FlawAtlas
Search the atlas
SUSE-SU-2024:4140-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-47589: igbvf: fix double free in `igbvf_probe` (bsc#1226557). - CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893). - CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() (bsc#1231979). - CVE-2022-48962: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() (bsc#1232286). - CVE-2022-48967: NFC: nci: Bounds check struct nfc_target arrays (bsc#1232304). - CVE-2022-48988: memcg: Fix possible use-after-free in memcg_write_event_control() (bsc#1232069). - CVE-2022-48991: khugepaged: retract_page_tables() remember to test exit (bsc#1232070 prerequisity). - CVE-2022-49003: nvme: fix SRCU protection of nvme_ns_head list (bsc#1232136). - CVE-2022-49014: net: tun: Fix use-after-free in tun_detach() (bsc#1231890). - CVE-2022-49015: net: hsr: Fix potential use-after-free (bsc#1231938). - CVE-2022-49023: wifi: cfg80211: fix buffer overflow in elem comparison (bsc#1231961). - CVE-2022-49025: net/mlx5e: Fix use-after-free when reverting termination table (bsc#1231960). - CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230429). - CVE-2024-45026: s390/dasd: fix error recovery leading to data corruption on ESE devices (bsc#1230454). - CVE-2024-46813: drm/amd/display: Check link_index before accessing dc->links (bsc#1231191). - CVE-2024-46814: drm/amd/display: Check msg_id before processing transcation (bsc#1231193). - CVE-2024-46816: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (bsc#1231197). - CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 (bsc#1231200). - CVE-2024-46818: drm/amd/display: Check gpio_id before used as array index (bsc#1231203). - CVE-2024-46849: ASoC: meson: axg-card: fix 'use-after-free' (bsc#1231073). - CVE-2024-47668: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (bsc#1231502). - CVE-2024-47674: mm: avoid leaving partial pfn mappings around in error case (bsc#1231673). - CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231987). - CVE-2024-47706: block, bfq: fix possible UAF for bfqq->bic with merge chain (bsc#1231942). - CVE-2024-47747: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition (bsc#1232145). - CVE-2024-49860: ACPI: sysfs: validate return type of _STR method (bsc#1231861). - CVE-2024-49936: net/xen-netback: prevent UAF in xenvif_flush_hash() (bsc#1232424). - CVE-2024-49969: drm/amd/display: Fix index out of bounds in DCN30 color transformation (bsc#1232519). - CVE-2024-49974: NFSD: Force all NFSv4.2 COPY requests to be synchronous (bsc#1232383). - CVE-2024-49991: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer (bsc#1232282). - CVE-2024-49995: tipc: guard against string buffer overrun (bsc#1232432). - CVE-2024-50047: smb: client: fix UAF in async decryption (bsc#1232418). The following non-security bugs were fixed: - bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation (bsc#1231375). - kernel-binary: generate and install compile_commands.json (bsc#1228971) - kernel-binary: vdso: Own module_dir - mkspec-dtb: add toplevel symlinks also on arm - net: mana: Fix the extra HZ in mana_hwc_send_request (bsc#1232033). - scsi: ibmvfc: Add max_sectors module parameter (bsc#1216223).

Exploit probability Not scored
Published December 2, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-syms
SUSE:Enterprise Storage 7.1 kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-preempt
SUSE:Enterprise Storage 7.1 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-docs
SUSE:Linux Enterprise Micro 5.2 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-preempt
SUSE:Linux Enterprise Micro 5.2 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Micro 5.1 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Micro 5.1 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise High Availability Extension 15 SP3 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-source
SUSE:Enterprise Storage 7.1 kernel-64kb
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-preempt
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-zfcpdump
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-default
SUSE:Enterprise Storage 7.1 kernel-preempt
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-livepatch-SLE15-SP3_Update_50
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2024:4140-1

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-47589: igbvf: fix double free in `igbvf_probe` (bsc#1226557). - CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893). - CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() (bsc#1231979). - CVE-2022-48962: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() (bsc#1232286). - CVE-2022-48967: NFC: nci: Bounds check struct nfc_target arrays (bsc#1232304). - CVE-2022-48988: memcg: Fix possible use-after-free in memcg_write_event_control() (bsc#1232069). - CVE-2022-48991: khugepaged: retract_page_tables() remember to test exit (bsc#1232070 prerequisity). - CVE-2022-49003: nvme: fix SRCU protection of nvme_ns_head list (bsc#1232136). - CVE-2022-49014: net: tun: Fix use-after-free in tun_detach() (bsc#1231890). - CVE-2022-49015: net: hsr: Fix potential use-after-free (bsc#1231938). - CVE-2022-49023: wifi: cfg80211: fix buffer overflow in elem comparison (bsc#1231961). - CVE-2022-49025: net/mlx5e: Fix use-after-free when reverting termination table (bsc#1231960). - CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230429). - CVE-2024-45026: s390/dasd: fix error recovery leading to data corruption on ESE devices (bsc#1230454). - CVE-2024-46813: drm/amd/display: Check link_index before accessing dc->links (bsc#1231191). - CVE-2024-46814: drm/amd/display: Check msg_id before processing transcation (bsc#1231193). - CVE-2024-46816: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (bsc#1231197). - CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 (bsc#1231200). - CVE-2024-46818: drm/amd/display: Check gpio_id before used as array index (bsc#1231203). - CVE-2024-46849: ASoC: meson: axg-card: fix 'use-after-free' (bsc#1231073). - CVE-2024-47668: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (bsc#1231502). - CVE-2024-47674: mm: avoid leaving partial pfn mappings around in error case (bsc#1231673). - CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231987). - CVE-2024-47706: block, bfq: fix possible UAF for bfqq->bic with merge chain (bsc#1231942). - CVE-2024-47747: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition (bsc#1232145). - CVE-2024-49860: ACPI: sysfs: validate return type of _STR method (bsc#1231861). - CVE-2024-49936: net/xen-netback: prevent UAF in xenvif_flush_hash() (bsc#1232424). - CVE-2024-49969: drm/amd/display: Fix index out of bounds in DCN30 color transformation (bsc#1232519). - CVE-2024-49974: NFSD: Force all NFSv4.2 COPY requests to be synchronous (bsc#1232383). - CVE-2024-49991: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer (bsc#1232282). - CVE-2024-49995: tipc: guard against string buffer overrun (bsc#1232432). - CVE-2024-50047: smb: client: fix UAF in async decryption (bsc#1232418). The following non-security bugs were fixed: - bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation (bsc#1231375). - kernel-binary: generate and install compile_commands.json (bsc#1228971) - kernel-binary: vdso: Own module_dir - mkspec-dtb: add toplevel symlinks also on arm - net: mana: Fix the extra HZ in mana_hwc_send_request (bsc#1232033). - scsi: ibmvfc: Add max_sectors module parameter (bsc#1216223).

View original source

05 / REFERENCES

Further evidence