🛡️ SUSE-SU-2024:2203-1 — dtb-aarch64 (CVE-2023-0160 +407 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2023-0160: Fixed deadlock flaw in BPF that could allow a local user to potentially crash the system (bsc#1209657).
  • CVE-2023-52434: Fixed potential OOBs in smb2_parse_contexts() (bsc#1220148).
  • CVE-2023-52458: Fixed check that partition length needs to be aligned with block size (bsc#1220428).
  • CVE-2023-52503: Fixed tee/amdtee use-after-free vulnerability in amdtee_close_session (bsc#1220915).
  • CVE-2023-52618: Fixed string overflow in block/rnbd-srv (bsc#1221615).
  • CVE-2023-52631: Fixed an NULL dereference bug (bsc#1222264 CVE-2023-52631).
  • CVE-2023-52635: Fixed PM/devfreq to synchronize devfreq_monitor_[start/stop] (bsc#1222294).
  • CVE-2023-52640: Fixed out-of-bounds in ntfs_listxattr (bsc#1222301).
  • CVE-2023-52641: Fixed NULL ptr dereference checking at the end of attr_allocate_frame() (bsc#1222303)
  • CVE-2023-52645: Fixed pmdomain/mediatek race conditions with genpd (bsc#1223033).
  • CVE-2023-52652: Fixed NTB for possible name leak in ntb_register_device() (bsc#1223686).
  • CVE-2023-52659: Fixed to pfn_to_kaddr() not treated as a 64-bit type (bsc#1224442).
  • CVE-2023-52674: Add clamp() in scarlett2_mixer_ctl_put() (bsc#1224727).
  • CVE-2023-52680: Fixed missing error checks to *_ctl_get() (bsc#1224608).
  • CVE-2023-52692: Fixed missing error check to scarlett2_usb_set_config() (bsc#1224628).
  • CVE-2023-52698: Fixed memory leak in netlbl_calipso_add_pass() (CVE-2023-52698 bsc#1224621)
  • CVE-2023-52771: Fixed delete_endpoint() vs parent unregistration race (bsc#1225007).
  • CVE-2023-52772: Fixed use-after-free in unix_stream_read_actor() (bsc#1224989).
  • CVE-2023-52860: Fixed null pointer dereference in hisi_hns3 (bsc#1224936).
  • CVE-2023-6238: Fixed kcalloc() arguments order (bsc#1217384).
  • CVE-2023-7042: Fixed a null-pointer-dereference in ath10k_wmi_tlv_op_pull_mgmt_tx_compl_ev() (bsc#1218336).
  • CVE-2024-0639: Fixed a denial-of-service vulnerability due to a deadlock found in sctp_auto_asconf_init in net/sctp/socket.c (bsc#1218917).
  • CVE-2024-21823: Fixed safety flag to struct ends (bsc#1223625).
  • CVE-2024-22099: Fixed a null-pointer-dereference in rfcomm_check_security (bsc#1219170).
  • CVE-2024-23848: Fixed media/cec for possible use-after-free in cec_queue_msg_fh (bsc#1219104).
  • CVE-2024-24861: Fixed an overflow due to race condition in media/xc4000 device driver in xc4000 xc4000_get_frequency() function (bsc#1219623).
  • CVE-2024-25739: Fixed possible crash in create_empty_lvol() in drivers/mtd/ubi/vtbl.c (bsc#1219834).
  • CVE-2024-26601: Fixed ext4 buddy bitmap corruption via fast commit replay (bsc#1220342).
  • CVE-2024-26614: Fixed the initialization of accept_queue's spinlocks (bsc#1221293).
  • CVE-2024-26632: Fixed iterating over an empty bio with bio_for_each_folio_all (bsc#1221635).
  • CVE-2024-26638: Fixed uninitialize struct msghdr completely (bsc#1221649 CVE-2024-26638).
  • CVE-2024-26642: Fixed the set of anonymous timeout flag in netfilter nf_tables (bsc#1221830).
  • CVE-2024-26643: Fixed mark set as dead when unbinding anonymous set with timeout (bsc#1221829).
  • CVE-2024-26654: Fixed use after free in ALSA/sh/aica (bsc#1222304).
  • CVE-2024-26656: Fixed drm/amdgpu use-after-free bug (bsc#1222307).
  • CVE-2024-26671: Fixed blk-mq IO hang from sbitmap wakeup race (bsc#1222357).
  • CVE-2024-26673: Fixed netfilter/nft_ct layer 3 and 4 protocol sanitization (bsc#1222368).
  • CVE-2024-26674: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups (bsc#1222378).
  • CVE-2024-26679: Fixed read sk->sk_family once in inet_recv_error() (bsc#1222385).
  • CVE-2024-26684: Fixed net/stmmac/xgmac handling of DPP safety error for DMA channels (bsc#1222445).
  • CVE-2024-26685: Fixed nilfs2 potential bug in end_buffer_async_write (bsc#1222437).
  • CVE-2024-26692: Fixed regression in writes when non-standard maximum write size negotiated (bsc#1222464).
  • CVE-2024-26704: Fixed a double-free of blocks due to wrong extents moved_len in ext4 (bsc#1222422).
  • CVE-2024-26726: Fixed invalid drop extent_map for free space inode on write error (bsc#1222532)
  • CVE-2024-26731: Fixed NULL pointer dereference in sk_psock_verdict_data_ready() (bsc#1222371).
  • CVE-2024-26733: Fixed an overflow in arp_req_get() in arp (bsc#1222585).
  • CVE-2024-26737: Fixed selftests/bpf racing between bpf_timer_cancel_and_free and bpf_timer_cancel (bsc#1222557).
  • CVE-2024-26740: Fixed use the backlog for mirred ingress (bsc#1222563).
  • CVE-2024-26760: Fixed bio_put() for error case (bsc#1222596 cve-2024-267600).
  • CVE-2024-26760: Fixed scsi/target/pscsi bio_put() for error case (bsc#1222596).
  • CVE-2024-26764: Fixed IOCB_AIO_RW check in fs/aio before the struct aio_kiocb conversion (bsc#1222721).
  • CVE-2024-26772: Fixed ext4 to avoid allocating blocks from corrupted group in ext4_mb_find_by_goal() (bsc#1222613).
  • CVE-2024-26773: Fixed ext4 block allocation fr

Affected software

SUSE-SU-2024:2203-1 is recorded against 13 packages.

  • dtb-aarch64 (fixed in 6.4.0-150600.23.7.1)
  • kernel-64kb (fixed in 6.4.0-150600.23.7.3)
  • kernel-debug (fixed in 6.4.0-150600.23.7.3)
  • kernel-default (fixed in 6.4.0-150600.23.7.3)
  • kernel-default-base (fixed in 6.4.0-150600.23.7.3.150600.12.2.7)
  • kernel-docs (fixed in 6.4.0-150600.23.7.4)
  • kernel-kvmsmall (fixed in 6.4.0-150600.23.7.3)
  • kernel-livepatch-sle15-sp6-update-1 (fixed in 1-150600.13.3.7)
  • kernel-obs-build (fixed in 6.4.0-150600.23.7.3)
  • kernel-obs-qa (fixed in 6.4.0-150600.23.7.1)
  • kernel-source (fixed in 6.4.0-150600.23.7.2)
  • kernel-syms (fixed in 6.4.0-150600.23.7.1)
  • kernel-zfcpdump (fixed in 6.4.0-150600.23.7.3)

Timeline and source

Published on 25 June 2024 and last revised on 2 May 2025. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-06-25
Updated 2026-08-20
Modified 2025-05-02
Fix URL N/A

Affected Packages

Software From version Fixed in
dtb-aarch64 6.4.0-150600.23.7.1
kernel-64kb 6.4.0-150600.23.7.3
kernel-debug 6.4.0-150600.23.7.3
kernel-default 6.4.0-150600.23.7.3
kernel-default-base 6.4.0-150600.23.7.3.150600.12.2.7
kernel-docs 6.4.0-150600.23.7.4
kernel-kvmsmall 6.4.0-150600.23.7.3
kernel-livepatch-sle15-sp6-update-1 1-150600.13.3.7
kernel-obs-build 6.4.0-150600.23.7.3
kernel-obs-qa 6.4.0-150600.23.7.1
kernel-source 6.4.0-150600.23.7.2
kernel-syms 6.4.0-150600.23.7.1
kernel-zfcpdump 6.4.0-150600.23.7.3

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:2203-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:2203-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024