SUSE-SU-2024:0975-1

Source
https://www.suse.com/support/update/announcement/2024/suse-su-20240975-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0975-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2024:0975-1
Related
Published
2024-03-22T11:01:39Z
Modified
2024-03-22T11:01:39Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2024-26600: Fixed NULL pointer dereference for SRP (bsc#1220340).
  • CVE-2021-47078: Fixed a bug by clearing all QP fields if creation failed (bsc#1220863)
  • CVE-2021-47076: Fixed a bug by returning CQE error if invalid lkey was supplied (bsc#1220860)
  • CVE-2023-52605: Fixed a NULL pointer dereference check (bsc#1221039)
  • CVE-2023-52597: Fixed a setting of fpc register in KVM (bsc#1221040).
  • CVE-2023-52574: Fixed a bug by hiding new member header_ops (bsc#1220870).
  • CVE-2023-52482: Fixed a bug by adding SRSO mitigation for Hygon processors (bsc#1220735).
  • CVE-2022-48627: Fixed a memory overlapping when deleting chars in the buffer (bsc#1220845).
  • CVE-2023-28746: Fixed Register File Data Sampling (bsc#1213456).
  • CVE-2021-47077: Fixed a NULL pointer dereference when in shost_data (bsc#1220861).
  • CVE-2023-35827: Fixed a use-after-free issue in ravbtxtimeout_work() (bsc#1212514).
  • CVE-2023-52532: Fixed a bug in TX CQE error handling (bsc#1220932).
  • CVE-2021-33200: Fixed a leakage of uninitialized bpf stack under speculation. (bsc#1186484)
  • CVE-2023-52530: Fixed a potential key use-after-free in wifi mac80211 (bsc#1220930).
  • CVE-2023-52531: Fixed a memory corruption issue in iwlwifi (bsc#1220931).
  • CVE-2023-52502: Fixed a race condition in nfcllcpsockget() and nfcllcpsockget_sn() (bsc#1220831).
  • CVE-2024-26585: Fixed race between tx work scheduling and socket close (bsc#1220187).
  • CVE-2023-52340: Fixed ICMPv6 “Packet Too Big” packets force a DoS of the Linux kernel by forcing 100% CPU (bsc#1219295).
  • CVE-2024-0607: Fixed 64-bit load issue in nftbyteordereval() (bsc#1218915).
  • CVE-2024-26622: Fixed UAF write bug in tomoyowritecontrol() (bsc#1220825).
  • CVE-2021-46921: Fixed ordering in queuedwritelock_slowpath (bsc#1220468).
  • CVE-2021-46932: Fixed missing work initialization before device registration (bsc#1220444)
  • CVE-2023-52451: Fixed access beyond end of drmem array (bsc#1220250).
  • CVE-2021-46953: Fixed a corruption in interrupt mappings on watchdow probe failure (bsc#1220599).
  • CVE-2023-52449: Fixed gluebi NULL pointer dereference caused by ftl notifier (bsc#1220238).
  • CVE-2023-52475: Fixed use-after-free in powermateconfigcomplete (bsc#1220649)
  • CVE-2023-52478: Fixed kernel crash on receiver USB disconnect (bsc#1220796)
  • CVE-2019-25162: Fixed a potential use after free (bsc#1220409).
  • CVE-2020-36784: Fixed reference leak when pmruntimeget_sync fails (bsc#1220570).
  • CVE-2021-47054: Fixed a bug to put child node before return (bsc#1220767).
  • CVE-2021-46924: Fixed fix memory leak in device probe and remove (bsc#1220459)
  • CVE-2021-46915: Fixed a bug to avoid possible divide error in nftlimitinit (bsc#1220436).
  • CVE-2021-46906: Fixed an info leak in hidsubmitctrl (bsc#1220421).
  • CVE-2023-52445: Fixed use after free on context disconnection (bsc#1220241).
  • CVE-2020-36777: Fixed a memory leak in dvbmediadevice_free (bsc#1220526).
  • CVE-2023-52443: Fixed crash when parsed profile name is empty (bsc#1220240).
  • CVE-2023-46343: Fixed a NULL pointer dereference in send_acknowledge() (CVE-2023-46343).
  • CVE-2021-46992: Fixed a bug to avoid overflows in nfthashbuckets (bsc#1220638).
  • CVE-2021-47013: Fixed a use after free in emacmactxbufsend (bsc#1220641).
  • CVE-2021-46991: Fixed a use-after-free in i40eclientsubtask (bsc#1220575).
  • CVE-2024-26595: Fixed NULL pointer dereference in error path (bsc#1220344).
  • CVE-2024-1151: Fixed unlimited number of recursions from action sets (bsc#1219835).
  • CVE-2023-52464: Fixed possible out-of-bounds string access (bsc#1220330)
  • CVE-2024-23849: Fixed array-index-out-of-bounds in rdscmsgrecv (bsc#1219127).

The following non-security bugs were fixed:

  • ASN.1: Fix check for strdup() success (git-fixes).
  • audit: fix possible soft lockup in _auditinode_child() (git-fixes).
  • Bluetooth: hcibcsp: do not call kfreeskb() under spinlockirqsave() (git-fixes).
  • Bluetooth: hcih5: do not call kfreeskb() under spinlockirqsave() (git-fixes).
  • Bluetooth: hcill: do not call kfreeskb() under spinlockirqsave() (git-fixes).
  • Bluetooth: hciqca: do not call kfreeskb() under spinlockirqsave() (git-fixes).
  • bnx2x: Fix PF-VF communication over multi-cos queues (git-fixes).
  • doc/README.KSYMS: Add to repo.
  • e1000: fix memory leaks (git-fixes).
  • gve: Fix skb truesize underestimation (git-fixes).
  • igb: clean up in all error paths when enabling SR-IOV (git-fixes).
  • igb: Fix constant media auto sense switching when no cable is connected (git-fixes).
  • ipv6: Fix handling of LLA with VRF and sockets bound to VRF (git-fixes).
  • ipv6: fix typos in _ip6finish_output() (git-fixes).
  • ixgbe: protect TX timestamping from API misuse (git-fixes).
  • kcm: Call strpstop before strpdone in kcm_attach (git-fixes).
  • kcm: fix strp_init() order and cleanup (git-fixes).
  • KVM: s390: vsie: fix race during shadow creation (git-fixes bsc#1220613).
  • KVM: VMX: Move VERW closer to VMentry for MDS mitigation (git-fixes).
  • KVM: VMX: Use BT+JNC, i.e. EFLAGS.CF to select VMRESUME vs. VMLAUNCH (git-fixes).
  • KVM: x86: add support for CPUID leaf 0x80000021 (git-fixes).
  • KVM: x86: Move open-coded CPUID leaf 0x80000021 EAX bit propagation code (git-fixes).
  • KVM: x86: synthesize CPUID leaf 0x80000021h if useful (git-fixes).
  • KVM: x86: work around QEMU issue with synthetic CPUID leaves (git-fixes).
  • locking/barriers: Introduce smpcondloadrelaxed() and atomiccondreadrelaxed() (bsc#1220468 bsc#1050549).
  • md: bypass block throttle for superblock update (git-fixes).
  • media: coda: constify platformdeviceid (git-fixes).
  • media: coda: explicitly request exclusive reset control (git-fixes).
  • media: coda: reduce iram size to leave space for suspend to ram (git-fixes).
  • media: coda: reuse codasfmtvidcap to propagate format in codasfmtvidout (git-fixes).
  • media: coda: set minbuffersneeded (git-fixes).
  • media: coda: wake up capture queue on encoder stop after output streamoff (git-fixes).
  • media: dvb-usb: Add memory free on error path in dw2102_probe() (git-fixes).
  • media: dvb-usb: dw2102: fix uninit-value in su3000readmac_address (git-fixes).
  • media: dvb-usb: m920x: Fix a potential memory leak in m920xi2cxfer() (git-fixes).
  • media: dw2102: Fix memleak on sequence of probes (git-fixes).
  • media: dw2102: Fix use after free (git-fixes).
  • media: dw2102: make dvbusbdevice_description structures const (git-fixes).
  • media: m920x: do not use stack on USB reads (git-fixes).
  • media: rc: do not remove first bit if leader pulse is present (git-fixes).
  • media: rc: ir-rc6-decoder: enable toggle bit for Kathrein RCU-676 remote (git-fixes).
  • media: usb: dvd-usb: fix uninit-value bug in dibusbreadeeprom_byte() (git-fixes).
  • media: uvcvideo: Set capability in s_param (git-fixes).
  • net: bonding: debug: avoid printing debug logs when bond is not notifying peers (git-fixes).
  • net: fec: add missed clkdisableunprepare in remove (git-fixes).
  • net: fec: Better handle pmruntimeget() failing in .remove() (git-fixes).
  • net: fec: fix clock count mis-match (git-fixes).
  • net: fec: fix use-after-free in fecdrvremove (git-fixes).
  • net: hisilicon: Fix dmamapsingle failed on arm64 (git-fixes).
  • net: hisilicon: fix hip04-xmit never return TX_BUSY (git-fixes).
  • net: hisilicon: Fix usage of uninitialized variable in function mdiosccfgregwrite() (git-fixes).
  • net: hisilicon: make hip04txreclaim non-reentrant (git-fixes).
  • net: hns3: add compatible handling for MAC VLAN switch parameter configuration (git-fixes).
  • net: hns3: not allow SSU loopback while execute ethtool -t dev (git-fixes).
  • net: lpc-enet: fix printk format strings (git-fixes).
  • net: nfc: llcp: Add lock when modifying device list (git-fixes).
  • net: phy: dp83867: enable robust auto-mdix (git-fixes).
  • net: phy: initialise phydev speed and duplex sanely (git-fixes).
  • net: sfp: add mutex to prevent concurrent state checks (git-fixes).
  • net: tundra: tsi108: use spinlockirqsave instead of spinlockirq in IRQ context (git-fixes).
  • net: usb: dm9601: fix wrong return value in dm9601mdioread (git-fixes).
  • net/mlx5e: ethtool, Avoid setting speed to 56GBASE when autoneg off (git-fixes).
  • net/sched: tcindex: search key must be 16 bits (git-fixes).
  • nfsd: Do not refuse to serve out of cache (bsc#1220957).
  • PCI: Prevent xHCI driver from claiming AMD VanGogh USB3 DRD device (git-fixes).
  • s390: use the correct count for _iowrite64copy() (git-fixes bsc#1220607).
  • stmmac: fix potential division by 0 (git-fixes).
  • tcp: fix tcpmtupprobesuccess vs wrong sndcwnd (bsc#1218450).
  • usb: host: fotg210: fix the actual_length of an iso packet (git-fixes).
  • usb: host: fotg210: fix the endpoint's transactional opportunities calculation (git-fixes).
  • usb: hub: check for alternate port before enabling AALTHNP_SUPPORT (bsc#1218527).
  • usb: musb: dsps: Fix the probe error path (git-fixes).
  • usb: musb: musbdsps: requestirq() after initializing musb (git-fixes).
  • usb: musb: tusb6010: check return value after calling platformgetresource() (git-fixes).
  • usb: typec: tcpci: clear the fault status bit (git-fixes).
  • wcn36xx: Fix (QoS) null data frame bitrate/modulation (git-fixes).
  • wcn36xx: Fix discarded frames due to wrong sequence number (git-fixes).
  • wcn36xx: fix RX BD rate mapping for 5GHz legacy rates (git-fixes).
  • x86/asm: Add ASMRIP() macro for x86-64 (%rip) suffix (git-fixes).
  • x86/bugs: Add asm helpers for executing VERW (bsc#1213456).
  • x86/bugs: Use ALTERNATIVE() instead of mdsuserclear static key (git-fixes). Also add mdsuserclear to kABI severity as it's used purely for mitigation so it's low risk.
  • x86/cpu, kvm: Move X86FEATURELFENCE_RDTSC to its native leaf (git-fixes).
  • x86/entry_32: Add VERW just before userspace transition (git-fixes).
  • x86/entry_64: Add VERW just before userspace transition (git-fixes).
References

Affected packages

SUSE:Linux Enterprise Server 12 SP5 / kernel-azure

Package

Name
kernel-azure
Purl
purl:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5 / kernel-source-azure

Package

Name
kernel-source-azure
Purl
purl:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP5 / kernel-syms-azure

Package

Name
kernel-syms-azure
Purl
purl:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / kernel-azure

Package

Name
kernel-azure
Purl
purl:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / kernel-source-azure

Package

Name
kernel-source-azure
Purl
purl:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP5 / kernel-syms-azure

Package

Name
kernel-syms-azure
Purl
purl:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-16.173.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "4.12.14-16.173.1",
            "kernel-azure-devel": "4.12.14-16.173.1",
            "kernel-devel-azure": "4.12.14-16.173.1",
            "kernel-syms-azure": "4.12.14-16.173.1",
            "kernel-azure-base": "4.12.14-16.173.1",
            "kernel-source-azure": "4.12.14-16.173.1"
        }
    ]
}