{"schema_version":"1.7.3","id":"SUSE-SU-2024:4081-1","published":"2024-11-27T14:22:35Z","modified":"2026-02-04T04:27:53.063098Z","related":["CVE-2021-47416","CVE-2022-3435","CVE-2022-45934","CVE-2022-48664","CVE-2022-48947","CVE-2022-48956","CVE-2022-48960","CVE-2022-48962","CVE-2022-48967","CVE-2022-48970","CVE-2022-48988","CVE-2022-48991","CVE-2022-48999","CVE-2022-49003","CVE-2022-49014","CVE-2022-49015","CVE-2022-49023","CVE-2022-49025","CVE-2023-28327","CVE-2023-46343","CVE-2023-52881","CVE-2023-52919","CVE-2023-6270","CVE-2024-27043","CVE-2024-36971","CVE-2024-42145","CVE-2024-44947","CVE-2024-45016","CVE-2024-45026","CVE-2024-46813","CVE-2024-46814","CVE-2024-46815","CVE-2024-46816","CVE-2024-46817","CVE-2024-46818","CVE-2024-46849","CVE-2024-47668","CVE-2024-47674","CVE-2024-47684","CVE-2024-47706","CVE-2024-47747","CVE-2024-49860","CVE-2024-49867","CVE-2024-49936","CVE-2024-49969","CVE-2024-49974","CVE-2024-49982","CVE-2024-49991","CVE-2024-49995","CVE-2024-50047"],"upstream":["CVE-2021-47416","CVE-2022-3435","CVE-2022-45934","CVE-2022-48664","CVE-2022-48947","CVE-2022-48956","CVE-2022-48960","CVE-2022-48962","CVE-2022-48967","CVE-2022-48970","CVE-2022-48988","CVE-2022-48991","CVE-2022-48999","CVE-2022-49003","CVE-2022-49014","CVE-2022-49015","CVE-2022-49023","CVE-2022-49025","CVE-2023-28327","CVE-2023-46343","CVE-2023-52881","CVE-2023-52919","CVE-2023-6270","CVE-2024-27043","CVE-2024-36971","CVE-2024-42145","CVE-2024-44947","CVE-2024-45016","CVE-2024-45026","CVE-2024-46813","CVE-2024-46814","CVE-2024-46815","CVE-2024-46816","CVE-2024-46817","CVE-2024-46818","CVE-2024-46849","CVE-2024-47668","CVE-2024-47674","CVE-2024-47684","CVE-2024-47706","CVE-2024-47747","CVE-2024-49860","CVE-2024-49867","CVE-2024-49936","CVE-2024-49969","CVE-2024-49974","CVE-2024-49982","CVE-2024-49991","CVE-2024-49995","CVE-2024-50047"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2022-48956: ipv6: avoid use-after-free in ip6_fragment() (bsc#1231893).\n- CVE-2022-48960: net: hisilicon: Fix potential use-after-free in hix5hd2_rx() (bsc#1231979).\n- CVE-2022-48962: net: hisilicon: Fix potential use-after-free in hisi_femac_rx() (bsc#1232286).\n- CVE-2022-48967: NFC: nci: Bounds check struct nfc_target arrays (bsc#1232304).\n- CVE-2022-48988: memcg: Fix possible use-after-free in memcg_write_event_control() (bsc#1232069).\n- CVE-2022-48991: mm/khugepaged: fix collapse_pte_mapped_thp() to allow anon_vma (bsc#1232070).\n- CVE-2022-49003: nvme: fix SRCU protection of nvme_ns_head list (bsc#1232136).\n- CVE-2022-49014: net: tun: Fix use-after-free in tun_detach() (bsc#1231890).\n- CVE-2022-49015: net: hsr: Fix potential use-after-free (bsc#1231938).\n- CVE-2022-49023: wifi: cfg80211: fix buffer overflow in elem comparison (bsc#1231961).\n- CVE-2022-49025: net/mlx5e: Fix use-after-free when reverting termination table (bsc#1231960).\n- CVE-2024-36971: Fixed __dst_negative_advice() race (bsc#1226145).\n- CVE-2024-45016: netem: fix return value if duplicate enqueue fails (bsc#1230429).\n- CVE-2024-45026: s390/dasd: fix error recovery leading to data corruption on ESE devices (bsc#1230454).\n- CVE-2024-46813: drm/amd/display: Check link_index before accessing dc->links (bsc#1231191).\n- CVE-2024-46814: drm/amd/display: Check msg_id before processing transcation (bsc#1231193).\n- CVE-2024-46815: drm/amd/display: Check num_valid_sets before accessing reader_wm_sets (bsc#1231195).\n- CVE-2024-46816: drm/amd/display: Stop amdgpu_dm initialize when link nums greater than max_links (bsc#1231197).\n- CVE-2024-46817: drm/amd/display: Stop amdgpu_dm initialize when stream nums greater than 6 (bsc#1231200).\n- CVE-2024-46818: drm/amd/display: Check gpio_id before used as array index (bsc#1231203).\n- CVE-2024-46849: ASoC: meson: axg-card: fix 'use-after-free' (bsc#1231073).\n- CVE-2024-47668: lib/generic-radix-tree.c: Fix rare race in __genradix_ptr_alloc() (bsc#1231502).\n- CVE-2024-47674: mm: avoid leaving partial pfn mappings around in error case (bsc#1231673).\n- CVE-2024-47684: tcp: check skb is non-NULL in tcp_rto_delta_us() (bsc#1231987).\n- CVE-2024-47706: block, bfq: fix possible UAF for bfqq->bic with merge chain (bsc#1231942).\n- CVE-2024-47747: net: seeq: Fix use after free vulnerability in ether3 Driver Due to Race Condition (bsc#1232145).\n- CVE-2024-49860: ACPI: sysfs: validate return type of _STR method (bsc#1231861).\n- CVE-2024-49936: net/xen-netback: prevent UAF in xenvif_flush_hash() (bsc#1232424).\n- CVE-2024-49969: drm/amd/display: Fix index out of bounds in DCN30 color transformation (bsc#1232519).\n- CVE-2024-49974: NFSD: Force all NFSv4.2 COPY requests to be synchronous (bsc#1232383).\n- CVE-2024-49991: drm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer (bsc#1232282).\n- CVE-2024-49995: tipc: guard against string buffer overrun (bsc#1232432).\n- CVE-2024-50047: smb: client: fix UAF in async decryption (bsc#1232418).\n\nThe following non-security bugs were fixed:\n\n- kernel-binary: generate and install compile_commands.json (bsc#1228971)\n- kernel-binary: vdso: Own module_dir\n- bpf: Fix pointer-leak due to insufficient speculative store bypass mitigation (bsc#1231375).\n- mkspec-dtb: add toplevel symlinks also on arm\n- net: mana: Fix the extra HZ in mana_hwc_send_request (bsc#1232033).\n- scsi: ibmvfc: Add max_sectors module parameter (bsc#1216223).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.191.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.191.1","kernel-source-rt":"5.3.18-150300.191.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4081-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.191.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.191.1","kernel-source-rt":"5.3.18-150300.191.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4081-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.191.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.191.1","kernel-source-rt":"5.3.18-150300.191.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4081-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.191.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.191.1","kernel-source-rt":"5.3.18-150300.191.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:4081-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20244081-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195775"},{"type":"REPORT","url":"https://bugzilla.suse.com/1204171"},{"type":"REPORT","url":"https://bugzilla.suse.com/1205796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209290"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216223"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1219125"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223384"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223524"},{"type":"REPORT","url":"https://bugzilla.suse.com/1223824"},{"type":"REPORT","url":"https://bugzilla.suse.com/1225189"},{"type":"REPORT","url":"https://bugzilla.suse.com/1225336"},{"type":"REPORT","url":"https://bugzilla.suse.com/1225611"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226211"},{"type":"REPORT","url":"https://bugzilla.suse.com/1226212"},{"type":"REPORT","url":"https://bugzilla.suse.com/1228743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229042"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229454"},{"type":"REPORT","url":"https://bugzilla.suse.com/1229456"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230454"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231073"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231191"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231197"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231200"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231203"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231293"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231375"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231861"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231887"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231890"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231893"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231936"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231960"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231961"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231979"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231987"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231988"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232069"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232070"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232136"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232262"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232383"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232424"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232432"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-47416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3435"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-45934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48999"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49003"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49014"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-46343"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-52881"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-52919"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6270"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-27043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-36971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-42145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-44947"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-45026"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46813"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46815"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46816"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46817"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46818"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46849"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47668"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47684"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47747"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49867"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49991"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-49995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-50047"}]}