🛡️ SUSE-SU-2024:3195-1 — kernel-livepatch-sle15-sp6-rt-update-2 (CVE-2024-41062 +392 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP6 RT kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2024-41062: Sync sock recv cb and release (bsc#1228576).
  • CVE-2023-52489: Fix race in accessing memory_section->usage (bsc#1221326).
  • CVE-2024-43821: Fix a possible null pointer dereference (bsc#1229315).
  • CVE-2024-43911: Fix NULL dereference at band check in starting tx ba session (bsc#1229827).
  • CVE-2024-42277: Avoid NULL deref in sprd_iommu_hw_en (bsc#1229409).
  • CVE-2024-43880: Put back removed metod in struct objagg_ops (bsc#1229481).
  • CVE-2024-43899: Fix null pointer deref in dcn20_resource.c (bsc#1229754).
  • CVE-2024-43882: Fixed ToCToU between perm check and set-uid/gid usage. (bsc#1229503)
  • CVE-2024-43866: Always drain health in shutdown callback (bsc#1229495).
  • CVE-2024-26812: Struct virqfd kABI workaround (bsc#1222808).
  • CVE-2024-27010: Fix mirred deadlock on device recursion (bsc#1223720).
  • CVE-2024-36881: Fix reset ptes when close() for wr-protected (bsc#1225718).
  • CVE-2024-42316: Fix div-by-zero in vmpressure_calc_level() (bsc#1229353).
  • CVE-2024-43855: Fix deadlock between mddev_suspend and flush bio (bsc#1229342).
  • CVE-2024-43864: Fix CT entry update leaks of modify header context (bsc#1229496).
  • CVE-2024-26631: Fix data-race in ipv6_mc_down / mld_ifc_work (bsc#1221630).
  • CVE-2024-42109: Unconditionally flush pending work before notifier (bsc#1228505).
  • CVE-2024-41084: Avoid null pointer dereference in region lookup (bsc#1228472).
  • CVE-2024-40905: Fix possible race in __fib6_drop_pcpu_from() (bsc#1227761)
  • CVE-2024-39489: Fix memleak in seg6_hmac_init_algo (bsc#1227623)
  • CVE-2024-36489: Fix missing memory barrier in tls_init (bsc#1226874)
  • CVE-2024-27079: Fix NULL domain on device release (bsc#1223742).
  • CVE-2024-41020: Fix fcntl/close race recovery compat path (bsc#1228427).
  • CVE-2024-35897: Discard table flag update with pending basechain deletion (bsc#1224510).
  • CVE-2024-27403: Restore const specifier in flow_offload_route_init() (bsc#1224415).
  • CVE-2024-27011: Fix memleak in map from abort path (bsc#1223803).
  • CVE-2024-26668: Reject configurations that cause integer overflow (bsc#1222335).
  • CVE-2024-26835: Set dormant flag on hook register failure (bsc#1222967).
  • CVE-2024-26808: Handle NETDEV_UNREGISTER for inet/ingress basechain (bsc#1222634).
  • CVE-2024-26809: Release elements in clone only from destroy path (bsc#1222633).
  • CVE-2023-52581: Fix memleak when more than 255 elements expired (bsc#1220877).
  • CVE-2024-43837: Fix updating attached freplace prog in prog_array map (bsc#1229297).
  • CVE-2024-35939: Fixed leak pages on dma_set_decrypted() failure (bsc#1224535).
  • CVE-2024-42291: Add a per-VF limit on number of FDIR filters (bsc#1229374).
  • CVE-2024-42268: Fix missing lock on sync reset reload (bsc#1229391).
  • CVE-2024-43834: Fix invalid wait context of page_pool_destroy() (bsc#1229314)
  • CVE-2024-27433: Fix an error handling path in clk_mt8135_apmixed_probe() (bsc#1224711).
  • CVE-2024-36286: Acquire rcu_read_lock() in instance_destroy_rcu() (bsc#1226801)
  • CVE-2024-26851: Add protection for bmp length out of range (bsc#1223074)
  • CVE-2024-40920: Fix suspicious rcu usage in br_mst_set_state (bsc#1227781).
  • CVE-2024-40921: Pass vlan group directly to br_mst_vlan_set_state (bsc#1227784).
  • CVE-2024-36979: Fix vlan use-after-free (bsc#1226604).
  • CVE-2024-26590: Fix inconsistent per-file compression format (bsc#1220252).
  • CVE-2023-52859: Fix use-after-free when register pmu fails (bsc#1225582).
  • CVE-2024-42270: Fix null-ptr-deref in iptable_nat_table_init() (bsc#1229404).
  • CVE-2024-42269: Fix potential null-ptr-deref in ip6table_nat_table_init() (bsc#1229402).
  • CVE-2024-42284: Return non-zero value from tipc_udp_addr2str() on error (bsc#1229382)
  • CVE-2024-42283: Initialize all fields in dumped nexthops (bsc#1229383)
  • CVE-2024-42312: Always initialize i_uid/i_gid (bsc#1229357)
  • CVE-2024-43854: Initialize integrity buffer to zero before writing it to media (bsc#1229345)
  • CVE-2024-42322: Properly dereference pe in ip_vs_add_service (bsc#1229347)
  • CVE-2024-42290: Handle runtime power management correctly (bsc#1229379).
  • CVE-2024-42318: Do not lose track of restrictions on cred_transfer (bsc#1229351).
  • CVE-2023-52889: Fix null pointer deref when receiving skb during sock creation (bsc#1229287).
  • CVE-2024-42295: Handle inconsistent state in nilfs_btnode_create_block() (bsc#1229370).
  • CVE-2024-43850: Fix refcount imbalance seen during bwmon_remove (bsc#1229316).
  • CVE-2024-43831: Handle invalid decoder vsi (bsc#1229309).
  • CVE-2024-43839: Adjust 'name' buf size of bna_tcb and bna_ccb structures (bsc#1229301).
  • CVE-2024-41007: Use signed arithmetic in tcp_rtx_probe0_timed_out() (bsc#1227863).
  • CVE-2024-42281: Fix a segment issue when downgrading gso_size (bsc#1229386).
  • CVE-2024-26669: Fix chain template offload (bsc#1222350).
  • CVE-2024-26677: Blacklist e7870cf13d20 (' Fix

Affected software

SUSE-SU-2024:3195-1 is recorded against 5 packages.

  • kernel-livepatch-sle15-sp6-rt-update-2 (fixed in 1-150600.1.3.2)
  • kernel-rt (fixed in 6.4.0-150600.10.8.3)
  • kernel-rt-debug (fixed in 6.4.0-150600.10.8.3)
  • kernel-source-rt (fixed in 6.4.0-150600.10.8.3)
  • kernel-syms-rt (fixed in 6.4.0-150600.10.8.1)

Timeline and source

Published on 10 September 2024 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-09-10
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-livepatch-sle15-sp6-rt-update-2 1-150600.1.3.2
kernel-rt 6.4.0-150600.10.8.3
kernel-rt-debug 6.4.0-150600.10.8.3
kernel-source-rt 6.4.0-150600.10.8.3
kernel-syms-rt 6.4.0-150600.10.8.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:3195-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:3195-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2024