SUSE update for the Linux Kernel



Published: 2024-10-08
Risk Low
Patch available YES
Number of vulnerabilities 10
CVE-ID CVE-2022-48911
CVE-2022-48923
CVE-2022-48944
CVE-2022-48945
CVE-2024-41087
CVE-2024-42301
CVE-2024-44946
CVE-2024-45021
CVE-2024-46674
CVE-2024-46774
CWE-ID CWE-416
CWE-119
CWE-20
CWE-415
CWE-125
CWE-665
Exploitation vector Local
Public exploit Public exploit code for vulnerability #7 is available.
Vulnerable software
Subscribe
SUSE Linux Enterprise Server 15 SP4 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing LTSS 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing ESPOS 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15 SP4 LTSS
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro for Rancher
Operating systems & Components / Operating system

SUSE Linux Enterprise High Availability Extension 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

SUSE Linux Enterprise Live Patching
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server
Operating systems & Components / Operating system

SUSE Manager Server
Operating systems & Components / Operating system

SUSE Manager Proxy
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

cluster-md-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-extra-debuginfo
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-optional
Operating systems & Components / Operating system package or component

dtb-nvidia
Operating systems & Components / Operating system package or component

dtb-renesas
Operating systems & Components / Operating system package or component

dtb-socionext
Operating systems & Components / Operating system package or component

kernel-64kb-optional-debuginfo
Operating systems & Components / Operating system package or component

dtb-amd
Operating systems & Components / Operating system package or component

dtb-apple
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dlm-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-marvell
Operating systems & Components / Operating system package or component

dtb-cavium
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-xilinx
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-amazon
Operating systems & Components / Operating system package or component

kernel-64kb-extra
Operating systems & Components / Operating system package or component

dtb-lg
Operating systems & Components / Operating system package or component

dtb-exynos
Operating systems & Components / Operating system package or component

dtb-freescale
Operating systems & Components / Operating system package or component

kernel-64kb-livepatch-devel
Operating systems & Components / Operating system package or component

dtb-amlogic
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dlm-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-hisilicon
Operating systems & Components / Operating system package or component

dtb-apm
Operating systems & Components / Operating system package or component

dtb-rockchip
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-arm
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-altera
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-allwinner
Operating systems & Components / Operating system package or component

dtb-broadcom
Operating systems & Components / Operating system package or component

dtb-qcom
Operating systems & Components / Operating system package or component

dtb-sprd
Operating systems & Components / Operating system package or component

dtb-mediatek
Operating systems & Components / Operating system package or component

dtb-aarch64
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_136-default
Operating systems & Components / Operating system package or component

kernel-livepatch-SLE15-SP4_Update_32-debugsource
Operating systems & Components / Operating system package or component

kernel-kvmsmall
Operating systems & Components / Operating system package or component

cluster-md-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-optional
Operating systems & Components / Operating system package or component

gfs2-kmp-default
Operating systems & Components / Operating system package or component

cluster-md-kmp-default
Operating systems & Components / Operating system package or component

gfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-livepatch
Operating systems & Components / Operating system package or component

ocfs2-kmp-default
Operating systems & Components / Operating system package or component

kernel-default-livepatch-devel
Operating systems & Components / Operating system package or component

ocfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-optional-debuginfo
Operating systems & Components / Operating system package or component

dlm-kmp-default
Operating systems & Components / Operating system package or component

dlm-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kselftests-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-qa
Operating systems & Components / Operating system package or component

kselftests-kmp-default
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-default-base-rebuild
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debugsource
Operating systems & Components / Operating system package or component

kernel-debug-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug-devel
Operating systems & Components / Operating system package or component

kernel-debug-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-debug-debugsource
Operating systems & Components / Operating system package or component

kernel-debug
Operating systems & Components / Operating system package or component

kernel-source-vanilla
Operating systems & Components / Operating system package or component

kernel-docs-html
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debuginfo
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debugsource
Operating systems & Components / Operating system package or component

kernel-zfcpdump
Operating systems & Components / Operating system package or component

reiserfs-kmp-default
Operating systems & Components / Operating system package or component

reiserfs-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-devel
Operating systems & Components / Operating system package or component

kernel-64kb-debugsource
Operating systems & Components / Operating system package or component

kernel-64kb
Operating systems & Components / Operating system package or component

kernel-docs
Operating systems & Components / Operating system package or component

kernel-devel
Operating systems & Components / Operating system package or component

kernel-macros
Operating systems & Components / Operating system package or component

kernel-source
Operating systems & Components / Operating system package or component

kernel-default-extra
Operating systems & Components / Operating system package or component

kernel-default-devel
Operating systems & Components / Operating system package or component

kernel-obs-build-debugsource
Operating systems & Components / Operating system package or component

kernel-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-syms
Operating systems & Components / Operating system package or component

kernel-default-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-build
Operating systems & Components / Operating system package or component

kernel-default-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-debugsource
Operating systems & Components / Operating system package or component

kernel-default-base
Operating systems & Components / Operating system package or component

kernel-default
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 10 vulnerabilities.

1) Use-after-free

EUVDB-ID: #VU96410

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48911

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the nf_queue_entry_dup() function in net/netfilter/nfnetlink_queue.c, within the nf_queue_entry_release_refs(), nf_queue_entry_get_refs() and __nf_queue() functions in net/netfilter/nf_queue.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Buffer overflow

EUVDB-ID: #VU96443

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48923

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the lzo_decompress_bio() function in fs/btrfs/lzo.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Input validation error

EUVDB-ID: #VU96648

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48944

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the tg_nop(), sched_fork(), sched_post_fork(), set_user_nice(), __setscheduler_params() and sched_init() functions in kernel/sched/core.c, within the copy_process() function in kernel/fork.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Buffer overflow

EUVDB-ID: #VU97681

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-48945

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to memory corruption within the vivid_vid_cap_s_selection() function in drivers/media/platform/vivid/vivid-vid-cap.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Double free

EUVDB-ID: #VU95008

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-41087

CWE-ID: CWE-415 - Double Free

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a double free error within the ata_host_alloc() function in drivers/ata/libata-core.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Out-of-bounds read

EUVDB-ID: #VU96116

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-42301

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the do_active_device(), do_autoprobe(), do_hardware_base_addr(), do_hardware_irq(), do_hardware_dma() and do_hardware_modes() functions in drivers/parport/procfs.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Use-after-free

EUVDB-ID: #VU96658

Risk: Low

CVSSv3.1: 7.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2024-44946

CWE-ID: CWE-416 - Use After Free

Exploit availability: Yes

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the kcm_sendmsg(), KCM_STATS_ADD(), sk->sk_write_space() and init_kcm_sock() functions in net/kcm/kcmsock.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

8) Improper Initialization

EUVDB-ID: #VU97184

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-45021

CWE-ID: CWE-665 - Improper Initialization

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper initialization within the memcg_write_event_control() function in mm/memcontrol.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Use-after-free

EUVDB-ID: #VU97252

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-46674

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the st_dwc3_probe() and reset_control_assert() functions in drivers/usb/dwc3/dwc3-st.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Buffer overflow

EUVDB-ID: #VU97563

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-46774

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the SYSCALL_DEFINE1() function in arch/powerpc/kernel/rtas.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-optional: before 5.14.21-150400.24.136.1

dtb-nvidia: before 5.14.21-150400.24.136.1

dtb-renesas: before 5.14.21-150400.24.136.1

dtb-socionext: before 5.14.21-150400.24.136.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.136.1

dtb-amd: before 5.14.21-150400.24.136.1

dtb-apple: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dlm-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-marvell: before 5.14.21-150400.24.136.1

dtb-cavium: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-xilinx: before 5.14.21-150400.24.136.1

kselftests-kmp-64kb: before 5.14.21-150400.24.136.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-amazon: before 5.14.21-150400.24.136.1

kernel-64kb-extra: before 5.14.21-150400.24.136.1

dtb-lg: before 5.14.21-150400.24.136.1

dtb-exynos: before 5.14.21-150400.24.136.1

dtb-freescale: before 5.14.21-150400.24.136.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.136.1

dtb-amlogic: before 5.14.21-150400.24.136.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-hisilicon: before 5.14.21-150400.24.136.1

dtb-apm: before 5.14.21-150400.24.136.1

dtb-rockchip: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-arm: before 5.14.21-150400.24.136.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.136.1

dtb-altera: before 5.14.21-150400.24.136.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.136.1

dtb-allwinner: before 5.14.21-150400.24.136.1

dtb-broadcom: before 5.14.21-150400.24.136.1

dtb-qcom: before 5.14.21-150400.24.136.1

dtb-sprd: before 5.14.21-150400.24.136.1

dtb-mediatek: before 5.14.21-150400.24.136.1

dtb-aarch64: before 5.14.21-150400.24.136.1

kernel-livepatch-5_14_21-150400_24_136-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-5_14_21-150400_24_136-default: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_32-debugsource: before 1-150400.9.3.1

kernel-kvmsmall: before 5.14.21-150400.24.136.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional: before 5.14.21-150400.24.136.1

gfs2-kmp-default: before 5.14.21-150400.24.136.1

cluster-md-kmp-default: before 5.14.21-150400.24.136.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-livepatch: before 5.14.21-150400.24.136.1

ocfs2-kmp-default: before 5.14.21-150400.24.136.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.136.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.136.1

dlm-kmp-default: before 5.14.21-150400.24.136.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-qa: before 5.14.21-150400.24.136.1

kselftests-kmp-default: before 5.14.21-150400.24.136.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-default-base-rebuild: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.136.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.136.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-debuginfo: before 5.14.21-150400.24.136.1

kernel-debug-devel: before 5.14.21-150400.24.136.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.136.1

kernel-debug-debugsource: before 5.14.21-150400.24.136.1

kernel-debug: before 5.14.21-150400.24.136.1

kernel-source-vanilla: before 5.14.21-150400.24.136.1

kernel-docs-html: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.136.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.136.1

kernel-zfcpdump: before 5.14.21-150400.24.136.1

reiserfs-kmp-default: before 5.14.21-150400.24.136.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.136.1

kernel-64kb-devel: before 5.14.21-150400.24.136.1

kernel-64kb-debugsource: before 5.14.21-150400.24.136.1

kernel-64kb: before 5.14.21-150400.24.136.1

kernel-docs: before 5.14.21-150400.24.136.1

kernel-devel: before 5.14.21-150400.24.136.1

kernel-macros: before 5.14.21-150400.24.136.1

kernel-source: before 5.14.21-150400.24.136.1

kernel-default-extra: before 5.14.21-150400.24.136.1

kernel-default-devel: before 5.14.21-150400.24.136.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.136.1

kernel-default-debuginfo: before 5.14.21-150400.24.136.1

kernel-syms: before 5.14.21-150400.24.136.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.136.1

kernel-obs-build: before 5.14.21-150400.24.136.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.136.1

kernel-default-debugsource: before 5.14.21-150400.24.136.1

kernel-default-base: before 5.14.21-150400.24.136.1.150400.24.66.1

kernel-default: before 5.14.21-150400.24.136.1

CPE2.3 External links

http://www.suse.com/support/update/announcement/2024/suse-su-20243547-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###