Security update for the Linux Kernel
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-35863: smb: client: fix potential UAF in is_valid_oplock_break() (bsc#1224763). - CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1234025). - CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235217). - CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235230). - CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235430). - CVE-2024-56759: btrfs: fix use-after-free when COWing tree bock and tracing is enabled (bsc#1235645). - CVE-2024-57850: jffs2: Prevent rtime decompress memory corruption (bsc#1235812). - CVE-2024-57893: ALSA: seq: oss: Fix races at processing SysEx messages (bsc#1235920).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-35863: smb: client: fix potential UAF in is_valid_oplock_break() (bsc#1224763). - CVE-2024-53104: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (bsc#1234025). - CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235217). - CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235230). - CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235430). - CVE-2024-56759: btrfs: fix use-after-free when COWing tree bock and tracing is enabled (bsc#1235645). - CVE-2024-57850: jffs2: Prevent rtime decompress memory corruption (bsc#1235812). - CVE-2024-57893: ALSA: seq: oss: Fix races at processing SysEx messages (bsc#1235920).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1224763
- https://bugzilla.suse.com/1234025
- https://bugzilla.suse.com/1234853
- https://bugzilla.suse.com/1234891
- https://bugzilla.suse.com/1234963
- https://bugzilla.suse.com/1235054
- https://bugzilla.suse.com/1235061
- https://bugzilla.suse.com/1235073
- https://bugzilla.suse.com/1235217
- https://bugzilla.suse.com/1235230
- https://bugzilla.suse.com/1235430
- https://bugzilla.suse.com/1235645
- https://bugzilla.suse.com/1235812
- https://bugzilla.suse.com/1235920
- https://www.suse.com/security/cve/CVE-2024-35863
- https://www.suse.com/security/cve/CVE-2024-53104
- https://www.suse.com/security/cve/CVE-2024-53173
- https://www.suse.com/security/cve/CVE-2024-53239
- https://www.suse.com/security/cve/CVE-2024-56539
- https://www.suse.com/security/cve/CVE-2024-56548
- https://www.suse.com/security/cve/CVE-2024-56600
- https://www.suse.com/security/cve/CVE-2024-56601
- https://www.suse.com/security/cve/CVE-2024-56605
- https://www.suse.com/security/cve/CVE-2024-56650
- https://www.suse.com/security/cve/CVE-2024-56759
- https://www.suse.com/security/cve/CVE-2024-57850
- https://www.suse.com/security/cve/CVE-2024-57893
- https://www.suse.com/support/update/announcement/2025/suse-su-20250603-1/