🛡️ SUSE-SU-2025:20077-1 — kernel-livepatch-micro-6-0-rt-update-3 (CVE-2023-52610 +161 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise Micro 6.0 RT kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2023-52610: net/sched: act_ct: fix skb leak and crash on ooo frags (bsc#1221610).
  • CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225487).
  • CVE-2023-52916: media: aspeed: Fix memory overwrite if timing is 1600x900 (bsc#1230269).
  • CVE-2024-26640: tcp: add sanity checks to rx zerocopy (bsc#1221650).
  • CVE-2024-26759: mm/swap: fix race when skipping swapcache (bsc#1230340).
  • CVE-2024-26804: net: ip_tunnel: prevent perpetual headroom growth (bsc#1222629).
  • CVE-2024-38538: net: bridge: xmit: make sure we have at least eth header len bytes (bsc#1226606).
  • CVE-2024-38596: af_unix: Fix data races in unix_release_sock/unix_stream_sendmsg (bsc#1226846).
  • CVE-2024-40965: i2c: lpi2c: Avoid calling clk_get_rate during transfer (bsc#1227885).
  • CVE-2024-40973: media: mtk-vcodec: potential null pointer deference in SCP (bsc#1227890).
  • CVE-2024-40983: tipc: force a dst refcount before doing decryption (bsc#1227819).
  • CVE-2024-42154: tcp_metrics: validate source addr length (bsc#1228507).
  • CVE-2024-42243: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray (bsc#1229001).
  • CVE-2024-42252: closures: Change BUG_ON() to WARN_ON() (bsc#1229004).
  • CVE-2024-42265: protect the fetch of ->fd[fd] in do_dup2() from mispredictions (bsc#1229334).
  • CVE-2024-42294: block: fix deadlock between sd_remove & sd_release (bsc#1229371).
  • CVE-2024-42304: ext4: make sure the first directory block is not a hole (bsc#1229364).
  • CVE-2024-42305: ext4: check dot and dotdot of dx_root before making dir indexed (bsc#1229363).
  • CVE-2024-42306: udf: Avoid using corrupted block bitmap buffer (bsc#1229362).
  • CVE-2024-43828: ext4: fix infinite loop when replaying fast_commit (bsc#1229394).
  • CVE-2024-43832: s390/uv: Do not call folio_wait_writeback() without a folio reference (bsc#1229380).
  • CVE-2024-43845: udf: Fix bogus checksum computation in udf_rename() (bsc#1229389).
  • CVE-2024-43890: tracing: Fix overflow in get_free_elt() (bsc#1229764).
  • CVE-2024-43898: ext4: sanity check for NULL pointer after ext4_force_shutdown (bsc#1229753).
  • CVE-2024-43914: md/raid5: avoid BUG_ON() while continue reshape after reassembling (bsc#1229790).
  • CVE-2024-44935: sctp: Fix null-ptr-deref in reuseport_add_sock() (bsc#1229810).
  • CVE-2024-44944: netfilter: ctnetlink: use helper function to calculate expect ID (bsc#1229899).
  • CVE-2024-44946: kcm: Serialise kcm_sendmsg() for the same socket (bsc#1230015).
  • CVE-2024-44950: serial: sc16is7xx: fix invalid FIFO access with special register set (bsc#1230180).
  • CVE-2024-44951: serial: sc16is7xx: fix TX fifo corruption (bsc#1230181).
  • CVE-2024-44970: net/mlx5e: SHAMPO, Fix invalid WQ linked list unlink (bsc#1230209).
  • CVE-2024-44971: net: dsa: bcm_sf2: Fix a possible memory leak in bcm_sf2_mdio_register() (bsc#1230211).
  • CVE-2024-44984: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT (bsc#1230240).
  • CVE-2024-44985: ipv6: prevent possible UAF in ip6_xmit() (bsc#1230206).
  • CVE-2024-44987: ipv6: prevent UAF in ip6_send_skb() (bsc#1230185).
  • CVE-2024-44988: net: dsa: mv88e6xxx: Fix out-of-bound access (bsc#1230192).
  • CVE-2024-44989: bonding: fix xfrm real_dev null pointer dereference (bsc#1230193).
  • CVE-2024-44990: bonding: fix null pointer deref in bond_ipsec_offload_ok (bsc#1230194).
  • CVE-2024-44991: tcp: prevent concurrent execution of tcp_sk_exit_batch (bsc#1230195).
  • CVE-2024-44998: atm: idt77252: prevent use after free in dequeue_rx() (bsc#1230171).
  • CVE-2024-44999: gtp: pull network headers in gtp_dev_xmit() (bsc#1230233).
  • CVE-2024-45002: rtla/osnoise: Prevent NULL dereference in error handling (bsc#1230169).
  • CVE-2024-45003: Don't evict inode under the inode lru traversing context (bsc#1230245).
  • CVE-2024-45013: nvme: move stopping keep-alive into nvme_uninit_ctrl() (bsc#1230442).
  • CVE-2024-45017: net/mlx5: Fix IPsec RoCE MPV trace call (bsc#1230430).
  • CVE-2024-45018: netfilter: flowtable: initialise extack before use (bsc#1230431).
  • CVE-2024-45019: net/mlx5e: Take state lock during tx timeout reporter (bsc#1230432).
  • CVE-2024-45021: memcg_write_event_control(): fix a user-triggerable oops (bsc#1230434).
  • CVE-2024-45022: mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 (bsc#1230435).
  • CVE-2024-45023: md/raid1: Fix data corruption for degraded array with slow disk (bsc#1230455).
  • CVE-2024-45029: i2c: tegra: Do not mark ACPI devices as irq safe (bsc#1230451).
  • CVE-2024-45030: igb: cope with large MAX_SKB_FRAGS (bsc#1230457).
  • CVE-2024-46673: scsi: aacraid: Fix double-free on probe failure (bsc#1230506).
  • CVE-2024-46677: gtp: fix a potential NULL pointer dereference (bsc#1230549).
  • CVE-2024-46679: ethtool: check device is present when getting link settings (bsc#1230556).
  • CVE-2024-46686: smb/client: avoid derefer

Affected software

SUSE-SU-2025:20077-1 is recorded against 3 packages.

  • kernel-livepatch-micro-6-0-rt-update-3 (fixed in 1-1.2)
  • kernel-rt (fixed in 6.4.0-11.1)
  • kernel-source-rt (fixed in 6.4.0-11.1)

Timeline and source

Published on 3 February 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-03
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-livepatch-micro-6-0-rt-update-3 1-1.2
kernel-rt 6.4.0-11.1
kernel-source-rt 6.4.0-11.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20077-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20077-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025