Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2024:2561-1 — kernel-default (CVE-2020-10135 +175 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2020-10135: Legacy pairing and secure-connections pairing authentication Bluetooth might have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access (bsc#1171988).
  • CVE-2021-47103: net: sock: preserve kabi for sock (bsc#1221010).
  • CVE-2021-47145: btrfs: do not BUG_ON in link_to_fixup_dir (bsc#1222005).
  • CVE-2021-47191: Fix out-of-bound read in resp_readcap16() (bsc#1222866).
  • CVE-2021-47201: iavf: free q_vectors before queues in iavf_disable_vf (bsc#1222792).
  • CVE-2021-47267: usb: fix various gadget panics on 10gbps cabling (bsc#1224993).
  • CVE-2021-47270: usb: fix various gadgets null ptr deref on 10gbps cabling (bsc#1224997).
  • CVE-2021-47275: bcache: avoid oversized read request in cache missing code path (bsc#1224965).
  • CVE-2021-47293: net/sched: act_skbmod: Skip non-Ethernet packets (bsc#1224978).
  • CVE-2021-47294: netrom: Decrease sock refcount when sock timers expire (bsc#1224977).
  • CVE-2021-47297: net: fix uninit-value in caif_seqpkt_sendmsg (bsc#1224976).
  • CVE-2021-47309: net: validate lwtstate->data before returning from skb_tunnel_info() (bsc#1224967).
  • CVE-2021-47328: blacklist.conf: bsc#1225047 CVE-2021-47328: breaks kABI Also, does not apply.
  • CVE-2021-47354: drm/sched: Avoid data corruptions (bsc#1225140)
  • CVE-2021-47372: net: macb: fix use after free on rmmod (bsc#1225184).
  • CVE-2021-47379: blk-cgroup: fix UAF by grabbing blkcg lock before destroying blkg pd (bsc#1225203).
  • CVE-2021-47407: KVM: x86: Handle SRCU initialization failure during page track init (bsc#1225306).
  • CVE-2021-47418: net_sched: fix NULL deref in fifo_set_limit() (bsc#1225337).
  • CVE-2021-47434: xhci: Fix commad ring abort, write all 64 bits to CRCR register (bsc#1225232).
  • CVE-2021-47438: net/mlx5e: nullify cq->dbg pointer in mlx5_debug_cq_remove() (bsc#1225229)
  • CVE-2021-47445: drm/msm: Fix null pointer dereference on pointer edp (bsc#1225261)
  • CVE-2021-47498: dm rq: do not queue request to blk-mq during DM suspend (bsc#1225357).
  • CVE-2021-47518: nfc: fix potential NULL pointer deref in nfc_genl_dump_ses_done (bsc#1225372).
  • CVE-2021-47520: can: pch_can: pch_can_rx_normal: fix use after free (bsc#1225431).
  • CVE-2021-47544: tcp: fix page frag corruption on page fault (bsc#1225463).
  • CVE-2021-47547: net: tulip: de4x5: fix the problem that the array 'lp->phy' may be out of bound (bsc#1225505).
  • CVE-2021-47566: Fix clearing user buffer by properly using clear_user() (bsc#1225514).
  • CVE-2021-47571: staging: rtl8192e: Fix use after free in _rtl92e_pci_disconnect() (bsc#1225518).
  • CVE-2021-47587: net: systemport: Add global locking for descriptor lifecycle (bsc#1226567).
  • CVE-2021-47602: mac80211: track only QoS data frames for admission control (bsc#1226554).
  • CVE-2021-47609: firmware: arm_scpi: Fix string overflow in SCPI genpd driver (bsc#1226562)
  • CVE-2022-48732: drm/nouveau: fix off by one in BIOS boundary checking (bsc#1226716)
  • CVE-2022-48733: btrfs: fix use-after-free after failure to create a snapshot (bsc#1226718).
  • CVE-2022-48740: selinux: fix double free of cond_list on error paths (bsc#1226699).
  • CVE-2022-48743: net: amd-xgbe: Fix skb data length underflow (bsc#1226705).
  • CVE-2022-48756: drm/msm/dsi: invalid parameter check in msm_dsi_phy_enable (bsc#1226698)
  • CVE-2022-48759: rpmsg: char: Fix race between the release of rpmsg_ctrldev and cdev (bsc#1226711).
  • CVE-2022-48761: usb: xhci-plat: fix crash when suspend if remote wake enable (bsc#1226701).
  • CVE-2022-48772: media: lgdt3306a: Add a check against null-pointer-def (bsc#1226976).
  • CVE-2023-24023: Bluetooth: Add more enc key size check (bsc#1218148).
  • CVE-2023-4244: Fixed a use-after-free in the nf_tables component, which could be exploited to achieve local privilege escalation (bsc#1215420).
  • CVE-2023-52507: Fixed possible shift-out-of-bounds in nfc/nci (bsc#1220833).
  • CVE-2023-52622: ext4: avoid online resizing failures due to oversized flex bg (bsc#1222080).
  • CVE-2023-52675: powerpc/imc-pmu: Add a null pointer check in update_events_in_group() (bsc#1224504).
  • CVE-2023-52683: ACPI: LPIT: Avoid u32 multiplication overflow (bsc#1224627).
  • CVE-2023-52693: ACPI: video: check for error while searching for backlight device parent (bsc#1224686).
  • CVE-2023-52737: btrfs: lock the inode in shared mode before starting fiemap (bsc#1225484).
  • CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225487).
  • CVE-2023-52753: drm/amd/display: Avoid NULL dereference of timing generator (bsc#1225478).
  • CVE-2023-52754: media: imon: fix access to invalid resource for the second interface (bsc#1225490).
  • CVE-2023-52757: Fixed potential deadlock when releasing mids (bsc#1225548).
  • CVE-2023-52762: virtio-blk: fix implicit overflow on virtio_max_dma_size (bsc#1225573).
  • CVE-2023-

Affected software

SUSE-SU-2024:2561-1 is recorded against 6 packages.

  • kernel-default (fixed in 4.12.14-122.222.1)
  • kernel-docs (fixed in 4.12.14-122.222.1)
  • kernel-obs-build (fixed in 4.12.14-122.222.1)
  • kernel-source (fixed in 4.12.14-122.222.1)
  • kernel-syms (fixed in 4.12.14-122.222.1)
  • kgraft-patch-sle12-sp5-update-58 (fixed in 1-8.3.1)

Timeline and source

Published on 18 July 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-07-18
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-default 4.12.14-122.222.1
kernel-docs 4.12.14-122.222.1
kernel-obs-build 4.12.14-122.222.1
kernel-source 4.12.14-122.222.1
kernel-syms 4.12.14-122.222.1
kgraft-patch-sle12-sp5-update-58 1-8.3.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:2561-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:2561-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.