Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2024:0483-1 — kernel-azure (CVE-2024-1086 +10 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2024-1086: Fixed a use-after-free vulnerability inside the nf_tables component that could have been exploited to achieve local privilege escalation (bsc#1219434).
  • CVE-2023-51780: Fixed a use-after-free in do_vcc_ioctl in net/atm/ioctl.c, because of a vcc_recvmsg race condition (bsc#1218730).
  • CVE-2023-46838: Fixed an issue with Xen netback processing of zero-length transmit fragment (bsc#1218836).
  • CVE-2021-33631: Fixed an integer overflow in ext4_write_inline_data_end() (bsc#1219412).
  • CVE-2023-47233: Fixed a use-after-free in the device unplugging (disconnect the USB by hotplug) code inside the brcm80211 component (bsc#1216702).
  • CVE-2023-51043: Fixed use-after-free during a race condition between a nonblocking atomic commit and a driver unload in drivers/gpu/drm/drm_atomic.c (bsc#1219120).
  • CVE-2024-0775: Fixed use-after-free in __ext4_remount in fs/ext4/super.c that could allow a local user to cause an information leak problem while freeing the old quota file names before a potential failure (bsc#1219053).
  • CVE-2023-6040: Fixed an out-of-bounds access vulnerability while creating a new netfilter table, lack of a safeguard against invalid nf_tables family (pf) values within nf_tables_newtable function (bsc#1218752).
  • CVE-2023-51782: Fixed use-after-free in rose_ioctl in net/rose/af_rose.c because of a rose_accept race condition (bsc#1218757).
  • CVE-2024-0340: Fixed information disclosure in vhost/vhost.c:vhost_new_msg() (bsc#1218689).
  • CVE-2023-51042: Fixed use-after-free in amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c (bsc#1219128).

The following non-security bugs were fixed:

  • Store the old kernel changelog entries in kernel-docs package (bsc#1218713)
  • 9p: missing chunk of 'fs/9p: Do not update file type when updating file attributes' (git-fixes).
  • ACPICA: Avoid cache flush inside virtual machines (git-fixes).
  • GFS2: Flush the GFS2 delete workqueue before stopping the kernel threads (git-fixes).
  • KVM: s390: vsie: Fix STFLE interpretive execution identification (git-fixes bsc#1219022).
  • UAPI: ndctl: Fix g++-unsupported initialisation in headers (git-fixes).
  • USB: serial: option: add Fibocom to DELL custom modem FM101R-GL (git-fixes).
  • USB: serial: option: add Telit LE910C4-WWX 0x1035 composition (git-fixes).
  • USB: serial: option: add entry for Sierra EM9191 with new firmware (git-fixes).
  • USB: serial: option: fix FM101R-GL defines (git-fixes).
  • acpi/nfit: Require opt-in for read-only label configurations (git-fixes).
  • acpi/nfit: improve bounds checking for 'func' (git-fixes).
  • affs: fix basic permission bits to actually work (git-fixes).
  • aio: fix mremap after fork null-deref (git-fixes).
  • asix: Add check for usbnet_get_endpoints (git-fixes).
  • bnxt_en: Log unknown link speed appropriately (git-fixes).
  • ceph: fix incorrect revoked caps assert in ceph_fill_file_size() (bsc#1219445).
  • chardev: fix error handling in cdev_device_add() (git-fixes).
  • configfs: fix a deadlock in configfs_symlink() (git-fixes).
  • configfs: fix a race in configfs_{,un}register_subsystem() (git-fixes).
  • configfs: fix a use-after-free in __configfs_open_file (git-fixes).
  • configfs: fix config_item refcnt leak in configfs_rmdir() (git-fixes).
  • configfs: fix memleak in configfs_release_bin_file (git-fixes).
  • configfs: new object reprsenting tree fragments (git-fixes).
  • configfs: provide exclusion between IO and removals (git-fixes).
  • configfs: stash the data we need into configfs_buffer at open time (git-fixes).
  • ext4: Avoid freeing inodes on dirty list (bsc#1216989).
  • ext4: silence the warning when evicting inode with dioread_nolock (bsc#1206889).
  • fat: add ratelimit to fat*_ent_bread() (git-fixes).
  • fs/exofs: fix potential memory leak in mount option parsing (git-fixes).
  • fs/fat/fatent.c: add cond_resched() to fat_count_free_clusters() (git-fixes).
  • fs/fat/file.c: issue flush after the writeback of FAT (git-fixes).
  • fs/file.c: initialize init_files.resize_wait (git-fixes).
  • fs: do not audit the capability check in simple_xattr_list() (git-fixes).
  • fs: ocfs2: namei: check return value of ocfs2_add_entry() (git-fixes).
  • fs: orangefs: fix error return code of orangefs_revalidate_lookup() (git-fixes).
  • fs: ratelimit __find_get_block_slow() failure message (git-fixes).
  • fs: warn about impending deprecation of mandatory locks (git-fixes).
  • gfs2: Allow lock_nolock mount to specify jid=X (git-fixes).
  • gfs2: Check sb_bsize_shift after reading superblock (git-fixes).
  • gfs2: Do not call dlm after protocol is unmounted (git-fixes).
  • gfs2: Do not set GFS2_RDF_UPTODATE when the lvb is updated (git-fixes).
  • gfs2: Do not skip dlm unlock if glock had an lvb (git-fixes).
  • gfs2: Fix inode height consistency check (git-fixes).
  • gfs2: Fix lru_count going negative (git-fixes).
  • gfs2: Fix marking

Affected software

SUSE-SU-2024:0483-1 is recorded against 3 packages.

  • kernel-azure (fixed in 4.12.14-16.168.1)
  • kernel-source-azure (fixed in 4.12.14-16.168.1)
  • kernel-syms-azure (fixed in 4.12.14-16.168.1)

Timeline and source

Published on 15 February 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-02-15
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-azure 4.12.14-16.168.1
kernel-source-azure 4.12.14-16.168.1
kernel-syms-azure 4.12.14-16.168.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:0483-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:0483-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.