitor() rearms the work if a \"krcp\" has to be still\noffloaded and this is done without holding krcp-\u003elock, whereas\nthe kvfree_call_rcu() holds it.\n\nFix it by acquiring the \"krcp-\u003elock\" for kfree_rcu_monitor() so\nboth functions do not race anymore.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53160", "url": "https://www.suse.com/security/cve/CVE-2024-53160" }, { "category": "external", "summary": "SUSE Bug 1234810 for CVE-2024-53160", "url": "https://bugzilla.suse.com/1234810" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53160" }, { "cve": "CVE-2024-53161", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53161" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/bluefield: Fix potential integer overflow\n\nThe 64-bit argument for the \"get DIMM info\" SMC call consists of mem_ctrl_idx\nleft-shifted 16 bits and OR-ed with DIMM index. With mem_ctrl_idx defined as\n32-bits wide the left-shift operation truncates the upper 16 bits of\ninformation during the calculation of the SMC argument.\n\nThe mem_ctrl_idx stack variable must be defined as 64-bits wide to prevent any\npotential integer overflow, i.e. loss of data from upper 16 bits.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53161", "url": "https://www.suse.com/security/cve/CVE-2024-53161" }, { "category": "external", "summary": "SUSE Bug 1234856 for CVE-2024-53161", "url": "https://bugzilla.suse.com/1234856" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53161" }, { "cve": "CVE-2024-53162", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53162" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat/qat_4xxx - fix off by one in uof_get_name()\n\nThe fw_objs[] array has \"num_objs\" elements so the \u003e needs to be \u003e= to\nprevent an out of bounds read.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53162", "url": "https://www.suse.com/security/cve/CVE-2024-53162" }, { "category": "external", "summary": "SUSE Bug 1234843 for CVE-2024-53162", "url": "https://bugzilla.suse.com/1234843" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53162" }, { "cve": "CVE-2024-53166", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53166" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix bfqq uaf in bfq_limit_depth()\n\nSet new allocated bfqq to bic or remove freed bfqq from bic are both\nprotected by bfqd-\u003elock, however bfq_limit_depth() is deferencing bfqq\nfrom bic without the lock, this can lead to UAF if the io_context is\nshared by multiple tasks.\n\nFor example, test bfq with io_uring can trigger following UAF in v6.6:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in bfqq_group+0x15/0x50\n\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x47/0x80\n print_address_description.constprop.0+0x66/0x300\n print_report+0x3e/0x70\n kasan_report+0xb4/0xf0\n bfqq_group+0x15/0x50\n bfqq_request_over_limit+0x130/0x9a0\n bfq_limit_depth+0x1b5/0x480\n __blk_mq_alloc_requests+0x2b5/0xa00\n blk_mq_get_new_requests+0x11d/0x1d0\n blk_mq_submit_bio+0x286/0xb00\n submit_bio_noacct_nocheck+0x331/0x400\n __block_write_full_folio+0x3d0/0x640\n writepage_cb+0x3b/0xc0\n write_cache_pages+0x254/0x6c0\n write_cache_pages+0x254/0x6c0\n do_writepages+0x192/0x310\n filemap_fdatawrite_wbc+0x95/0xc0\n __filemap_fdatawrite_range+0x99/0xd0\n filemap_write_and_wait_range.part.0+0x4d/0xa0\n blkdev_read_iter+0xef/0x1e0\n io_read+0x1b6/0x8a0\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork_asm+0x1b/0x30\n \u003c/TASK\u003e\n\nAllocated by task 808602:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_slab_alloc+0x83/0x90\n kmem_cache_alloc_node+0x1b1/0x6d0\n bfq_get_queue+0x138/0xfa0\n bfq_get_bfqq_handle_split+0xe3/0x2c0\n bfq_init_rq+0x196/0xbb0\n bfq_insert_request.isra.0+0xb5/0x480\n bfq_insert_requests+0x156/0x180\n blk_mq_insert_request+0x15d/0x440\n blk_mq_submit_bio+0x8a4/0xb00\n submit_bio_noacct_nocheck+0x331/0x400\n __blkdev_direct_IO_async+0x2dd/0x330\n blkdev_write_iter+0x39a/0x450\n io_write+0x22a/0x840\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork+0x2d/0x50\n ret_from_fork_asm+0x1b/0x30\n\nFreed by task 808589:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x27/0x40\n __kasan_slab_free+0x126/0x1b0\n kmem_cache_free+0x10c/0x750\n bfq_put_queue+0x2dd/0x770\n __bfq_insert_request.isra.0+0x155/0x7a0\n bfq_insert_request.isra.0+0x122/0x480\n bfq_insert_requests+0x156/0x180\n blk_mq_dispatch_plug_list+0x528/0x7e0\n blk_mq_flush_plug_list.part.0+0xe5/0x590\n __blk_flush_plug+0x3b/0x90\n blk_finish_plug+0x40/0x60\n do_writepages+0x19d/0x310\n filemap_fdatawrite_wbc+0x95/0xc0\n __filemap_fdatawrite_range+0x99/0xd0\n filemap_write_and_wait_range.part.0+0x4d/0xa0\n blkdev_read_iter+0xef/0x1e0\n io_read+0x1b6/0x8a0\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork+0x2d/0x50\n ret_from_fork_asm+0x1b/0x30\n\nFix the problem by protecting bic_to_bfqq() with bfqd-\u003elock.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53166", "url": "https://www.suse.com/security/cve/CVE-2024-53166" }, { "category": "external", "summary": "SUSE Bug 1234884 for CVE-2024-53166", "url": "https://bugzilla.suse.com/1234884" }, { "category": "external", "summary": "SUSE Bug 1234885 for CVE-2024-53166", "url": "https://bugzilla.suse.com/1234885" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53166" }, { "cve": "CVE-2024-53169", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53169" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-fabrics: fix kernel crash while shutting down controller\n\nThe nvme keep-alive operation, which executes at a periodic interval,\ncould potentially sneak in while shutting down a fabric controller.\nThis may lead to a race between the fabric controller admin queue\ndestroy code path (invoked while shutting down controller) and hw/hctx\nqueue dispatcher called from the nvme keep-alive async request queuing\noperation. This race could lead to the kernel crash shown below:\n\nCall Trace:\n autoremove_wake_function+0x0/0xbc (unreliable)\n __blk_mq_sched_dispatch_requests+0x114/0x24c\n blk_mq_sched_dispatch_requests+0x44/0x84\n blk_mq_run_hw_queue+0x140/0x220\n nvme_keep_alive_work+0xc8/0x19c [nvme_core]\n process_one_work+0x200/0x4e0\n worker_thread+0x340/0x504\n kthread+0x138/0x140\n start_kernel_thread+0x14/0x18\n\nWhile shutting down fabric controller, if nvme keep-alive request sneaks\nin then it would be flushed off. The nvme_keep_alive_end_io function is\nthen invoked to handle the end of the keep-alive operation which\ndecrements the admin-\u003eq_usage_counter and assuming this is the last/only\nrequest in the admin queue then the admin-\u003eq_usage_counter becomes zero.\nIf that happens then blk-mq destroy queue operation (blk_mq_destroy_\nqueue()) which could be potentially running simultaneously on another\ncpu (as this is the controller shutdown code path) would forward\nprogress and deletes the admin queue. So, now from this point onward\nwe are not supposed to access the admin queue resources. However the\nissue here\u0027s that the nvme keep-alive thread running hw/hctx queue\ndispatch operation hasn\u0027t yet finished its work and so it could still\npotentially access the admin queue resource while the admin queue had\nbeen already deleted and that causes the above crash.\n\nThe above kernel crash is regression caused due to changes implemented\nin commit a54a93d0e359 (\"nvme: move stopping keep-alive into\nnvme_uninit_ctrl()\"). Ideally we should stop keep-alive before destroyin\ng the admin queue and freeing the admin tagset so that it wouldn\u0027t sneak\nin during the shutdown operation. However we removed the keep alive stop\noperation from the beginning of the controller shutdown code path in commit\na54a93d0e359 (\"nvme: move stopping keep-alive into nvme_uninit_ctrl()\")\nand added it under nvme_uninit_ctrl() which executes very late in the\nshutdown code path after the admin queue is destroyed and its tagset is\nremoved. So this change created the possibility of keep-alive sneaking in\nand interfering with the shutdown operation and causing observed kernel\ncrash.\n\nTo fix the observed crash, we decided to move nvme_stop_keep_alive() from\nnvme_uninit_ctrl() to nvme_remove_admin_tag_set(). This change would ensure\nthat we don\u0027t forward progress and delete the admin queue until the keep-\nalive operation is finished (if it\u0027s in-flight) or cancelled and that would\nhelp contain the race condition explained above and hence avoid the crash.\n\nMoving nvme_stop_keep_alive() to nvme_remove_admin_tag_set() instead of\nadding nvme_stop_keep_alive() to the beginning of the controller shutdown\ncode path in nvme_stop_ctrl(), as was the case earlier before commit\na54a93d0e359 (\"nvme: move stopping keep-alive into nvme_uninit_ctrl()\"),\nwould help save one callsite of nvme_stop_keep_alive().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53169", "url": "https://www.suse.com/security/cve/CVE-2024-53169" }, { "category": "external", "summary": "SUSE Bug 1234900 for CVE-2024-53169", "url": "https://bugzilla.suse.com/1234900" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53169" }, { "cve": "CVE-2024-53171", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53171" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit\n\nAfter an insertion in TNC, the tree might split and cause a node to\nchange its `znode-\u003eparent`. A further deletion of other nodes in the\ntree (which also could free the nodes), the aforementioned node\u0027s\n`znode-\u003ecparent` could still point to a freed node. This\n`znode-\u003ecparent` may not be updated when getting nodes to commit in\n`ubifs_tnc_start_commit()`. This could then trigger a use-after-free\nwhen accessing the `znode-\u003ecparent` in `write_index()` in\n`ubifs_tnc_end_commit()`.\n\nThis can be triggered by running\n\n rm -f /etc/test-file.bin\n dd if=/dev/urandom of=/etc/test-file.bin bs=1M count=60 conv=fsync\n\nin a loop, and with `CONFIG_UBIFS_FS_AUTHENTICATION`. KASAN then\nreports:\n\n BUG: KASAN: use-after-free in ubifs_tnc_end_commit+0xa5c/0x1950\n Write of size 32 at addr ffffff800a3af86c by task ubifs_bgt0_20/153\n\n Call trace:\n dump_backtrace+0x0/0x340\n show_stack+0x18/0x24\n dump_stack_lvl+0x9c/0xbc\n print_address_description.constprop.0+0x74/0x2b0\n kasan_report+0x1d8/0x1f0\n kasan_check_range+0xf8/0x1a0\n memcpy+0x84/0xf4\n ubifs_tnc_end_commit+0xa5c/0x1950\n do_commit+0x4e0/0x1340\n ubifs_bg_thread+0x234/0x2e0\n kthread+0x36c/0x410\n ret_from_fork+0x10/0x20\n\n Allocated by task 401:\n kasan_save_stack+0x38/0x70\n __kasan_kmalloc+0x8c/0xd0\n __kmalloc+0x34c/0x5bc\n tnc_insert+0x140/0x16a4\n ubifs_tnc_add+0x370/0x52c\n ubifs_jnl_write_data+0x5d8/0x870\n do_writepage+0x36c/0x510\n ubifs_writepage+0x190/0x4dc\n __writepage+0x58/0x154\n write_cache_pages+0x394/0x830\n do_writepages+0x1f0/0x5b0\n filemap_fdatawrite_wbc+0x170/0x25c\n file_write_and_wait_range+0x140/0x190\n ubifs_fsync+0xe8/0x290\n vfs_fsync_range+0xc0/0x1e4\n do_fsync+0x40/0x90\n __arm64_sys_fsync+0x34/0x50\n invoke_syscall.constprop.0+0xa8/0x260\n do_el0_svc+0xc8/0x1f0\n el0_svc+0x34/0x70\n el0t_64_sync_handler+0x108/0x114\n el0t_64_sync+0x1a4/0x1a8\n\n Freed by task 403:\n kasan_save_stack+0x38/0x70\n kasan_set_track+0x28/0x40\n kasan_set_free_info+0x28/0x4c\n __kasan_slab_free+0xd4/0x13c\n kfree+0xc4/0x3a0\n tnc_delete+0x3f4/0xe40\n ubifs_tnc_remove_range+0x368/0x73c\n ubifs_tnc_remove_ino+0x29c/0x2e0\n ubifs_jnl_delete_inode+0x150/0x260\n ubifs_evict_inode+0x1d4/0x2e4\n evict+0x1c8/0x450\n iput+0x2a0/0x3c4\n do_unlinkat+0x2cc/0x490\n __arm64_sys_unlinkat+0x90/0x100\n invoke_syscall.constprop.0+0xa8/0x260\n do_el0_svc+0xc8/0x1f0\n el0_svc+0x34/0x70\n el0t_64_sync_handler+0x108/0x114\n el0t_64_sync+0x1a4/0x1a8\n\nThe offending `memcpy()` in `ubifs_copy_hash()` has a use-after-free\nwhen a node becomes root in TNC but still has a `cparent` to an already\nfreed node. More specifically, consider the following TNC:\n\n zroot\n /\n /\n zp1\n /\n /\n zn\n\nInserting a new node `zn_new` with a key smaller then `zn` will trigger\na split in `tnc_insert()` if `zp1` is full:\n\n zroot\n / \\\n / \\\n zp1 zp2\n / \\\n / \\\n zn_new zn\n\n`zn-\u003eparent` has now been moved to `zp2`, *but* `zn-\u003ecparent` still\npoints to `zp1`.\n\nNow, consider a removal of all the nodes _except_ `zn`. Just when\n`tnc_delete()` is about to delete `zroot` and `zp2`:\n\n zroot\n \\\n \\\n zp2\n \\\n \\\n zn\n\n`zroot` and `zp2` get freed and the tree collapses:\n\n zn\n\n`zn` now becomes the new `zroot`.\n\n`get_znodes_to_commit()` will now only find `zn`, the new `zroot`, and\n`write_index()` will check its `znode-\u003ecparent` that wrongly points to\nthe already freed `zp1`. `ubifs_copy_hash()` thus gets wrongly called\nwith `znode-\u003ecparent-\u003ezbranch[znode-\u003eiip].hash` that triggers the\nuse-after-free!\n\nFix this by explicitly setting `znode-\u003ecparent` to `NULL` in\n`get_znodes_to_commit()` for the root node. The search for the dirty\nnodes\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53171", "url": "https://www.suse.com/security/cve/CVE-2024-53171" }, { "category": "external", "summary": "SUSE Bug 1234889 for CVE-2024-53171", "url": "https://bugzilla.suse.com/1234889" }, { "category": "external", "summary": "SUSE Bug 1236234 for CVE-2024-53171", "url": "https://bugzilla.suse.com/1236234" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53171" }, { "cve": "CVE-2024-53173", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53173" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4.0: Fix a use-after-free problem in the asynchronous open()\n\nYang Erkun reports that when two threads are opening files at the same\ntime, and are forced to abort before a reply is seen, then the call to\nnfs_release_seqid() in nfs4_opendata_free() can result in a\nuse-after-free of the pointer to the defunct rpc task of the other\nthread.\nThe fix is to ensure that if the RPC call is aborted before the call to\nnfs_wait_on_sequence() is complete, then we must call nfs_release_seqid()\nin nfs4_open_release() before the rpc_task is freed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53173", "url": "https://www.suse.com/security/cve/CVE-2024-53173" }, { "category": "external", "summary": "SUSE Bug 1234853 for CVE-2024-53173", "url": "https://bugzilla.suse.com/1234853" }, { "category": "external", "summary": "SUSE Bug 1234891 for CVE-2024-53173", "url": "https://bugzilla.suse.com/1234891" }, { "category": "external", "summary": "SUSE Bug 1234892 for CVE-2024-53173", "url": "https://bugzilla.suse.com/1234892" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53173" }, { "cve": "CVE-2024-53174", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53174" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: make sure cache entry active before cache_show\n\nThe function `c_show` was called with protection from RCU. This only\nensures that `cp` will not be freed. Therefore, the reference count for\n`cp` can drop to zero, which will trigger a refcount use-after-free\nwarning when `cache_get` is called. To resolve this issue, use\n`cache_get_rcu` to ensure that `cp` remains active.\n\n------------[ cut here ]------------\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 7 PID: 822 at lib/refcount.c:25\nrefcount_warn_saturate+0xb1/0x120\nCPU: 7 UID: 0 PID: 822 Comm: cat Not tainted 6.12.0-rc3+ #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xb1/0x120\n\nCall Trace:\n \u003cTASK\u003e\n c_show+0x2fc/0x380 [sunrpc]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n proc_reg_read+0xe1/0x140\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53174", "url": "https://www.suse.com/security/cve/CVE-2024-53174" }, { "category": "external", "summary": "SUSE Bug 1234899 for CVE-2024-53174", "url": "https://bugzilla.suse.com/1234899" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53174" }, { "cve": "CVE-2024-53179", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53179" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free of signing key\n\nCustomers have reported use-after-free in @ses-\u003eauth_key.response with\nSMB2.1 + sign mounts which occurs due to following race:\n\ntask A task B\ncifs_mount()\n dfs_mount_share()\n get_session()\n cifs_mount_get_session() cifs_send_recv()\n cifs_get_smb_ses() compound_send_recv()\n cifs_setup_session() smb2_setup_request()\n kfree_sensitive() smb2_calc_signature()\n crypto_shash_setkey() *UAF*\n\nFix this by ensuring that we have a valid @ses-\u003eauth_key.response by\nchecking whether @ses-\u003eses_status is SES_GOOD or SES_EXITING with\n@ses-\u003eses_lock held. After commit 24a9799aa8ef (\"smb: client: fix UAF\nin smb2_reconnect_server()\"), we made sure to call -\u003elogoff() only\nwhen @ses was known to be good (e.g. valid -\u003eauth_key.response), so\nit\u0027s safe to access signing key when @ses-\u003eses_status == SES_EXITING.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53179", "url": "https://www.suse.com/security/cve/CVE-2024-53179" }, { "category": "external", "summary": "SUSE Bug 1234921 for CVE-2024-53179", "url": "https://bugzilla.suse.com/1234921" }, { "category": "external", "summary": "SUSE Bug 1234927 for CVE-2024-53179", "url": "https://bugzilla.suse.com/1234927" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53179" }, { "cve": "CVE-2024-53180", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53180" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Add sanity NULL check for the default mmap fault handler\n\nA driver might allow the mmap access before initializing its\nruntime-\u003edma_area properly. Add a proper NULL check before passing to\nvirt_to_page() for avoiding a panic.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53180", "url": "https://www.suse.com/security/cve/CVE-2024-53180" }, { "category": "external", "summary": "SUSE Bug 1234929 for CVE-2024-53180", "url": "https://bugzilla.suse.com/1234929" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53180" }, { "cve": "CVE-2024-53188", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53188" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix crash when unbinding\n\nIf there is an error during some initialization related to firmware,\nthe function ath12k_dp_cc_cleanup is called to release resources.\nHowever this is released again when the device is unbinded (ath12k_pci),\nand we get:\nBUG: kernel NULL pointer dereference, address: 0000000000000020\nat RIP: 0010:ath12k_dp_cc_cleanup.part.0+0xb6/0x500 [ath12k]\nCall Trace:\nath12k_dp_cc_cleanup\nath12k_dp_free\nath12k_core_deinit\nath12k_pci_remove\n...\n\nThe issue is always reproducible from a VM because the MSI addressing\ninitialization is failing.\n\nIn order to fix the issue, just set to NULL the released structure in\nath12k_dp_cc_cleanup at the end.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53188", "url": "https://www.suse.com/security/cve/CVE-2024-53188" }, { "category": "external", "summary": "SUSE Bug 1234948 for CVE-2024-53188", "url": "https://bugzilla.suse.com/1234948" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53188" }, { "cve": "CVE-2024-53190", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53190" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtlwifi: Drastically reduce the attempts to read efuse in case of failures\n\nSyzkaller reported a hung task with uevent_show() on stack trace. That\nspecific issue was addressed by another commit [0], but even with that\nfix applied (for example, running v6.12-rc5) we face another type of hung\ntask that comes from the same reproducer [1]. By investigating that, we\ncould narrow it to the following path:\n\n(a) Syzkaller emulates a Realtek USB WiFi adapter using raw-gadget and\ndummy_hcd infrastructure.\n\n(b) During the probe of rtl8192cu, the driver ends-up performing an efuse\nread procedure (which is related to EEPROM load IIUC), and here lies the\nissue: the function read_efuse() calls read_efuse_byte() many times, as\nloop iterations depending on the efuse size (in our example, 512 in total).\n\nThis procedure for reading efuse bytes relies in a loop that performs an\nI/O read up to *10k* times in case of failures. We measured the time of\nthe loop inside read_efuse_byte() alone, and in this reproducer (which\ninvolves the dummy_hcd emulation layer), it takes 15 seconds each. As a\nconsequence, we have the driver stuck in its probe routine for big time,\nexposing a stack trace like below if we attempt to reboot the system, for\nexample:\n\ntask:kworker/0:3 state:D stack:0 pid:662 tgid:662 ppid:2 flags:0x00004000\nWorkqueue: usb_hub_wq hub_event\nCall Trace:\n __schedule+0xe22/0xeb6\n schedule_timeout+0xe7/0x132\n __wait_for_common+0xb5/0x12e\n usb_start_wait_urb+0xc5/0x1ef\n ? usb_alloc_urb+0x95/0xa4\n usb_control_msg+0xff/0x184\n _usbctrl_vendorreq_sync+0xa0/0x161\n _usb_read_sync+0xb3/0xc5\n read_efuse_byte+0x13c/0x146\n read_efuse+0x351/0x5f0\n efuse_read_all_map+0x42/0x52\n rtl_efuse_shadow_map_update+0x60/0xef\n rtl_get_hwinfo+0x5d/0x1c2\n rtl92cu_read_eeprom_info+0x10a/0x8d5\n ? rtl92c_read_chip_version+0x14f/0x17e\n rtl_usb_probe+0x323/0x851\n usb_probe_interface+0x278/0x34b\n really_probe+0x202/0x4a4\n __driver_probe_device+0x166/0x1b2\n driver_probe_device+0x2f/0xd8\n [...]\n\nWe propose hereby to drastically reduce the attempts of doing the I/O\nreads in case of failures, restricted to USB devices (given that\nthey\u0027re inherently slower than PCIe ones). By retrying up to 10 times\n(instead of 10000), we got reponsiveness in the reproducer, while seems\nreasonable to believe that there\u0027s no sane USB device implementation in\nthe field requiring this amount of retries at every I/O read in order\nto properly work. Based on that assumption, it\u0027d be good to have it\nbackported to stable but maybe not since driver implementation (the 10k\nnumber comes from day 0), perhaps up to 6.x series makes sense.\n\n[0] Commit 15fffc6a5624 (\"driver core: Fix uevent_show() vs driver detach race\")\n\n[1] A note about that: this syzkaller report presents multiple reproducers\nthat differs by the type of emulated USB device. For this specific case,\ncheck the entry from 2024/08/08 06:23 in the list of crashes; the C repro\nis available at https://syzkaller.appspot.com/text?tag=ReproC\u0026x=1521fc83980000.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53190", "url": "https://www.suse.com/security/cve/CVE-2024-53190" }, { "category": "external", "summary": "SUSE Bug 1234950 for CVE-2024-53190", "url": "https://bugzilla.suse.com/1234950" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 2.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "low" } ], "title": "CVE-2024-53190" }, { "cve": "CVE-2024-53191", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53191" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix warning when unbinding\n\nIf there is an error during some initialization related to firmware,\nthe buffers dp-\u003etx_ring[i].tx_status are released.\nHowever this is released again when the device is unbinded (ath12k_pci),\nand we get:\nWARNING: CPU: 0 PID: 2098 at mm/slub.c:4689 free_large_kmalloc+0x4d/0x80\nCall Trace:\nfree_large_kmalloc\nath12k_dp_free\nath12k_core_deinit\nath12k_pci_remove\n...\n\nThe issue is always reproducible from a VM because the MSI addressing\ninitialization is failing.\n\nIn order to fix the issue, just set the buffers to NULL after releasing in\norder to avoid the double free.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53191", "url": "https://www.suse.com/security/cve/CVE-2024-53191" }, { "category": "external", "summary": "SUSE Bug 1234952 for CVE-2024-53191", "url": "https://bugzilla.suse.com/1234952" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53191" }, { "cve": "CVE-2024-53200", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53200" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null check for pipe_ctx-\u003eplane_state in hwss_setup_dpp\n\nThis commit addresses a null pointer dereference issue in\nhwss_setup_dpp(). The issue could occur when pipe_ctx-\u003eplane_state is\nnull. The fix adds a check to ensure `pipe_ctx-\u003eplane_state` is not null\nbefore accessing. This prevents a null pointer dereference.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53200", "url": "https://www.suse.com/security/cve/CVE-2024-53200" }, { "category": "external", "summary": "SUSE Bug 1234968 for CVE-2024-53200", "url": "https://bugzilla.suse.com/1234968" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53200" }, { "cve": "CVE-2024-53201", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53201" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null check for pipe_ctx-\u003eplane_state in dcn20_program_pipe\n\nThis commit addresses a null pointer dereference issue in\ndcn20_program_pipe(). Previously, commit 8e4ed3cf1642 (\"drm/amd/display:\nAdd null check for pipe_ctx-\u003eplane_state in dcn20_program_pipe\")\npartially fixed the null pointer dereference issue. However, in\ndcn20_update_dchubp_dpp(), the variable pipe_ctx is passed in, and\nplane_state is accessed again through pipe_ctx. Multiple if statements\ndirectly call attributes of plane_state, leading to potential null\npointer dereference issues. This patch adds necessary null checks to\nensure stability.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53201", "url": "https://www.suse.com/security/cve/CVE-2024-53201" }, { "category": "external", "summary": "SUSE Bug 1234969 for CVE-2024-53201", "url": "https://bugzilla.suse.com/1234969" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53201" }, { "cve": "CVE-2024-53202", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53202" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware_loader: Fix possible resource leak in fw_log_firmware_info()\n\nThe alg instance should be released under the exception path, otherwise\nthere may be resource leak here.\n\nTo mitigate this, free the alg instance with crypto_free_shash when kmalloc\nfails.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53202", "url": "https://www.suse.com/security/cve/CVE-2024-53202" }, { "category": "external", "summary": "SUSE Bug 1234970 for CVE-2024-53202", "url": "https://bugzilla.suse.com/1234970" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 3.3, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53202" }, { "cve": "CVE-2024-53206", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53206" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Fix use-after-free of nreq in reqsk_timer_handler().\n\nThe cited commit replaced inet_csk_reqsk_queue_drop_and_put() with\n__inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_handler().\n\nThen, oreq should be passed to reqsk_put() instead of req; otherwise\nuse-after-free of nreq could happen when reqsk is migrated but the\nretry attempt failed (e.g. due to timeout).\n\nLet\u0027s pass oreq to reqsk_put().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53206", "url": "https://www.suse.com/security/cve/CVE-2024-53206" }, { "category": "external", "summary": "SUSE Bug 1234960 for CVE-2024-53206", "url": "https://bugzilla.suse.com/1234960" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53206" }, { "cve": "CVE-2024-53207", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53207" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix possible deadlocks\n\nThis fixes possible deadlocks like the following caused by\nhci_cmd_sync_dequeue causing the destroy function to run:\n\n INFO: task kworker/u19:0:143 blocked for more than 120 seconds.\n Tainted: G W O 6.8.0-2024-03-19-intel-next-iLS-24ww14 #1\n \"echo 0 \u003e /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u19:0 state:D stack:0 pid:143 tgid:143 ppid:2 flags:0x00004000\n Workqueue: hci0 hci_cmd_sync_work [bluetooth]\n Call Trace:\n \u003cTASK\u003e\n __schedule+0x374/0xaf0\n schedule+0x3c/0xf0\n schedule_preempt_disabled+0x1c/0x30\n __mutex_lock.constprop.0+0x3ef/0x7a0\n __mutex_lock_slowpath+0x13/0x20\n mutex_lock+0x3c/0x50\n mgmt_set_connectable_complete+0xa4/0x150 [bluetooth]\n ? kfree+0x211/0x2a0\n hci_cmd_sync_dequeue+0xae/0x130 [bluetooth]\n ? __pfx_cmd_complete_rsp+0x10/0x10 [bluetooth]\n cmd_complete_rsp+0x26/0x80 [bluetooth]\n mgmt_pending_foreach+0x4d/0x70 [bluetooth]\n __mgmt_power_off+0x8d/0x180 [bluetooth]\n ? _raw_spin_unlock_irq+0x23/0x40\n hci_dev_close_sync+0x445/0x5b0 [bluetooth]\n hci_set_powered_sync+0x149/0x250 [bluetooth]\n set_powered_sync+0x24/0x60 [bluetooth]\n hci_cmd_sync_work+0x90/0x150 [bluetooth]\n process_one_work+0x13e/0x300\n worker_thread+0x2f7/0x420\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x107/0x140\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3d/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53207", "url": "https://www.suse.com/security/cve/CVE-2024-53207" }, { "category": "external", "summary": "SUSE Bug 1234907 for CVE-2024-53207", "url": "https://bugzilla.suse.com/1234907" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53207" }, { "cve": "CVE-2024-53208", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53208" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync\n\nThis fixes the following crash:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in set_powered_sync+0x3a/0xc0 net/bluetooth/mgmt.c:1353\nRead of size 8 at addr ffff888029b4dd18 by task kworker/u9:0/54\n\nCPU: 1 UID: 0 PID: 54 Comm: kworker/u9:0 Not tainted 6.11.0-rc6-syzkaller-01155-gf723224742fc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n \u003cTASK\u003e\n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\nq kasan_report+0x143/0x180 mm/kasan/report.c:601\n set_powered_sync+0x3a/0xc0 net/bluetooth/mgmt.c:1353\n hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:328\n process_one_work kernel/workqueue.c:3231 [inline]\n process_scheduled_works+0xa2c/0x1830 kernel/workqueue.c:3312\n worker_thread+0x86d/0xd10 kernel/workqueue.c:3389\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \u003c/TASK\u003e\n\nAllocated by task 5247:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:370 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:387\n kasan_kmalloc include/linux/kasan.h:211 [inline]\n __kmalloc_cache_noprof+0x19c/0x2c0 mm/slub.c:4193\n kmalloc_noprof include/linux/slab.h:681 [inline]\n kzalloc_noprof include/linux/slab.h:807 [inline]\n mgmt_pending_new+0x65/0x250 net/bluetooth/mgmt_util.c:269\n mgmt_pending_add+0x36/0x120 net/bluetooth/mgmt_util.c:296\n set_powered+0x3cd/0x5e0 net/bluetooth/mgmt.c:1394\n hci_mgmt_cmd+0xc47/0x11d0 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x7b8/0x11c0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xa72/0xc90 fs/read_write.c:590\n ksys_write+0x1a0/0x2c0 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 5246:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2256 [inline]\n slab_free mm/slub.c:4477 [inline]\n kfree+0x149/0x360 mm/slub.c:4598\n settings_rsp+0x2bc/0x390 net/bluetooth/mgmt.c:1443\n mgmt_pending_foreach+0xd1/0x130 net/bluetooth/mgmt_util.c:259\n __mgmt_power_off+0x112/0x420 net/bluetooth/mgmt.c:9455\n hci_dev_close_sync+0x665/0x11a0 net/bluetooth/hci_sync.c:5191\n hci_dev_do_close net/bluetooth/hci_core.c:483 [inline]\n hci_dev_close+0x112/0x210 net/bluetooth/hci_core.c:508\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83gv\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53208", "url": "https://www.suse.com/security/cve/CVE-2024-53208" }, { "category": "external", "summary": "SUSE Bug 1234909 for CVE-2024-53208", "url": "https://bugzilla.suse.com/1234909" }, { "category": "external", "summary": "SUSE Bug 1236244 for CVE-2024-53208", "url": "https://bugzilla.suse.com/1236244" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53208" }, { "cve": "CVE-2024-53209", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53209" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix receive ring space parameters when XDP is active\n\nThe MTU setting at the time an XDP multi-buffer is attached\ndetermines whether the aggregation ring will be used and the\nrx_skb_func handler. This is done in bnxt_set_rx_skb_mode().\n\nIf the MTU is later changed, the aggregation ring setting may need\nto be changed and it may become out-of-sync with the settings\ninitially done in bnxt_set_rx_skb_mode(). This may result in\nrandom memory corruption and crashes as the HW may DMA data larger\nthan the allocated buffer size, such as:\n\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 17 PID: 0 Comm: swapper/17 Kdump: loaded Tainted: G S OE 6.1.0-226bf9805506 #1\nHardware name: Wiwynn Delta Lake PVT BZA.02601.0150/Delta Lake-Class1, BIOS F0E_3A12 08/26/2021\nRIP: 0010:bnxt_rx_pkt+0xe97/0x1ae0 [bnxt_en]\nCode: 8b 95 70 ff ff ff 4c 8b 9d 48 ff ff ff 66 41 89 87 b4 00 00 00 e9 0b f7 ff ff 0f b7 43 0a 49 8b 95 a8 04 00 00 25 ff 0f 00 00 \u003c0f\u003e b7 14 42 48 c1 e2 06 49 03 95 a0 04 00 00 0f b6 42 33f\nRSP: 0018:ffffa19f40cc0d18 EFLAGS: 00010202\nRAX: 00000000000001e0 RBX: ffff8e2c805c6100 RCX: 00000000000007ff\nRDX: 0000000000000000 RSI: ffff8e2c271ab990 RDI: ffff8e2c84f12380\nRBP: ffffa19f40cc0e48 R08: 000000000001000d R09: 974ea2fcddfa4cbf\nR10: 0000000000000000 R11: ffffa19f40cc0ff8 R12: ffff8e2c94b58980\nR13: ffff8e2c952d6600 R14: 0000000000000016 R15: ffff8e2c271ab990\nFS: 0000000000000000(0000) GS:ffff8e3b3f840000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000000003c0 CR3: 0000000e8580a004 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \u003cIRQ\u003e\n __bnxt_poll_work+0x1c2/0x3e0 [bnxt_en]\n\nTo address the issue, we now call bnxt_set_rx_skb_mode() within\nbnxt_change_mtu() to properly set the AGG rings configuration and\nupdate rx_skb_func based on the new MTU value.\nAdditionally, BNXT_FLAG_NO_AGG_RINGS is cleared at the beginning of\nbnxt_set_rx_skb_mode() to make sure it gets set or cleared based on\nthe current MTU.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53209", "url": "https://www.suse.com/security/cve/CVE-2024-53209" }, { "category": "external", "summary": "SUSE Bug 1235002 for CVE-2024-53209", "url": "https://bugzilla.suse.com/1235002" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53209" }, { "cve": "CVE-2024-53210", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53210" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/iucv: MSG_PEEK causes memory leak in iucv_sock_destruct()\n\nPassing MSG_PEEK flag to skb_recv_datagram() increments skb refcount\n(skb-\u003eusers) and iucv_sock_recvmsg() does not decrement skb refcount\nat exit.\nThis results in skb memory leak in skb_queue_purge() and WARN_ON in\niucv_sock_destruct() during socket close. To fix this decrease\nskb refcount by one if MSG_PEEK is set in order to prevent memory\nleak and WARN_ON.\n\nWARNING: CPU: 2 PID: 6292 at net/iucv/af_iucv.c:286 iucv_sock_destruct+0x144/0x1a0 [af_iucv]\nCPU: 2 PID: 6292 Comm: afiucv_test_msg Kdump: loaded Tainted: G W 6.10.0-rc7 #1\nHardware name: IBM 3931 A01 704 (z/VM 7.3.0)\nCall Trace:\n [\u003c001587c682c4aa98\u003e] iucv_sock_destruct+0x148/0x1a0 [af_iucv]\n [\u003c001587c682c4a9d0\u003e] iucv_sock_destruct+0x80/0x1a0 [af_iucv]\n [\u003c001587c704117a32\u003e] __sk_destruct+0x52/0x550\n [\u003c001587c704104a54\u003e] __sock_release+0xa4/0x230\n [\u003c001587c704104c0c\u003e] sock_close+0x2c/0x40\n [\u003c001587c702c5f5a8\u003e] __fput+0x2e8/0x970\n [\u003c001587c7024148c4\u003e] task_work_run+0x1c4/0x2c0\n [\u003c001587c7023b0716\u003e] do_exit+0x996/0x1050\n [\u003c001587c7023b13aa\u003e] do_group_exit+0x13a/0x360\n [\u003c001587c7023b1626\u003e] __s390x_sys_exit_group+0x56/0x60\n [\u003c001587c7022bccca\u003e] do_syscall+0x27a/0x380\n [\u003c001587c7049a6a0c\u003e] __do_syscall+0x9c/0x160\n [\u003c001587c7049ce8a8\u003e] system_call+0x70/0x98\n Last Breaking-Event-Address:\n [\u003c001587c682c4a9d4\u003e] iucv_sock_destruct+0x84/0x1a0 [af_iucv]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53210", "url": "https://www.suse.com/security/cve/CVE-2024-53210" }, { "category": "external", "summary": "SUSE Bug 1234971 for CVE-2024-53210", "url": "https://bugzilla.suse.com/1234971" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53210" }, { "cve": "CVE-2024-53213", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53213" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: lan78xx: Fix double free issue with interrupt buffer allocation\n\nIn lan78xx_probe(), the buffer `buf` was being freed twice: once\nimplicitly through `usb_free_urb(dev-\u003eurb_intr)` with the\n`URB_FREE_BUFFER` flag and again explicitly by `kfree(buf)`. This caused\na double free issue.\n\nTo resolve this, reordered `kmalloc()` and `usb_alloc_urb()` calls to\nsimplify the initialization sequence and removed the redundant\n`kfree(buf)`. Now, `buf` is allocated after `usb_alloc_urb()`, ensuring\nit is correctly managed by `usb_fill_int_urb()` and freed by\n`usb_free_urb()` as intended.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53213", "url": "https://www.suse.com/security/cve/CVE-2024-53213" }, { "category": "external", "summary": "SUSE Bug 1234973 for CVE-2024-53213", "url": "https://bugzilla.suse.com/1234973" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53213" }, { "cve": "CVE-2024-53214", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53214" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/pci: Properly hide first-in-list PCIe extended capability\n\nThere are cases where a PCIe extended capability should be hidden from\nthe user. For example, an unknown capability (i.e., capability with ID\ngreater than PCI_EXT_CAP_ID_MAX) or a capability that is intentionally\nchosen to be hidden from the user.\n\nHiding a capability is done by virtualizing and modifying the \u0027Next\nCapability Offset\u0027 field of the previous capability so it points to the\ncapability after the one that should be hidden.\n\nThe special case where the first capability in the list should be hidden\nis handled differently because there is no previous capability that can\nbe modified. In this case, the capability ID and version are zeroed\nwhile leaving the next pointer intact. This hides the capability and\nleaves an anchor for the rest of the capability list.\n\nHowever, today, hiding the first capability in the list is not done\nproperly if the capability is unknown, as struct\nvfio_pci_core_device-\u003epci_config_map is set to the capability ID during\ninitialization but the capability ID is not properly checked later when\nused in vfio_config_do_rw(). This leads to the following warning [1] and\nto an out-of-bounds access to ecap_perms array.\n\nFix it by checking cap_id in vfio_config_do_rw(), and if it is greater\nthan PCI_EXT_CAP_ID_MAX, use an alternative struct perm_bits for direct\nread only access instead of the ecap_perms array.\n\nNote that this is safe since the above is the only case where cap_id can\nexceed PCI_EXT_CAP_ID_MAX (except for the special capabilities, which\nare already checked before).\n\n[1]\n\nWARNING: CPU: 118 PID: 5329 at drivers/vfio/pci/vfio_pci_config.c:1900 vfio_pci_config_rw+0x395/0x430 [vfio_pci_core]\nCPU: 118 UID: 0 PID: 5329 Comm: simx-qemu-syste Not tainted 6.12.0+ #1\n(snip)\nCall Trace:\n \u003cTASK\u003e\n ? show_regs+0x69/0x80\n ? __warn+0x8d/0x140\n ? vfio_pci_config_rw+0x395/0x430 [vfio_pci_core]\n ? report_bug+0x18f/0x1a0\n ? handle_bug+0x63/0xa0\n ? exc_invalid_op+0x19/0x70\n ? asm_exc_invalid_op+0x1b/0x20\n ? vfio_pci_config_rw+0x395/0x430 [vfio_pci_core]\n ? vfio_pci_config_rw+0x244/0x430 [vfio_pci_core]\n vfio_pci_rw+0x101/0x1b0 [vfio_pci_core]\n vfio_pci_core_read+0x1d/0x30 [vfio_pci_core]\n vfio_device_fops_read+0x27/0x40 [vfio]\n vfs_read+0xbd/0x340\n ? vfio_device_fops_unl_ioctl+0xbb/0x740 [vfio]\n ? __rseq_handle_notify_resume+0xa4/0x4b0\n __x64_sys_pread64+0x96/0xc0\n x64_sys_call+0x1c3d/0x20d0\n do_syscall_64+0x4d/0x120\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53214", "url": "https://www.suse.com/security/cve/CVE-2024-53214" }, { "category": "external", "summary": "SUSE Bug 1235004 for CVE-2024-53214", "url": "https://bugzilla.suse.com/1235004" }, { "category": "external", "summary": "SUSE Bug 1235005 for CVE-2024-53214", "url": "https://bugzilla.suse.com/1235005" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53214" }, { "cve": "CVE-2024-53215", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53215" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: fix miss destroy percpu_counter in svc_rdma_proc_init()\n\nThere\u0027s issue as follows:\nRPC: Registered rdma transport module.\nRPC: Registered rdma backchannel transport module.\nRPC: Unregistered rdma transport module.\nRPC: Unregistered rdma backchannel transport module.\nBUG: unable to handle page fault for address: fffffbfff80c609a\nPGD 123fee067 P4D 123fee067 PUD 123fea067 PMD 10c624067 PTE 0\nOops: Oops: 0000 [#1] PREEMPT SMP KASAN NOPTI\nRIP: 0010:percpu_counter_destroy_many+0xf7/0x2a0\nCall Trace:\n \u003cTASK\u003e\n __die+0x1f/0x70\n page_fault_oops+0x2cd/0x860\n spurious_kernel_fault+0x36/0x450\n do_kern_addr_fault+0xca/0x100\n exc_page_fault+0x128/0x150\n asm_exc_page_fault+0x26/0x30\n percpu_counter_destroy_many+0xf7/0x2a0\n mmdrop+0x209/0x350\n finish_task_switch.isra.0+0x481/0x840\n schedule_tail+0xe/0xd0\n ret_from_fork+0x23/0x80\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nIf register_sysctl() return NULL, then svc_rdma_proc_cleanup() will not\ndestroy the percpu counters which init in svc_rdma_proc_init().\nIf CONFIG_HOTPLUG_CPU is enabled, residual nodes may be in the\n\u0027percpu_counters\u0027 list. The above issue may occur once the module is\nremoved. If the CONFIG_HOTPLUG_CPU configuration is not enabled, memory\nleakage occurs.\nTo solve above issue just destroy all percpu counters when\nregister_sysctl() return NULL.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53215", "url": "https://www.suse.com/security/cve/CVE-2024-53215" }, { "category": "external", "summary": "SUSE Bug 1234962 for CVE-2024-53215", "url": "https://bugzilla.suse.com/1234962" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53215" }, { "cve": "CVE-2024-53216", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53216" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: release svc_expkey/svc_export with rcu_work\n\nThe last reference for `cache_head` can be reduced to zero in `c_show`\nand `e_show`(using `rcu_read_lock` and `rcu_read_unlock`). Consequently,\n`svc_export_put` and `expkey_put` will be invoked, leading to two\nissues:\n\n1. The `svc_export_put` will directly free ex_uuid. However,\n `e_show`/`c_show` will access `ex_uuid` after `cache_put`, which can\n trigger a use-after-free issue, shown below.\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in svc_export_show+0x362/0x430 [nfsd]\n Read of size 1 at addr ff11000010fdc120 by task cat/870\n\n CPU: 1 UID: 0 PID: 870 Comm: cat Not tainted 6.12.0-rc3+ #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n 1.16.1-2.fc37 04/01/2014\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x53/0x70\n print_address_description.constprop.0+0x2c/0x3a0\n print_report+0xb9/0x280\n kasan_report+0xae/0xe0\n svc_export_show+0x362/0x430 [nfsd]\n c_show+0x161/0x390 [sunrpc]\n seq_read_iter+0x589/0x770\n seq_read+0x1e5/0x270\n proc_reg_read+0xe1/0x140\n vfs_read+0x125/0x530\n ksys_read+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Allocated by task 830:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n __kmalloc_node_track_caller_noprof+0x1bc/0x400\n kmemdup_noprof+0x22/0x50\n svc_export_parse+0x8a9/0xb80 [nfsd]\n cache_do_downcall+0x71/0xa0 [sunrpc]\n cache_write_procfs+0x8e/0xd0 [sunrpc]\n proc_reg_write+0xe1/0x140\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 868:\n kasan_save_stack+0x20/0x40\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x37/0x50\n kfree+0xf3/0x3e0\n svc_export_put+0x87/0xb0 [nfsd]\n cache_purge+0x17f/0x1f0 [sunrpc]\n nfsd_destroy_serv+0x226/0x2d0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n2. We cannot sleep while using `rcu_read_lock`/`rcu_read_unlock`.\n However, `svc_export_put`/`expkey_put` will call path_put, which\n subsequently triggers a sleeping operation due to the following\n `dput`.\n\n =============================\n WARNING: suspicious RCU usage\n 5.10.0-dirty #141 Not tainted\n -----------------------------\n ...\n Call Trace:\n dump_stack+0x9a/0xd0\n ___might_sleep+0x231/0x240\n dput+0x39/0x600\n path_put+0x1b/0x30\n svc_export_put+0x17/0x80\n e_show+0x1c9/0x200\n seq_read_iter+0x63f/0x7c0\n seq_read+0x226/0x2d0\n vfs_read+0x113/0x2c0\n ksys_read+0xc9/0x170\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nFix these issues by using `rcu_work` to help release\n`svc_expkey`/`svc_export`. This approach allows for an asynchronous\ncontext to invoke `path_put` and also facilitates the freeing of\n`uuid/exp/key` after an RCU grace period.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53216", "url": "https://www.suse.com/security/cve/CVE-2024-53216" }, { "category": "external", "summary": "SUSE Bug 1235003 for CVE-2024-53216", "url": "https://bugzilla.suse.com/1235003" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53216" }, { "cve": "CVE-2024-53217", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53217" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Prevent NULL dereference in nfsd4_process_cb_update()\n\n@ses is initialized to NULL. If __nfsd4_find_backchannel() finds no\navailable backchannel session, setup_callback_client() will try to\ndereference @ses and segfault.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53217", "url": "https://www.suse.com/security/cve/CVE-2024-53217" }, { "category": "external", "summary": "SUSE Bug 1234999 for CVE-2024-53217", "url": "https://bugzilla.suse.com/1234999" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53217" }, { "cve": "CVE-2024-53222", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53222" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix NULL pointer in comp_algorithm_show()\n\nLTP reported a NULL pointer dereference as followed:\n\n CPU: 7 UID: 0 PID: 5995 Comm: cat Kdump: loaded Not tainted 6.12.0-rc6+ #3\n Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __pi_strcmp+0x24/0x140\n lr : zcomp_available_show+0x60/0x100 [zram]\n sp : ffff800088b93b90\n x29: ffff800088b93b90 x28: 0000000000000001 x27: 0000000000400cc0\n x26: 0000000000000ffe x25: ffff80007b3e2388 x24: 0000000000000000\n x23: ffff80007b3e2390 x22: ffff0004041a9000 x21: ffff80007b3e2900\n x20: 0000000000000000 x19: 0000000000000000 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: ffff80007b3e2900 x9 : ffff80007b3cb280\n x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000040 x4 : 0000000000000000 x3 : 00656c722d6f7a6c\n x2 : 0000000000000000 x1 : ffff80007b3e2900 x0 : 0000000000000000\n Call trace:\n __pi_strcmp+0x24/0x140\n comp_algorithm_show+0x40/0x70 [zram]\n dev_attr_show+0x28/0x80\n sysfs_kf_seq_show+0x90/0x140\n kernfs_seq_show+0x34/0x48\n seq_read_iter+0x1d4/0x4e8\n kernfs_fop_read_iter+0x40/0x58\n new_sync_read+0x9c/0x168\n vfs_read+0x1a8/0x1f8\n ksys_read+0x74/0x108\n __arm64_sys_read+0x24/0x38\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x38/0x138\n el0t_64_sync_handler+0xc0/0xc8\n el0t_64_sync+0x188/0x190\n\nThe zram-\u003ecomp_algs[ZRAM_PRIMARY_COMP] can be NULL in zram_add() if\ncomp_algorithm_set() has not been called. User can access the zram device\nby sysfs after device_add_disk(), so there is a time window to trigger the\nNULL pointer dereference. Move it ahead device_add_disk() to make sure\nwhen user can access the zram device, it is ready. comp_algorithm_set()\nis protected by zram-\u003einit_lock in other places and no such problem.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53222", "url": "https://www.suse.com/security/cve/CVE-2024-53222" }, { "category": "external", "summary": "SUSE Bug 1234974 for CVE-2024-53222", "url": "https://bugzilla.suse.com/1234974" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53222" }, { "cve": "CVE-2024-53224", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53224" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Move events notifier registration to be after device registration\n\nMove pkey change work initialization and cleanup from device resources\nstage to notifier stage, since this is the stage which handles this work\nevents.\n\nFix a race between the device deregistration and pkey change work by moving\nMLX5_IB_STAGE_DEVICE_NOTIFIER to be after MLX5_IB_STAGE_IB_REG in order to\nensure that the notifier is deregistered before the device during cleanup.\nWhich ensures there are no works that are being executed after the\ndevice has already unregistered which can cause the panic below.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 1 PID: 630071 Comm: kworker/1:2 Kdump: loaded Tainted: G W OE --------- --- 5.14.0-162.6.1.el9_1.x86_64 #1\nHardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS 090008 02/27/2023\nWorkqueue: events pkey_change_handler [mlx5_ib]\nRIP: 0010:setup_qp+0x38/0x1f0 [mlx5_ib]\nCode: ee 41 54 45 31 e4 55 89 f5 53 48 89 fb 48 83 ec 20 8b 77 08 65 48 8b 04 25 28 00 00 00 48 89 44 24 18 48 8b 07 48 8d 4c 24 16 \u003c4c\u003e 8b 38 49 8b 87 80 0b 00 00 4c 89 ff 48 8b 80 08 05 00 00 8b 40\nRSP: 0018:ffffbcc54068be20 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff954054494128 RCX: ffffbcc54068be36\nRDX: ffff954004934000 RSI: 0000000000000001 RDI: ffff954054494128\nRBP: 0000000000000023 R08: ffff954001be2c20 R09: 0000000000000001\nR10: ffff954001be2c20 R11: ffff9540260133c0 R12: 0000000000000000\nR13: 0000000000000023 R14: 0000000000000000 R15: ffff9540ffcb0905\nFS: 0000000000000000(0000) GS:ffff9540ffc80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000010625c001 CR4: 00000000003706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\nmlx5_ib_gsi_pkey_change+0x20/0x40 [mlx5_ib]\nprocess_one_work+0x1e8/0x3c0\nworker_thread+0x50/0x3b0\n? rescuer_thread+0x380/0x380\nkthread+0x149/0x170\n? set_kthread_struct+0x50/0x50\nret_from_fork+0x22/0x30\nModules linked in: rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) mlx5_fwctl(OE) fwctl(OE) ib_uverbs(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlx_compat(OE) psample mlxfw(OE) tls knem(OE) netconsole nfsv3 nfs_acl nfs lockd grace fscache netfs qrtr rfkill sunrpc intel_rapl_msr intel_rapl_common rapl hv_balloon hv_utils i2c_piix4 pcspkr joydev fuse ext4 mbcache jbd2 sr_mod sd_mod cdrom t10_pi sg ata_generic pci_hyperv pci_hyperv_intf hyperv_drm drm_shmem_helper drm_kms_helper hv_storvsc syscopyarea hv_netvsc sysfillrect sysimgblt hid_hyperv fb_sys_fops scsi_transport_fc hyperv_keyboard drm ata_piix crct10dif_pclmul crc32_pclmul crc32c_intel libata ghash_clmulni_intel hv_vmbus serio_raw [last unloaded: ib_core]\nCR2: 0000000000000000\n---[ end trace f6f8be4eae12f7bc ]---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53224", "url": "https://www.suse.com/security/cve/CVE-2024-53224" }, { "category": "external", "summary": "SUSE Bug 1235009 for CVE-2024-53224", "url": "https://bugzilla.suse.com/1235009" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53224" }, { "cve": "CVE-2024-53229", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53229" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix the qp flush warnings in req\n\nWhen the qp is in error state, the status of WQEs in the queue should be\nset to error. Or else the following will appear.\n\n[ 920.617269] WARNING: CPU: 1 PID: 21 at drivers/infiniband/sw/rxe/rxe_comp.c:756 rxe_completer+0x989/0xcc0 [rdma_rxe]\n[ 920.617744] Modules linked in: rnbd_client(O) rtrs_client(O) rtrs_core(O) rdma_ucm rdma_cm iw_cm ib_cm crc32_generic rdma_rxe ip6_udp_tunnel udp_tunnel ib_uverbs ib_core loop brd null_blk ipv6\n[ 920.618516] CPU: 1 PID: 21 Comm: ksoftirqd/1 Tainted: G O 6.1.113-storage+ #65\n[ 920.618986] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n[ 920.619396] RIP: 0010:rxe_completer+0x989/0xcc0 [rdma_rxe]\n[ 920.619658] Code: 0f b6 84 24 3a 02 00 00 41 89 84 24 44 04 00 00 e9 2a f7 ff ff 39 ca bb 03 00 00 00 b8 0e 00 00 00 48 0f 45 d8 e9 15 f7 ff ff \u003c0f\u003e 0b e9 cb f8 ff ff 41 bf f5 ff ff ff e9 08 f8 ff ff 49 8d bc 24\n[ 920.620482] RSP: 0018:ffff97b7c00bbc38 EFLAGS: 00010246\n[ 920.620817] RAX: 0000000000000000 RBX: 000000000000000c RCX: 0000000000000008\n[ 920.621183] RDX: ffff960dc396ebc0 RSI: 0000000000005400 RDI: ffff960dc4e2fbac\n[ 920.621548] RBP: 0000000000000000 R08: 0000000000000001 R09: ffffffffac406450\n[ 920.621884] R10: ffffffffac4060c0 R11: 0000000000000001 R12: ffff960dc4e2f800\n[ 920.622254] R13: ffff960dc4e2f928 R14: ffff97b7c029c580 R15: 0000000000000000\n[ 920.622609] FS: 0000000000000000(0000) GS:ffff960ef7d00000(0000) knlGS:0000000000000000\n[ 920.622979] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 920.623245] CR2: 00007fa056965e90 CR3: 00000001107f1000 CR4: 00000000000006e0\n[ 920.623680] Call Trace:\n[ 920.623815] \u003cTASK\u003e\n[ 920.623933] ? __warn+0x79/0xc0\n[ 920.624116] ? rxe_completer+0x989/0xcc0 [rdma_rxe]\n[ 920.624356] ? report_bug+0xfb/0x150\n[ 920.624594] ? handle_bug+0x3c/0x60\n[ 920.624796] ? exc_invalid_op+0x14/0x70\n[ 920.624976] ? asm_exc_invalid_op+0x16/0x20\n[ 920.625203] ? rxe_completer+0x989/0xcc0 [rdma_rxe]\n[ 920.625474] ? rxe_completer+0x329/0xcc0 [rdma_rxe]\n[ 920.625749] rxe_do_task+0x80/0x110 [rdma_rxe]\n[ 920.626037] rxe_requester+0x625/0xde0 [rdma_rxe]\n[ 920.626310] ? rxe_cq_post+0xe2/0x180 [rdma_rxe]\n[ 920.626583] ? do_complete+0x18d/0x220 [rdma_rxe]\n[ 920.626812] ? rxe_completer+0x1a3/0xcc0 [rdma_rxe]\n[ 920.627050] rxe_do_task+0x80/0x110 [rdma_rxe]\n[ 920.627285] tasklet_action_common.constprop.0+0xa4/0x120\n[ 920.627522] handle_softirqs+0xc2/0x250\n[ 920.627728] ? sort_range+0x20/0x20\n[ 920.627942] run_ksoftirqd+0x1f/0x30\n[ 920.628158] smpboot_thread_fn+0xc7/0x1b0\n[ 920.628334] kthread+0xd6/0x100\n[ 920.628504] ? kthread_complete_and_exit+0x20/0x20\n[ 920.628709] ret_from_fork+0x1f/0x30\n[ 920.628892] \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53229", "url": "https://www.suse.com/security/cve/CVE-2024-53229" }, { "category": "external", "summary": "SUSE Bug 1234905 for CVE-2024-53229", "url": "https://bugzilla.suse.com/1234905" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53229" }, { "cve": "CVE-2024-53234", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53234" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: handle NONHEAD !delta[1] lclusters gracefully\n\nsyzbot reported a WARNING in iomap_iter_done:\n iomap_fiemap+0x73b/0x9b0 fs/iomap/fiemap.c:80\n ioctl_fiemap fs/ioctl.c:220 [inline]\n\nGenerally, NONHEAD lclusters won\u0027t have delta[1]==0, except for crafted\nimages and filesystems created by pre-1.0 mkfs versions.\n\nPreviously, it would immediately bail out if delta[1]==0, which led to\ninadequate decompressed lengths (thus FIEMAP is impacted). Treat it as\ndelta[1]=1 to work around these legacy mkfs versions.\n\n`lclusterbits \u003e 14` is illegal for compact indexes, error out too.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53234", "url": "https://www.suse.com/security/cve/CVE-2024-53234" }, { "category": "external", "summary": "SUSE Bug 1235045 for CVE-2024-53234", "url": "https://bugzilla.suse.com/1235045" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53234" }, { "cve": "CVE-2024-53237", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53237" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix use-after-free in device_for_each_child()\n\nSyzbot has reported the following KASAN splat:\n\nBUG: KASAN: slab-use-after-free in device_for_each_child+0x18f/0x1a0\nRead of size 8 at addr ffff88801f605308 by task kbnepd bnep0/4980\n\nCPU: 0 UID: 0 PID: 4980 Comm: kbnepd bnep0 Not tainted 6.12.0-rc4-00161-gae90f6a6170d #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nCall Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x100/0x190\n ? device_for_each_child+0x18f/0x1a0\n print_report+0x13a/0x4cb\n ? __virt_addr_valid+0x5e/0x590\n ? __phys_addr+0xc6/0x150\n ? device_for_each_child+0x18f/0x1a0\n kasan_report+0xda/0x110\n ? device_for_each_child+0x18f/0x1a0\n ? __pfx_dev_memalloc_noio+0x10/0x10\n device_for_each_child+0x18f/0x1a0\n ? __pfx_device_for_each_child+0x10/0x10\n pm_runtime_set_memalloc_noio+0xf2/0x180\n netdev_unregister_kobject+0x1ed/0x270\n unregister_netdevice_many_notify+0x123c/0x1d80\n ? __mutex_trylock_common+0xde/0x250\n ? __pfx_unregister_netdevice_many_notify+0x10/0x10\n ? trace_contention_end+0xe6/0x140\n ? __mutex_lock+0x4e7/0x8f0\n ? __pfx_lock_acquire.part.0+0x10/0x10\n ? rcu_is_watching+0x12/0xc0\n ? unregister_netdev+0x12/0x30\n unregister_netdevice_queue+0x30d/0x3f0\n ? __pfx_unregister_netdevice_queue+0x10/0x10\n ? __pfx_down_write+0x10/0x10\n unregister_netdev+0x1c/0x30\n bnep_session+0x1fb3/0x2ab0\n ? __pfx_bnep_session+0x10/0x10\n ? __pfx_lock_release+0x10/0x10\n ? __pfx_woken_wake_function+0x10/0x10\n ? __kthread_parkme+0x132/0x200\n ? __pfx_bnep_session+0x10/0x10\n ? kthread+0x13a/0x370\n ? __pfx_bnep_session+0x10/0x10\n kthread+0x2b7/0x370\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x48/0x80\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\nAllocated by task 4974:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n __kmalloc_noprof+0x1d1/0x440\n hci_alloc_dev_priv+0x1d/0x2820\n __vhci_create_device+0xef/0x7d0\n vhci_write+0x2c7/0x480\n vfs_write+0x6a0/0xfc0\n ksys_write+0x12f/0x260\n do_syscall_64+0xc7/0x250\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 4979:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x4f/0x70\n kfree+0x141/0x490\n hci_release_dev+0x4d9/0x600\n bt_host_release+0x6a/0xb0\n device_release+0xa4/0x240\n kobject_put+0x1ec/0x5a0\n put_device+0x1f/0x30\n vhci_release+0x81/0xf0\n __fput+0x3f6/0xb30\n task_work_run+0x151/0x250\n do_exit+0xa79/0x2c30\n do_group_exit+0xd5/0x2a0\n get_signal+0x1fcd/0x2210\n arch_do_signal_or_restart+0x93/0x780\n syscall_exit_to_user_mode+0x140/0x290\n do_syscall_64+0xd4/0x250\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nIn \u0027hci_conn_del_sysfs()\u0027, \u0027device_unregister()\u0027 may be called when\nan underlying (kobject) reference counter is greater than 1. This\nmeans that reparenting (happened when the device is actually freed)\nis delayed and, during that delay, parent controller device (hciX)\nmay be deleted. Since the latter may create a dangling pointer to\nfreed parent, avoid that scenario by reparenting to NULL explicitly.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53237", "url": "https://www.suse.com/security/cve/CVE-2024-53237" }, { "category": "external", "summary": "SUSE Bug 1235007 for CVE-2024-53237", "url": "https://bugzilla.suse.com/1235007" }, { "category": "external", "summary": "SUSE Bug 1235008 for CVE-2024-53237", "url": "https://bugzilla.suse.com/1235008" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-53237" }, { "cve": "CVE-2024-53240", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53240" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/netfront: fix crash when removing device\n\nWhen removing a netfront device directly after a suspend/resume cycle\nit might happen that the queues have not been setup again, causing a\ncrash during the attempt to stop the queues another time.\n\nFix that by checking the queues are existing before trying to stop\nthem.\n\nThis is XSA-465 / CVE-2024-53240.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53240", "url": "https://www.suse.com/security/cve/CVE-2024-53240" }, { "category": "external", "summary": "SUSE Bug 1234281 for CVE-2024-53240", "url": "https://bugzilla.suse.com/1234281" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53240" }, { "cve": "CVE-2024-53241", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-53241" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/xen: don\u0027t do PV iret hypercall through hypercall page\n\nInstead of jumping to the Xen hypercall page for doing the iret\nhypercall, directly code the required sequence in xen-asm.S.\n\nThis is done in preparation of no longer using hypercall page at all,\nas it has shown to cause problems with speculation mitigations.\n\nThis is part of XSA-466 / CVE-2024-53241.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-53241", "url": "https://www.suse.com/security/cve/CVE-2024-53241" }, { "category": "external", "summary": "SUSE Bug 1234282 for CVE-2024-53241", "url": "https://bugzilla.suse.com/1234282" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-53241" }, { "cve": "CVE-2024-56536", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56536" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cw1200: Fix potential NULL dereference\n\nA recent refactoring was identified by static analysis to\ncause a potential NULL dereference, fix this!", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56536", "url": "https://www.suse.com/security/cve/CVE-2024-56536" }, { "category": "external", "summary": "SUSE Bug 1234911 for CVE-2024-56536", "url": "https://bugzilla.suse.com/1234911" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56536" }, { "cve": "CVE-2024-56539", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56539" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: Fix memcpy() field-spanning write warning in mwifiex_config_scan()\n\nReplace one-element array with a flexible-array member in `struct\nmwifiex_ie_types_wildcard_ssid_params` to fix the following warning\non a MT8173 Chromebook (mt8173-elm-hana):\n\n[ 356.775250] ------------[ cut here ]------------\n[ 356.784543] memcpy: detected field-spanning write (size 6) of single field \"wildcard_ssid_tlv-\u003essid\" at drivers/net/wireless/marvell/mwifiex/scan.c:904 (size 1)\n[ 356.813403] WARNING: CPU: 3 PID: 742 at drivers/net/wireless/marvell/mwifiex/scan.c:904 mwifiex_scan_networks+0x4fc/0xf28 [mwifiex]\n\nThe \"(size 6)\" above is exactly the length of the SSID of the network\nthis device was connected to. The source of the warning looks like:\n\n ssid_len = user_scan_in-\u003essid_list[i].ssid_len;\n [...]\n memcpy(wildcard_ssid_tlv-\u003essid,\n user_scan_in-\u003essid_list[i].ssid, ssid_len);\n\nThere is a #define WILDCARD_SSID_TLV_MAX_SIZE that uses sizeof() on this\nstruct, but it already didn\u0027t account for the size of the one-element\narray, so it doesn\u0027t need to be changed.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56539", "url": "https://www.suse.com/security/cve/CVE-2024-56539" }, { "category": "external", "summary": "SUSE Bug 1234853 for CVE-2024-56539", "url": "https://bugzilla.suse.com/1234853" }, { "category": "external", "summary": "SUSE Bug 1234963 for CVE-2024-56539", "url": "https://bugzilla.suse.com/1234963" }, { "category": "external", "summary": "SUSE Bug 1234964 for CVE-2024-56539", "url": "https://bugzilla.suse.com/1234964" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-56539" }, { "cve": "CVE-2024-56549", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56549" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix NULL pointer dereference in object-\u003efile\n\nAt present, the object-\u003efile has the NULL pointer dereference problem in\nondemand-mode. The root cause is that the allocated fd and object-\u003efile\nlifetime are inconsistent, and the user-space invocation to anon_fd uses\nobject-\u003efile. Following is the process that triggers the issue:\n\n\t [write fd]\t\t\t\t[umount]\ncachefiles_ondemand_fd_write_iter\n\t\t\t\t fscache_cookie_state_machine\n\t\t\t\t\t cachefiles_withdraw_cookie\n if (!file) return -ENOBUFS\n\t\t\t\t\t cachefiles_clean_up_object\n\t\t\t\t\t cachefiles_unmark_inode_in_use\n\t\t\t\t\t fput(object-\u003efile)\n\t\t\t\t\t object-\u003efile = NULL\n // file NULL pointer dereference!\n __cachefiles_write(..., file, ...)\n\nFix this issue by add an additional reference count to the object-\u003efile\nbefore write/llseek, and decrement after it finished.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56549", "url": "https://www.suse.com/security/cve/CVE-2024-56549" }, { "category": "external", "summary": "SUSE Bug 1234912 for CVE-2024-56549", "url": "https://bugzilla.suse.com/1234912" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56549" }, { "cve": "CVE-2024-56551", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56551" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix usage slab after free\n\n[ +0.000021] BUG: KASAN: slab-use-after-free in drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000027] Read of size 8 at addr ffff8881b8605f88 by task amd_pci_unplug/2147\n\n[ +0.000023] CPU: 6 PID: 2147 Comm: amd_pci_unplug Not tainted 6.10.0+ #1\n[ +0.000016] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.000016] Call Trace:\n[ +0.000008] \u003cTASK\u003e\n[ +0.000009] dump_stack_lvl+0x76/0xa0\n[ +0.000017] print_report+0xce/0x5f0\n[ +0.000017] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000019] ? srso_return_thunk+0x5/0x5f\n[ +0.000015] ? kasan_complete_mode_report_info+0x72/0x200\n[ +0.000016] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000019] kasan_report+0xbe/0x110\n[ +0.000015] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000023] __asan_report_load8_noabort+0x14/0x30\n[ +0.000014] drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_write+0x14/0x30\n[ +0.000016] ? __pfx_drm_sched_entity_flush+0x10/0x10 [gpu_sched]\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_write+0x14/0x30\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? enable_work+0x124/0x220\n[ +0.000015] ? __pfx_enable_work+0x10/0x10\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? free_large_kmalloc+0x85/0xf0\n[ +0.000016] drm_sched_entity_destroy+0x18/0x30 [gpu_sched]\n[ +0.000020] amdgpu_vce_sw_fini+0x55/0x170 [amdgpu]\n[ +0.000735] ? __kasan_check_read+0x11/0x20\n[ +0.000016] vce_v4_0_sw_fini+0x80/0x110 [amdgpu]\n[ +0.000726] amdgpu_device_fini_sw+0x331/0xfc0 [amdgpu]\n[ +0.000679] ? mutex_unlock+0x80/0xe0\n[ +0.000017] ? __pfx_amdgpu_device_fini_sw+0x10/0x10 [amdgpu]\n[ +0.000662] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __kasan_check_write+0x14/0x30\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? mutex_unlock+0x80/0xe0\n[ +0.000016] amdgpu_driver_release_kms+0x16/0x80 [amdgpu]\n[ +0.000663] drm_minor_release+0xc9/0x140 [drm]\n[ +0.000081] drm_release+0x1fd/0x390 [drm]\n[ +0.000082] __fput+0x36c/0xad0\n[ +0.000018] __fput_sync+0x3c/0x50\n[ +0.000014] __x64_sys_close+0x7d/0xe0\n[ +0.000014] x64_sys_call+0x1bc6/0x2680\n[ +0.000014] do_syscall_64+0x70/0x130\n[ +0.000014] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? irqentry_exit_to_user_mode+0x60/0x190\n[ +0.000015] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? irqentry_exit+0x43/0x50\n[ +0.000012] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? exc_page_fault+0x7c/0x110\n[ +0.000015] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000014] RIP: 0033:0x7ffff7b14f67\n[ +0.000013] Code: ff e8 0d 16 02 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 03 00 00 00 0f 05 \u003c48\u003e 3d 00 f0 ff ff 77 41 c3 48 83 ec 18 89 7c 24 0c e8 73 ba f7 ff\n[ +0.000026] RSP: 002b:00007fffffffe378 EFLAGS: 00000246 ORIG_RAX: 0000000000000003\n[ +0.000019] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ffff7b14f67\n[ +0.000014] RDX: 0000000000000000 RSI: 00007ffff7f6f47a RDI: 0000000000000003\n[ +0.000014] RBP: 00007fffffffe3a0 R08: 0000555555569890 R09: 0000000000000000\n[ +0.000014] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fffffffe5c8\n[ +0.000013] R13: 00005555555552a9 R14: 0000555555557d48 R15: 00007ffff7ffd040\n[ +0.000020] \u003c/TASK\u003e\n\n[ +0.000016] Allocated by task 383 on cpu 7 at 26.880319s:\n[ +0.000014] kasan_save_stack+0x28/0x60\n[ +0.000008] kasan_save_track+0x18/0x70\n[ +0.000007] kasan_save_alloc_info+0x38/0x60\n[ +0.000007] __kasan_kmalloc+0xc1/0xd0\n[ +0.000007] kmalloc_trace_noprof+0x180/0x380\n[ +0.000007] drm_sched_init+0x411/0xec0 [gpu_sched]\n[ +0.000012] amdgpu_device_init+0x695f/0xa610 [amdgpu]\n[ +0.000658] amdgpu_driver_load_kms+0x1a/0x120 [amdgpu]\n[ +0.000662] amdgpu_pci_p\n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56551", "url": "https://www.suse.com/security/cve/CVE-2024-56551" }, { "category": "external", "summary": "SUSE Bug 1235075 for CVE-2024-56551", "url": "https://bugzilla.suse.com/1235075" }, { "category": "external", "summary": "SUSE Bug 1235102 for CVE-2024-56551", "url": "https://bugzilla.suse.com/1235102" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.7, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56551" }, { "cve": "CVE-2024-56562", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56562" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: Fix miss free init_dyn_addr at i3c_master_put_i3c_addrs()\n\nif (dev-\u003eboardinfo \u0026\u0026 dev-\u003eboardinfo-\u003einit_dyn_addr)\n ^^^ here check \"init_dyn_addr\"\n\ti3c_bus_set_addr_slot_status(\u0026master-\u003ebus, dev-\u003einfo.dyn_addr, ...)\n\t\t\t\t\t\t ^^^^\n\t\t\t\t\t\t\tfree \"dyn_addr\"\nFix copy/paste error \"dyn_addr\" by replacing it with \"init_dyn_addr\".", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56562", "url": "https://www.suse.com/security/cve/CVE-2024-56562" }, { "category": "external", "summary": "SUSE Bug 1234930 for CVE-2024-56562", "url": "https://bugzilla.suse.com/1234930" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56562" }, { "cve": "CVE-2024-56566", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56566" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: Avoid list corruption when removing a slab from the full list\n\nBoot with slub_debug=UFPZ.\n\nIf allocated object failed in alloc_consistency_checks, all objects of\nthe slab will be marked as used, and then the slab will be removed from\nthe partial list.\n\nWhen an object belonging to the slab got freed later, the remove_full()\nfunction is called. Because the slab is neither on the partial list nor\non the full list, it eventually lead to a list corruption (actually a\nlist poison being detected).\n\nSo we need to mark and isolate the slab page with metadata corruption,\ndo not put it back in circulation.\n\nBecause the debug caches avoid all the fastpaths, reusing the frozen bit\nto mark slab page with metadata corruption seems to be fine.\n\n[ 4277.385669] list_del corruption, ffffea00044b3e50-\u003enext is LIST_POISON1 (dead000000000100)\n[ 4277.387023] ------------[ cut here ]------------\n[ 4277.387880] kernel BUG at lib/list_debug.c:56!\n[ 4277.388680] invalid opcode: 0000 [#1] PREEMPT SMP PTI\n[ 4277.389562] CPU: 5 PID: 90 Comm: kworker/5:1 Kdump: loaded Tainted: G OE 6.6.1-1 #1\n[ 4277.392113] Workqueue: xfs-inodegc/vda1 xfs_inodegc_worker [xfs]\n[ 4277.393551] RIP: 0010:__list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.394518] Code: 48 91 82 e8 37 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 28 49 91 82 e8 26 f9 9a ff 0f 0b 48 89 fe 48 c7 c7 58 49 91\n[ 4277.397292] RSP: 0018:ffffc90000333b38 EFLAGS: 00010082\n[ 4277.398202] RAX: 000000000000004e RBX: ffffea00044b3e50 RCX: 0000000000000000\n[ 4277.399340] RDX: 0000000000000002 RSI: ffffffff828f8715 RDI: 00000000ffffffff\n[ 4277.400545] RBP: ffffea00044b3e40 R08: 0000000000000000 R09: ffffc900003339f0\n[ 4277.401710] R10: 0000000000000003 R11: ffffffff82d44088 R12: ffff888112cf9910\n[ 4277.402887] R13: 0000000000000001 R14: 0000000000000001 R15: ffff8881000424c0\n[ 4277.404049] FS: 0000000000000000(0000) GS:ffff88842fd40000(0000) knlGS:0000000000000000\n[ 4277.405357] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 4277.406389] CR2: 00007f2ad0b24000 CR3: 0000000102a3a006 CR4: 00000000007706e0\n[ 4277.407589] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 4277.408780] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 4277.410000] PKRU: 55555554\n[ 4277.410645] Call Trace:\n[ 4277.411234] \u003cTASK\u003e\n[ 4277.411777] ? die+0x32/0x80\n[ 4277.412439] ? do_trap+0xd6/0x100\n[ 4277.413150] ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.414158] ? do_error_trap+0x6a/0x90\n[ 4277.414948] ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.415915] ? exc_invalid_op+0x4c/0x60\n[ 4277.416710] ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.417675] ? asm_exc_invalid_op+0x16/0x20\n[ 4277.418482] ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.419466] ? __list_del_entry_valid_or_report+0x7b/0xc0\n[ 4277.420410] free_to_partial_list+0x515/0x5e0\n[ 4277.421242] ? xfs_iext_remove+0x41a/0xa10 [xfs]\n[ 4277.422298] xfs_iext_remove+0x41a/0xa10 [xfs]\n[ 4277.423316] ? xfs_inodegc_worker+0xb4/0x1a0 [xfs]\n[ 4277.424383] xfs_bmap_del_extent_delay+0x4fe/0x7d0 [xfs]\n[ 4277.425490] __xfs_bunmapi+0x50d/0x840 [xfs]\n[ 4277.426445] xfs_itruncate_extents_flags+0x13a/0x490 [xfs]\n[ 4277.427553] xfs_inactive_truncate+0xa3/0x120 [xfs]\n[ 4277.428567] xfs_inactive+0x22d/0x290 [xfs]\n[ 4277.429500] xfs_inodegc_worker+0xb4/0x1a0 [xfs]\n[ 4277.430479] process_one_work+0x171/0x340\n[ 4277.431227] worker_thread+0x277/0x390\n[ 4277.431962] ? __pfx_worker_thread+0x10/0x10\n[ 4277.432752] kthread+0xf0/0x120\n[ 4277.433382] ? __pfx_kthread+0x10/0x10\n[ 4277.434134] ret_from_fork+0x2d/0x50\n[ 4277.434837] ? __pfx_kthread+0x10/0x10\n[ 4277.435566] ret_from_fork_asm+0x1b/0x30\n[ 4277.436280] \u003c/TASK\u003e", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56566", "url": "https://www.suse.com/security/cve/CVE-2024-56566" }, { "category": "external", "summary": "SUSE Bug 1235033 for CVE-2024-56566", "url": "https://bugzilla.suse.com/1235033" }, { "category": "external", "summary": "SUSE Bug 1235034 for CVE-2024-56566", "url": "https://bugzilla.suse.com/1235034" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56566" }, { "cve": "CVE-2024-56567", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56567" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nad7780: fix division by zero in ad7780_write_raw()\n\nIn the ad7780_write_raw() , val2 can be zero, which might lead to a\ndivision by zero error in DIV_ROUND_CLOSEST(). The ad7780_write_raw()\nis based on iio_info\u0027s write_raw. While val is explicitly declared that\ncan be zero (in read mode), val2 is not specified to be non-zero.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56567", "url": "https://www.suse.com/security/cve/CVE-2024-56567" }, { "category": "external", "summary": "SUSE Bug 1234916 for CVE-2024-56567", "url": "https://bugzilla.suse.com/1234916" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56567" }, { "cve": "CVE-2024-56576", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56576" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: tc358743: Fix crash in the probe error path when using polling\n\nIf an error occurs in the probe() function, we should remove the polling\ntimer that was alarmed earlier, otherwise the timer is called with\narguments that are already freed, which results in a crash.\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 0 at kernel/time/timer.c:1830 __run_timers+0x244/0x268\nModules linked in:\nCPU: 3 UID: 0 PID: 0 Comm: swapper/3 Not tainted 6.11.0 #226\nHardware name: Diasom DS-RK3568-SOM-EVB (DT)\npstate: 804000c9 (Nzcv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : __run_timers+0x244/0x268\nlr : __run_timers+0x1d4/0x268\nsp : ffffff80eff2baf0\nx29: ffffff80eff2bb50 x28: 7fffffffffffffff x27: ffffff80eff2bb00\nx26: ffffffc080f669c0 x25: ffffff80efef6bf0 x24: ffffff80eff2bb00\nx23: 0000000000000000 x22: dead000000000122 x21: 0000000000000000\nx20: ffffff80efef6b80 x19: ffffff80041c8bf8 x18: ffffffffffffffff\nx17: ffffffc06f146000 x16: ffffff80eff27dc0 x15: 000000000000003e\nx14: 0000000000000000 x13: 00000000000054da x12: 0000000000000000\nx11: 00000000000639c0 x10: 000000000000000c x9 : 0000000000000009\nx8 : ffffff80eff2cb40 x7 : ffffff80eff2cb40 x6 : ffffff8002bee480\nx5 : ffffffc080cb2220 x4 : ffffffc080cb2150 x3 : 00000000000f4240\nx2 : 0000000000000102 x1 : ffffff80eff2bb00 x0 : ffffff80041c8bf0\nCall trace:\n __run_timers+0x244/0x268\n timer_expire_remote+0x50/0x68\n tmigr_handle_remote+0x388/0x39c\n run_timer_softirq+0x38/0x44\n handle_softirqs+0x138/0x298\n __do_softirq+0x14/0x20\n ____do_softirq+0x10/0x1c\n call_on_irq_stack+0x24/0x4c\n do_softirq_own_stack+0x1c/0x2c\n irq_exit_rcu+0x9c/0xcc\n el1_interrupt+0x48/0xc0\n el1h_64_irq_handler+0x18/0x24\n el1h_64_irq+0x7c/0x80\n default_idle_call+0x34/0x68\n do_idle+0x23c/0x294\n cpu_startup_entry+0x38/0x3c\n secondary_start_kernel+0x128/0x160\n __secondary_switched+0xb8/0xbc\n---[ end trace 0000000000000000 ]---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56576", "url": "https://www.suse.com/security/cve/CVE-2024-56576" }, { "category": "external", "summary": "SUSE Bug 1235019 for CVE-2024-56576", "url": "https://bugzilla.suse.com/1235019" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56576" }, { "cve": "CVE-2024-56582", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56582" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free in btrfs_encoded_read_endio()\n\nShinichiro reported the following use-after free that sometimes is\nhappening in our CI system when running fstests\u0027 btrfs/284 on a TCMU\nrunner device:\n\n BUG: KASAN: slab-use-after-free in lock_release+0x708/0x780\n Read of size 8 at addr ffff888106a83f18 by task kworker/u80:6/219\n\n CPU: 8 UID: 0 PID: 219 Comm: kworker/u80:6 Not tainted 6.12.0-rc6-kts+ #15\n Hardware name: Supermicro Super Server/X11SPi-TF, BIOS 3.3 02/21/2020\n Workqueue: btrfs-endio btrfs_end_bio_work [btrfs]\n Call Trace:\n \u003cTASK\u003e\n dump_stack_lvl+0x6e/0xa0\n ? lock_release+0x708/0x780\n print_report+0x174/0x505\n ? lock_release+0x708/0x780\n ? __virt_addr_valid+0x224/0x410\n ? lock_release+0x708/0x780\n kasan_report+0xda/0x1b0\n ? lock_release+0x708/0x780\n ? __wake_up+0x44/0x60\n lock_release+0x708/0x780\n ? __pfx_lock_release+0x10/0x10\n ? __pfx_do_raw_spin_lock+0x10/0x10\n ? lock_is_held_type+0x9a/0x110\n _raw_spin_unlock_irqrestore+0x1f/0x60\n __wake_up+0x44/0x60\n btrfs_encoded_read_endio+0x14b/0x190 [btrfs]\n btrfs_check_read_bio+0x8d9/0x1360 [btrfs]\n ? lock_release+0x1b0/0x780\n ? trace_lock_acquire+0x12f/0x1a0\n ? __pfx_btrfs_check_read_bio+0x10/0x10 [btrfs]\n ? process_one_work+0x7e3/0x1460\n ? lock_acquire+0x31/0xc0\n ? process_one_work+0x7e3/0x1460\n process_one_work+0x85c/0x1460\n ? __pfx_process_one_work+0x10/0x10\n ? assign_work+0x16c/0x240\n worker_thread+0x5e6/0xfc0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x2c3/0x3a0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x70\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \u003c/TASK\u003e\n\n Allocated by task 3661:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0xaa/0xb0\n btrfs_encoded_read_regular_fill_pages+0x16c/0x6d0 [btrfs]\n send_extent_data+0xf0f/0x24a0 [btrfs]\n process_extent+0x48a/0x1830 [btrfs]\n changed_cb+0x178b/0x2ea0 [btrfs]\n btrfs_ioctl_send+0x3bf9/0x5c20 [btrfs]\n _btrfs_ioctl_send+0x117/0x330 [btrfs]\n btrfs_ioctl+0x184a/0x60a0 [btrfs]\n __x64_sys_ioctl+0x12e/0x1a0\n do_syscall_64+0x95/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n Freed by task 3661:\n kasan_save_stack+0x30/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x70\n __kasan_slab_free+0x4f/0x70\n kfree+0x143/0x490\n btrfs_encoded_read_regular_fill_pages+0x531/0x6d0 [btrfs]\n send_extent_data+0xf0f/0x24a0 [btrfs]\n process_extent+0x48a/0x1830 [btrfs]\n changed_cb+0x178b/0x2ea0 [btrfs]\n btrfs_ioctl_send+0x3bf9/0x5c20 [btrfs]\n _btrfs_ioctl_send+0x117/0x330 [btrfs]\n btrfs_ioctl+0x184a/0x60a0 [btrfs]\n __x64_sys_ioctl+0x12e/0x1a0\n do_syscall_64+0x95/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n The buggy address belongs to the object at ffff888106a83f00\n which belongs to the cache kmalloc-rnd-07-96 of size 96\n The buggy address is located 24 bytes inside of\n freed 96-byte region [ffff888106a83f00, ffff888106a83f60)\n\n The buggy address belongs to the physical page:\n page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888106a83800 pfn:0x106a83\n flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff)\n page_type: f5(slab)\n raw: 0017ffffc0000000 ffff888100053680 ffffea0004917200 0000000000000004\n raw: ffff888106a83800 0000000080200019 00000001f5000000 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888106a83e00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff888106a83e80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n \u003effff888106a83f00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ^\n ffff888106a83f80: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n ffff888106a84000: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ==================================================================\n\nFurther analyzing the trace and \n---truncated---", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56582", "url": "https://www.suse.com/security/cve/CVE-2024-56582" }, { "category": "external", "summary": "SUSE Bug 1235128 for CVE-2024-56582", "url": "https://bugzilla.suse.com/1235128" }, { "category": "external", "summary": "SUSE Bug 1235129 for CVE-2024-56582", "url": "https://bugzilla.suse.com/1235129" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-56582" }, { "cve": "CVE-2024-56599", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56599" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath10k: avoid NULL pointer error during sdio remove\n\nWhen running \u0027rmmod ath10k\u0027, ath10k_sdio_remove() will free sdio\nworkqueue by destroy_workqueue(). But if CONFIG_INIT_ON_FREE_DEFAULT_ON\nis set to yes, kernel panic will happen:\nCall trace:\n destroy_workqueue+0x1c/0x258\n ath10k_sdio_remove+0x84/0x94\n sdio_bus_remove+0x50/0x16c\n device_release_driver_internal+0x188/0x25c\n device_driver_detach+0x20/0x2c\n\nThis is because during \u0027rmmod ath10k\u0027, ath10k_sdio_remove() will call\nath10k_core_destroy() before destroy_workqueue(). wiphy_dev_release()\nwill finally be called in ath10k_core_destroy(). This function will free\nstruct cfg80211_registered_device *rdev and all its members, including\nwiphy, dev and the pointer of sdio workqueue. Then the pointer of sdio\nworkqueue will be set to NULL due to CONFIG_INIT_ON_FREE_DEFAULT_ON.\n\nAfter device release, destroy_workqueue() will use NULL pointer then the\nkernel panic happen.\n\nCall trace:\nath10k_sdio_remove\n -\u003eath10k_core_unregister\n \u2026\u2026\n -\u003eath10k_core_stop\n -\u003eath10k_hif_stop\n -\u003eath10k_sdio_irq_disable\n -\u003eath10k_hif_power_down\n -\u003edel_timer_sync(\u0026ar_sdio-\u003esleep_timer)\n -\u003eath10k_core_destroy\n -\u003eath10k_mac_destroy\n -\u003eieee80211_free_hw\n -\u003ewiphy_free\n \u2026\u2026\n -\u003ewiphy_dev_release\n -\u003edestroy_workqueue\n\nNeed to call destroy_workqueue() before ath10k_core_destroy(), free\nthe work queue buffer first and then free pointer of work queue by\nath10k_core_destroy(). This order matches the error path order in\nath10k_sdio_probe().\n\nNo work will be queued on sdio workqueue between it is destroyed and\nath10k_core_destroy() is called. Based on the call_stack above, the\nreason is:\nOnly ath10k_sdio_sleep_timer_handler(), ath10k_sdio_hif_tx_sg() and\nath10k_sdio_irq_disable() will queue work on sdio workqueue.\nSleep timer will be deleted before ath10k_core_destroy() in\nath10k_hif_power_down().\nath10k_sdio_irq_disable() only be called in ath10k_hif_stop().\nath10k_core_unregister() will call ath10k_hif_power_down() to stop hif\nbus, so ath10k_sdio_hif_tx_sg() won\u0027t be called anymore.\n\nTested-on: QCA6174 hw3.2 SDIO WLAN.RMH.4.4.1-00189", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56599", "url": "https://www.suse.com/security/cve/CVE-2024-56599" }, { "category": "external", "summary": "SUSE Bug 1235138 for CVE-2024-56599", "url": "https://bugzilla.suse.com/1235138" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.4, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56599" }, { "cve": "CVE-2024-56604", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56604" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()\n\nbt_sock_alloc() attaches allocated sk object to the provided sock object.\nIf rfcomm_dlc_alloc() fails, we release the sk object, but leave the\ndangling pointer in the sock object, which may cause use-after-free.\n\nFix this by swapping calls to bt_sock_alloc() and rfcomm_dlc_alloc().", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56604", "url": "https://www.suse.com/security/cve/CVE-2024-56604" }, { "category": "external", "summary": "SUSE Bug 1235056 for CVE-2024-56604", "url": "https://bugzilla.suse.com/1235056" }, { "category": "external", "summary": "SUSE Bug 1235058 for CVE-2024-56604", "url": "https://bugzilla.suse.com/1235058" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-56604" }, { "cve": "CVE-2024-56605", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56605" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()\n\nbt_sock_alloc() allocates the sk object and attaches it to the provided\nsock object. On error l2cap_sock_alloc() frees the sk object, but the\ndangling pointer is still attached to the sock object, which may create\nuse-after-free in other code.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56605", "url": "https://www.suse.com/security/cve/CVE-2024-56605" }, { "category": "external", "summary": "SUSE Bug 1234853 for CVE-2024-56605", "url": "https://bugzilla.suse.com/1234853" }, { "category": "external", "summary": "SUSE Bug 1235061 for CVE-2024-56605", "url": "https://bugzilla.suse.com/1235061" }, { "category": "external", "summary": "SUSE Bug 1235062 for CVE-2024-56605", "url": "https://bugzilla.suse.com/1235062" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-56605" }, { "cve": "CVE-2024-56645", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56645" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_session_new(): fix skb reference counting\n\nSince j1939_session_skb_queue() does an extra skb_get() for each new\nskb, do the same for the initial one in j1939_session_new() to avoid\nrefcount underflow.\n\n[mkl: clean up commit message]", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56645", "url": "https://www.suse.com/security/cve/CVE-2024-56645" }, { "category": "external", "summary": "SUSE Bug 1235134 for CVE-2024-56645", "url": "https://bugzilla.suse.com/1235134" }, { "category": "external", "summary": "SUSE Bug 1235135 for CVE-2024-56645", "url": "https://bugzilla.suse.com/1235135" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-56645" }, { "cve": "CVE-2024-56667", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56667" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix NULL pointer dereference in capture_engine\n\nWhen the intel_context structure contains NULL,\nit raises a NULL pointer dereference error in drm_info().\n\n(cherry picked from commit 754302a5bc1bd8fd3b7d85c168b0a1af6d4bba4d)", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56667", "url": "https://www.suse.com/security/cve/CVE-2024-56667" }, { "category": "external", "summary": "SUSE Bug 1235016 for CVE-2024-56667", "url": "https://bugzilla.suse.com/1235016" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56667" }, { "cve": "CVE-2024-56752", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56752" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new()\n\nWhen the call to gf100_grctx_generate() fails, unlock gr-\u003efecs.mutex\nbefore returning the error.\n\nFixes smatch warning:\n\ndrivers/gpu/drm/nouveau/nvkm/engine/gr/gf100.c:480 gf100_gr_chan_new() warn: inconsistent returns \u0027\u0026gr-\u003efecs.mutex\u0027.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56752", "url": "https://www.suse.com/security/cve/CVE-2024-56752" }, { "category": "external", "summary": "SUSE Bug 1234937 for CVE-2024-56752", "url": "https://bugzilla.suse.com/1234937" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56752" }, { "cve": "CVE-2024-56754", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56754" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - Fix the pointer passed to caam_qi_shutdown()\n\nThe type of the last parameter given to devm_add_action_or_reset() is\n\"struct caam_drv_private *\", but in caam_qi_shutdown(), it is casted to\n\"struct device *\".\n\nPass the correct parameter to devm_add_action_or_reset() so that the\nresources are released as expected.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56754", "url": "https://www.suse.com/security/cve/CVE-2024-56754" }, { "category": "external", "summary": "SUSE Bug 1234918 for CVE-2024-56754", "url": "https://bugzilla.suse.com/1234918" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.1, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56754" }, { "cve": "CVE-2024-56755", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56755" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING\n\nIn fscache_create_volume(), there is a missing memory barrier between the\nbit-clearing operation and the wake-up operation. This may cause a\nsituation where, after a wake-up, the bit-clearing operation hasn\u0027t been\ndetected yet, leading to an indefinite wait. The triggering process is as\nfollows:\n\n [cookie1] [cookie2] [volume_work]\nfscache_perform_lookup\n fscache_create_volume\n fscache_perform_lookup\n fscache_create_volume\n\t\t\t fscache_create_volume_work\n cachefiles_acquire_volume\n clear_and_wake_up_bit\n test_and_set_bit\n test_and_set_bit\n goto maybe_wait\n goto no_wait\n\nIn the above process, cookie1 and cookie2 has the same volume. When cookie1\nenters the -no_wait- process, it will clear the bit and wake up the waiting\nprocess. If a barrier is missing, it may cause cookie2 to remain in the\n-wait- process indefinitely.\n\nIn commit 3288666c7256 (\"fscache: Use clear_and_wake_up_bit() in\nfscache_create_volume_work()\"), barriers were added to similar operations\nin fscache_create_volume_work(), but fscache_create_volume() was missed.\n\nBy combining the clear and wake operations into clear_and_wake_up_bit() to\nfix this issue.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56755", "url": "https://www.suse.com/security/cve/CVE-2024-56755" }, { "category": "external", "summary": "SUSE Bug 1234920 for CVE-2024-56755", "url": "https://bugzilla.suse.com/1234920" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 2.5, "baseSeverity": "LOW", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "low" } ], "title": "CVE-2024-56755" }, { "cve": "CVE-2024-56756", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-56756" } ], "notes": [ { "category": "general", "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix freeing of the HMB descriptor table\n\nThe HMB descriptor table is sized to the maximum number of descriptors\nthat could be used for a given device, but __nvme_alloc_host_mem could\nbreak out of the loop earlier on memory allocation failure and end up\nusing less descriptors than planned for, which leads to an incorrect\nsize passed to dma_free_coherent.\n\nIn practice this was not showing up because the number of descriptors\ntends to be low and the dma coherent allocator always allocates and\nfrees at least a page.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-56756", "url": "https://www.suse.com/security/cve/CVE-2024-56756" }, { "category": "external", "summary": "SUSE Bug 1234922 for CVE-2024-56756", "url": "https://bugzilla.suse.com/1234922" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "moderate" } ], "title": "CVE-2024-56756" }, { "cve": "CVE-2024-8805", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2024-8805" } ], "notes": [ { "category": "general", "text": "BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of BlueZ. Authentication is not required to exploit this vulnerability.\n\nThe specific flaw exists within the implementation of the HID over GATT Profile. The issue results from the lack of authorization prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-25177.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2024-8805", "url": "https://www.suse.com/security/cve/CVE-2024-8805" }, { "category": "external", "summary": "SUSE Bug 1230697 for CVE-2024-8805", "url": "https://bugzilla.suse.com/1230697" }, { "category": "external", "summary": "SUSE Bug 1240804 for CVE-2024-8805", "url": "https://bugzilla.suse.com/1240804" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "SUSE Linux Enterprise Module for Public Cloud 15 SP6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:cluster-md-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:dlm-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:gfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-devel-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-extra-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-azure-optional-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-azure-vdso-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kernel-devel-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-source-azure-6.4.0-150600.8.23.1.noarch", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kernel-syms-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:kselftests-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:ocfs2-kmp-azure-6.4.0-150600.8.23.1.x86_64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.aarch64", "openSUSE Leap 15.6:reiserfs-kmp-azure-6.4.0-150600.8.23.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2025-01-15T09:07:49Z", "details": "important" } ], "title": "CVE-2024-8805" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…