SUSE-SU-2024:1669-1

    Dashboard / Vulnerabilities / SUSE-SU-2024:1669-1

    SUSE-SU-2024:1669-1

    Published: 16 May 2024Last Modified: 4 Feb 2026

    Summary: Security update for the Linux Kernel

    Details: The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2024-27043: Fixed a use-after-free in edia/dvbdev in different places (bsc#1223824). - CVE-2024-26733: Fixed an overflow in arp_req_get() in arp (bsc#1222585). - CVE-2022-48619: Fixed a denial-of-service issue in drivers/input/input.c (bsc#1218220). - CVE-2021-46904: Fixed NULL pointer dereference during tty device unregistration (bsc#1220416). - CVE-2023-28746: Fixed Register File Data Sampling (bsc#1213456). - CVE-2021-46905: Fixed NULL pointer dereference on disconnect regression (bsc#1220418). - CVE-2023-52340: Fixed a denial of service related to ICMPv6 'Packet Too Big' packets (bsc#1219295). - CVE-2021-46932: Initialized work before appletouch device registration (bsc#1220444). - CVE-2023-52449: Fixed gluebi NULL pointer dereference caused by ftl notifier (bsc#1220238). - CVE-2023-52475: Fixed a use-after-free in powermate_config_complete() (bsc#1220649). - CVE-2023-52445: Fixed a use-after-free on context disconnection in pvrusb2 (bsc#1220241). - CVE-2023-52429: Limited the number of targets and parameter size area for device mapper (bsc#1219146). - CVE-2023-51780: Fixed a use-after-free in do_vcc_ioctl() related to a vcc_recvmsg race condition (bsc#1218730). - CVE-2023-51782: Fixed a use-after-free in rose_ioctl() related to a rose_accept race condition (bsc#1218757). - CVE-2023-31083: Fixed a NULL pointer dereference in hci_uart_tty_ioctl() (bsc#1210780). The following non-security bugs were fixed: - KVM: VMX: Move VERW closer to VMentry for MDS mitigation (git-fixes). - KVM: VMX: Use BT+JNC, i.e. EFLAGS.CF to select VMRESUME vs. VMLAUNCH (git-fixes). - tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc (bsc#1222619). - x86/asm: Add _ASM_RIP() macro for x86-64 (%rip) suffix (git-fixes). - x86/bugs: Add asm helpers for executing VERW (bsc#1213456). - x86/bugs: Use ALTERNATIVE() instead of mds_user_clear static key (git-fixes). - x86/entry_32: Add VERW just before userspace transition (git-fixes). - x86/entry_64: Add VERW just before userspace transition (git-fixes).

    References: https://www.suse.com/support/update/announcement/2024/suse-su-20241669-1/, https://bugzilla.suse.com/1210780, https://bugzilla.suse.com/1213456, https://bugzilla.suse.com/1218220, https://bugzilla.suse.com/1218562, https://bugzilla.suse.com/1218730, https://bugzilla.suse.com/1218757, https://bugzilla.suse.com/1219146, https://bugzilla.suse.com/1219295, https://bugzilla.suse.com/1219827, https://bugzilla.suse.com/1220191, https://bugzilla.suse.com/1220238, https://bugzilla.suse.com/1220241, https://bugzilla.suse.com/1220416, https://bugzilla.suse.com/1220418, https://bugzilla.suse.com/1220444, https://bugzilla.suse.com/1220649, https://bugzilla.suse.com/1221044, https://bugzilla.suse.com/1221088, https://bugzilla.suse.com/1221578, https://bugzilla.suse.com/1221598, https://bugzilla.suse.com/1222585, https://bugzilla.suse.com/1222619, https://bugzilla.suse.com/1223016, https://bugzilla.suse.com/1223824, https://www.suse.com/security/cve/CVE-2021-46904, https://www.suse.com/security/cve/CVE-2021-46905, https://www.suse.com/security/cve/CVE-2021-46932, https://www.suse.com/security/cve/CVE-2022-48619, https://www.suse.com/security/cve/CVE-2023-28746, https://www.suse.com/security/cve/CVE-2023-31083, https://www.suse.com/security/cve/CVE-2023-51780, https://www.suse.com/security/cve/CVE-2023-51782, https://www.suse.com/security/cve/CVE-2023-52340, https://www.suse.com/security/cve/CVE-2023-52429, https://www.suse.com/security/cve/CVE-2023-52445, https://www.suse.com/security/cve/CVE-2023-52449, https://www.suse.com/security/cve/CVE-2023-52475, https://www.suse.com/security/cve/CVE-2023-52590, https://www.suse.com/security/cve/CVE-2023-52591, https://www.suse.com/security/cve/CVE-2023-6270, https://www.suse.com/security/cve/CVE-2024-23851, https://www.suse.com/security/cve/CVE-2024-26733, https://www.suse.com/security/cve/CVE-2024-26898, https://www.suse.com/security/cve/CVE-2024-27043

    Affected packages

    Package

    Name: kernel-default

    Purl: pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4%20LTSS%20EXTREME%20CORE

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.0.101-108.153.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2024:1669-1 | CVE-DB