FlawAtlas
Search the atlas
SUSE-SU-2025:0243-1 Not scored

Security update for the Linux Kernel (Live Patch 46 for SLE 15 SP3)

This update for the Linux Kernel 5.3.18-150300_59_167 fixes several issues. The following security issues were fixed: - CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). - CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (bsc#1233712). - CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). - CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). - CVE-2021-47598: sch_cake: do not call cake_destroy() from cake_init() (bsc#1227471). - CVE-2021-47291: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions (bsc#1227651). - CVE-2024-41059: hfsplus: fix uninit-value in copy_name (bsc#1228573).

Exploit probability Not scored
Published January 27, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP3 kernel-livepatch-SLE15-SP3_Update_46

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:0243-1

This update for the Linux Kernel 5.3.18-150300_59_167 fixes several issues. The following security issues were fixed: - CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226324). - CVE-2024-50264: vsock/virtio: Initialization of the dangling pointer occurring in vsk->trans (bsc#1233712). - CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1232637). - CVE-2024-43861: Fix memory leak for not ip packets (bsc#1229553). - CVE-2021-47598: sch_cake: do not call cake_destroy() from cake_init() (bsc#1227471). - CVE-2021-47291: ipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions (bsc#1227651). - CVE-2024-41059: hfsplus: fix uninit-value in copy_name (bsc#1228573).

View original source

05 / REFERENCES

Further evidence