Security update for the Linux Kernel
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-38538: net: bridge: xmit: make sure we have at least eth header len bytes (bsc#1226606). - CVE-2024-40902: jfs: xattr: fix buffer overflow for invalid xattr (bsc#1227764). - CVE-2024-42104: nilfs2: add missing check for inode numbers on directory entries (bsc#1228654). - CVE-2024-42148: Fix multiple UBSAN array-index-out-of-bounds (bsc#1228487). - CVE-2024-45021: memcg_write_event_control(): fix a user-triggerable oops (bsc#1230434). The following non-security bugs were fixed: - alarmtimer: Lock k_itimer during timer callback (bsc#1214298). - alarmtimers: Add alarm_forward functionality (bsc#1214298). - alarmtimers: Change alarmtimer functions to return alarmtimer_restart (bsc#1214298). - alarmtimers: Push rearming peroidic timers down into alamrtimer (bsc#1214298). - alarmtimers: Remove interval cap limit hack (bsc#1214298). - kABI fix for alarmtimer_restart functionality (bsc#1214298). - kABI fix update for alarm_forward (bsc#1214298).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-38538: net: bridge: xmit: make sure we have at least eth header len bytes (bsc#1226606). - CVE-2024-40902: jfs: xattr: fix buffer overflow for invalid xattr (bsc#1227764). - CVE-2024-42104: nilfs2: add missing check for inode numbers on directory entries (bsc#1228654). - CVE-2024-42148: Fix multiple UBSAN array-index-out-of-bounds (bsc#1228487). - CVE-2024-45021: memcg_write_event_control(): fix a user-triggerable oops (bsc#1230434). The following non-security bugs were fixed: - alarmtimer: Lock k_itimer during timer callback (bsc#1214298). - alarmtimers: Add alarm_forward functionality (bsc#1214298). - alarmtimers: Change alarmtimer functions to return alarmtimer_restart (bsc#1214298). - alarmtimers: Push rearming peroidic timers down into alamrtimer (bsc#1214298). - alarmtimers: Remove interval cap limit hack (bsc#1214298). - kABI fix for alarmtimer_restart functionality (bsc#1214298). - kABI fix update for alarm_forward (bsc#1214298).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1214298
- https://bugzilla.suse.com/1226606
- https://bugzilla.suse.com/1227764
- https://bugzilla.suse.com/1228487
- https://bugzilla.suse.com/1228654
- https://bugzilla.suse.com/1230434
- https://www.suse.com/security/cve/CVE-2024-38538
- https://www.suse.com/security/cve/CVE-2024-40902
- https://www.suse.com/security/cve/CVE-2024-42104
- https://www.suse.com/security/cve/CVE-2024-42148
- https://www.suse.com/security/cve/CVE-2024-45021
- https://www.suse.com/support/update/announcement/2024/suse-su-20243617-1/