SUSE-SU-2024:2362-1

Advisory lineage Upstream: 72 Downstream: 0
Published: 09 Jul 2024, 14:02
Last modified:04 Feb 2026, 04:35

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

09 Jul 2024, 14:02
Published
Vulnerability first disclosed
04 Feb 2026, 04:35
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-47247: net/mlx5e: Fix use-after-free of encap entry in neigh update handler (bsc#1224865). - CVE-2021-47311: net: qcom/emac: fix UAF in emac_remove (bsc#1225010). - CVE-2021-47368: enetc: Fix illegal access when reading affinity_hint (bsc#1225161). - CVE-2021-47372: net: macb: fix use after free on rmmod (bsc#1225184). - CVE-2021-47379: blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd (bsc#1225203). - CVE-2021-47571: staging: rtl8192e: Fix use after free in _rtl92e_pci_disconnect() (bsc#1225518). - CVE-2022-48760: USB: core: Fix hang in usb_kill_urb by adding memory barriers (bsc#1226712). - CVE-2023-52707: sched/psi: Fix use-after-free in ep_remove_wait_queue() (bsc#1225109). polled (bsc#1202623). - CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225487). - CVE-2023-52881: tcp: do not accept ACK of bytes we never sent (bsc#1225611). - CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223384). - CVE-2024-35789: Check fast rx for non-4addr sta VLAN changes (bsc#1224749). - CVE-2024-35861: Fixed potential UAF in cifs_signal_cifsd_for_reconnect() (bsc#1224766). - CVE-2024-35862: Fixed potential UAF in smb2_is_network_name_deleted() (bsc#1224764). - CVE-2024-35864: Fixed potential UAF in smb2_is_valid_lease_break() (bsc#1224765). - CVE-2024-35950: drm/client: Fully protect modes with dev->mode_config.mutex (bsc#1224703). - CVE-2024-36894: usb: gadget: f_fs: Fix race between aio_cancel() and AIO request complete (bsc#1225749). - CVE-2024-36904: tcp: Use refcount_inc_not_zero() in tcp_twsk_unique() (bsc#1225732). - CVE-2024-36940: pinctrl: core: delete incorrect free in pinctrl_enable() (bsc#1225840). - CVE-2024-36964: fs/9p: only translate RWX permissions for plain 9P2000 (bsc#1225866). - CVE-2024-38545: RDMA/hns: Fix UAF for cq async event (bsc#1226595) - CVE-2024-38559: scsi: qedf: Ensure the copied buf is NUL terminated (bsc#1226758). - CVE-2024-38560: scsi: bfa: Ensure the copied buf is NUL terminated (bsc#1226786). The following non-security bugs were fixed: - NFS: avoid infinite loop in pnfs_update_layout (bsc#1219633 bsc#1226226). - ocfs2: adjust enabling place for la window (bsc#1219224). - ocfs2: fix sparse warnings (bsc#1219224). - ocfs2: improve write IO performance when fragmentation is high (bsc#1219224). - ocfs2: speed up chain-list searching (bsc#1219224). - psi: Fix uaf issue when psi trigger is destroyed while being - x86/tsc: Trust initial offset in architectural TSC-adjust MSRs (bsc#1222015 bsc#1226962).

Affected Systems

  • susekernel-64kb&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-64kb&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-default-base&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.1

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.2

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1.150300.18.98.1

  • susekernel-default&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.1

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.2

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-docs&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-livepatch-SLE15-SP3_Update_46&distro=SUSE Linux Enterprise Live Patching 15 SP3

    < 1-150300.7.3.1

  • susekernel-obs-build&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-preempt&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-preempt&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-preempt&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-preempt&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-source&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-syms&distro=SUSE Enterprise Storage 7.1

    < 5.3.18-150300.59.167.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP3

    < 5.3.18-150300.59.167.1

  • susekernel-zfcpdump&distro=SUSE Linux Enterprise Server 15 SP3-LTSS

    < 5.3.18-150300.59.167.1

References (155)