🛡️ SUSE-SU-2025:20047-1 — kernel-livepatch-micro-6-0-rt-update-2 (CVE-2023-52489 +382 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise Micro 6.0 RT kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2023-52489: mm/sparsemem: fix race in accessing memory_section->usage (bsc#1221326).
  • CVE-2023-52581: netfilter: nf_tables: fix memleak when more than 255 elements expired (bsc#1220877).
  • CVE-2023-52859: perf: hisi: Fix use-after-free when register pmu fails (bsc#1225582).
  • CVE-2023-52889: apparmor: Fix null pointer deref when receiving skb during sock creation (bsc#1229287).
  • CVE-2024-26590: erofs: fix inconsistent per-file compression format (bsc#1220252).
  • CVE-2024-26631: ipv6: mcast: fix data-race in ipv6_mc_down / mld_ifc_work (bsc#1221630).
  • CVE-2024-26668: netfilter: nft_limit: reject configurations that cause integer overflow (bsc#1222335).
  • CVE-2024-26669: kABI fix for net/sched: flower: Fix chain template offload (bsc#1222350).
  • CVE-2024-26677: Blacklist e7870cf13d20 (" Fix delayed ACKs to not set the reference serial number") (bsc#1222387)
  • CVE-2024-26735: ipv6: sr: fix possible use-after-free and null-ptr-deref (bsc#1222372).
  • CVE-2024-26808: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain (bsc#1222634).
  • CVE-2024-26809: netfilter: nft_set_pipapo: release elements in clone only from destroy path (bsc#1222633).
  • CVE-2024-26812: kABI: vfio: struct virqfd kABI workaround (bsc#1222808).
  • CVE-2024-26835: netfilter: nf_tables: set dormant flag on hook register failure (bsc#1222967).
  • CVE-2024-26837: net: bridge: switchdev: race between creation of new group memberships and generation of the list of MDB events to replay (bsc#1222973).
  • CVE-2024-26851: netfilter: nf_conntrack_h323: Add protection for bmp length out of range (bsc#1223074)
  • CVE-2024-27010: net/sched: Fix mirred deadlock on device recursion (bsc#1223720).
  • CVE-2024-27011: netfilter: nf_tables: fix memleak in map from abort path (bsc#1223803).
  • CVE-2024-27024: net/rds: fix WARNING in rds_conn_connect_if_down (bsc#1223777).
  • CVE-2024-27079: iommu/vt-d: Fix NULL domain on device release (bsc#1223742).
  • CVE-2024-27403: kabi: restore const specifier in flow_offload_route_init() (bsc#1224415).
  • CVE-2024-27433: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() (bsc#1224711).
  • CVE-2024-27437: vfio/pci: Disable auto-enable of exclusive INTx IRQ (bsc#1222625).
  • CVE-2024-35897: netfilter: nf_tables: discard table flag update with pending basechain deletion (bsc#1224510).
  • CVE-2024-35939: Fixed leak pages on dma_set_decrypted() failure (bsc#1224535).
  • CVE-2024-35949: btrfs: make sure that WRITTEN is set on all metadata blocks (bsc#1224700).
  • CVE-2024-36286: netfilter: nfnetlink_queue: acquire rcu_read_lock() in instance_destroy_rcu() (bsc#1226801)
  • CVE-2024-36489: tls: fix missing memory barrier in tls_init (bsc#1226874)
  • CVE-2024-36881: mm/userfaultfd: Fix reset ptes when close() for wr-protected (bsc#1225718).
  • CVE-2024-36929: net: core: reject skb_copy(_expand) for fraglist GSO skbs (bsc#1225814).
  • CVE-2024-36933: net: nsh: Use correct mac_offset to unwind gso skb in nsh_gso_segment() (bsc#1225832).
  • CVE-2024-36979: net: bridge: mst: fix vlan use-after-free (bsc#1226604).
  • CVE-2024-38662: selftests/bpf: Cover verifier checks for mutating sockmap/sockhash (bsc#1226885).
  • CVE-2024-39489: ipv6: sr: fix memleak in seg6_hmac_init_algo (bsc#1227623)
  • CVE-2024-39506: liquidio: adjust a NULL pointer handling path in lio_vf_rep_copy_packet (bsc#1227729).
  • CVE-2024-40905: ipv6: fix possible race in __fib6_drop_pcpu_from() (bsc#1227761)
  • CVE-2024-40909: bpf: Fix a potential use-after-free in bpf_link_free() (bsc#1227798).
  • CVE-2024-40920: net: bridge: mst: fix suspicious rcu usage in br_mst_set_state (bsc#1227781).
  • CVE-2024-40921: net: bridge: mst: pass vlan group directly to br_mst_vlan_set_state (bsc#1227784).
  • CVE-2024-40938: landlock: fix d_parent walk (bsc#1227840).
  • CVE-2024-40939: net: wwan: iosm: Fix tainted pointer delete is case of region creation fail (bsc#1227799).
  • CVE-2024-40954: net: do not leave a dangling sk pointer, when socket creation fails (bsc#1227808)
  • CVE-2024-40956: dmaengine: idxd: Fix possible Use-After-Free in irq_process_work_list (bsc#1227810).
  • CVE-2024-40957: seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors (bsc#1227811).
  • CVE-2024-40958: netns: Make get_net_ns() handle zero refcount net (bsc#1227812).
  • CVE-2024-40959: xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() (bsc#1227884).
  • CVE-2024-40978: scsi: qedi: Fix crash while reading debugfs attribute (bsc#1227929).
  • CVE-2024-40989: KVM: arm64: Disassociate vcpus from redistributor region on teardown (bsc#1227823).
  • CVE-2024-40994: ptp: fix integer overflow in max_vclocks_store (bsc#1227829).
  • CVE-2024-40995: net/sched: act_api: fix possible infinite loop in tcf_idr_check_alloc() (bsc#1227830).
  • CVE-2024-41000: block/ioctl: prefe

Affected software

SUSE-SU-2025:20047-1 is recorded against 3 packages.

  • kernel-livepatch-micro-6-0-rt-update-2 (fixed in 1-1.1)
  • kernel-rt (fixed in 6.4.0-10.1)
  • kernel-source-rt (fixed in 6.4.0-10.1)

Timeline and source

Published on 3 February 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-03
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-livepatch-micro-6-0-rt-update-2 1-1.1
kernel-rt 6.4.0-10.1
kernel-source-rt 6.4.0-10.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20047-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20047-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025