Security update for kernel-livepatch-MICRO-6-0_Update_3
This update for kernel-livepatch-MICRO-6-0_Update_3 fixes the following issues: - CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235231) - CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233708) - CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission (bsc#1233680) - CVE-2024-53074: wifi: iwlwifi: mvm: don't leak a link on AP removal (bsc#1235086) - CVE-2024-56582: btrfs: fix use-after-free in btrfs_encoded_read_endio() (bsc#1235129) - CVE-2024-53208: Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync (bsc#1236244) - CVE-2024-50257: netfilter: fix use-after-free in get_info() (bsc#1233245) - CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232908) - CVE-2024-56605: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (bsc#1235062) - CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232929) - CVE-2024-50124: Bluetooth: ISO: Fix UAF on iso_sock_timeout (bsc#1232927)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for kernel-livepatch-MICRO-6-0_Update_3 fixes the following issues: - CVE-2024-56601: net: inet: do not leave a dangling sk pointer in inet_create() (bsc#1235231) - CVE-2024-50279: dm cache: fix out-of-bounds access to the dirty bitset when resizing (bsc#1233708) - CVE-2024-50301: security/keys: fix slab-out-of-bounds in key_task_permission (bsc#1233680) - CVE-2024-53074: wifi: iwlwifi: mvm: don't leak a link on AP removal (bsc#1235086) - CVE-2024-56582: btrfs: fix use-after-free in btrfs_encoded_read_endio() (bsc#1235129) - CVE-2024-53208: Bluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync (bsc#1236244) - CVE-2024-50257: netfilter: fix use-after-free in get_info() (bsc#1233245) - CVE-2024-50127: net: sched: fix use-after-free in taprio_change() (bsc#1232908) - CVE-2024-56605: Bluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create() (bsc#1235062) - CVE-2024-50125: Bluetooth: SCO: Fix UAF on sco_sock_timeout (bsc#1232929) - CVE-2024-50124: Bluetooth: ISO: Fix UAF on iso_sock_timeout (bsc#1232927)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1232908
- https://bugzilla.suse.com/1232927
- https://bugzilla.suse.com/1232929
- https://bugzilla.suse.com/1233245
- https://bugzilla.suse.com/1233680
- https://bugzilla.suse.com/1233708
- https://bugzilla.suse.com/1235062
- https://bugzilla.suse.com/1235086
- https://bugzilla.suse.com/1235129
- https://bugzilla.suse.com/1235231
- https://bugzilla.suse.com/1236244
- https://www.suse.com/security/cve/CVE-2024-50124
- https://www.suse.com/security/cve/CVE-2024-50125
- https://www.suse.com/security/cve/CVE-2024-50127
- https://www.suse.com/security/cve/CVE-2024-50257
- https://www.suse.com/security/cve/CVE-2024-50279
- https://www.suse.com/security/cve/CVE-2024-50301
- https://www.suse.com/security/cve/CVE-2024-53074
- https://www.suse.com/security/cve/CVE-2024-53208
- https://www.suse.com/security/cve/CVE-2024-56582
- https://www.suse.com/security/cve/CVE-2024-56601
- https://www.suse.com/security/cve/CVE-2024-56605
- https://www.suse.com/support/update/announcement/2025/suse-su-202520437-1/