rpm package
suse/kernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS
Vulnerabilities (2,843)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-39965 | Hig | 7.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 13, 2025 | In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this | |
| CVE-2023-53687 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk() when iterating clk When the best clk is searched, we iterate over all possible clk. If we find a better match, the previous one, if any, n | |
| CVE-2023-53683 | Hig | 7.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are n | |
| CVE-2023-53681 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: bcache: Fix __bch_btree_node_alloc to make the failure behavior consistent In some specific situations, the return value of __bch_btree_node_alloc may be NULL. This may lead to a potential NULL pointer derefere | |
| CVE-2023-53680 | Hig | 7.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calli | |
| CVE-2023-53679 | Hig | 8.3 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: mt7601u: fix an integer underflow Fix an integer underflow that leads to a null pointer dereference in 'mt7601u_rx_skb_from_seg()'. The variable 'dma_len' in the URB packet could be manipulated, which cou | |
| CVE-2023-53676 | Hig | 8.8 | < 5.14.21-150400.24.187.3.150400.24.96.3 | 5.14.21-150400.24.187.3.150400.24.96.3 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The function lio_target_nacl_info_show() uses sprintf() in a loop to print details for every iSCSI connection in a session without checkin | |
| CVE-2023-53675 | Hig | 8.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible desc_ptr out-of-bounds accesses Sanitize possible desc_ptr out-of-bounds accesses in ses_enclosure_data_process(). | |
| CVE-2023-53674 | Hig | 7.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: clk: Fix memory leak in devm_clk_notifier_register() devm_clk_notifier_register() allocates a devres resource for clk notifier but didn't register that to the device, so the notifier didn't get unregistered on | |
| CVE-2023-53673 | Hig | 8.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_disconnect, we do hci_conn_del even if disconnection failed. ISO, L2CAP and SCO connections refer to the hci_conn without hci_conn_ | |
| CVE-2023-53670 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix dev_pm_qos memleak Call dev_pm_qos_hide_latency_tolerance() in the error unwind patch to avoid following kmemleak:- blktests (master) # kmemleak-clear; ./check nvme/044; blktests (master) # kmem | |
| CVE-2023-53668 | Hig | 7.1 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix deadloop issue on reading trace_pipe Soft lockup occurs when reading file 'trace_pipe': watchdog: BUG: soft lockup - CPU#6 stuck for 22s! [cat:4488] [...] RIP: 0010:ring_buffer_empty_cpu | |
| CVE-2023-53667 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize Currently in cdc_ncm_check_tx_max(), if dwNtbOutMaxSize is lower than the calculated "min" value, but greater than zero, the logic sets tx_max to dwNtbO | |
| CVE-2023-53662 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} If the filename casefolding fails, we'll be leaking memory from the fscrypt_name struct, namely from the 'crypto_buf.name' member. Make sure | |
| CVE-2023-53659 | Hig | 7.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: iavf: Fix out-of-bounds when setting channels on remove If we set channels greater during iavf_remove(), and waiting reset done would be timeout, then returned with error but changed num_active_queues directly, | |
| CVE-2023-53658 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: bcm-qspi: return error if neither hif_mspi nor mspi is available If neither a "hif_mspi" nor "mspi" resource is present, the driver will just early exit in probe but still return success. Apart from not do | |
| CVE-2023-53651 | Hig | 7.8 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: Input: exc3000 - properly stop timer on shutdown We need to stop the timer on driver unbind or probe failures, otherwise we get UAF/Oops. | |
| CVE-2023-53650 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: lcd_mipid: Fix an error handling path in mipid_spi_probe() If 'mipid_detect()' fails, we must free 'md' to avoid a memory leak. | |
| CVE-2023-53648 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer smatch error: sound/pci/ac97/ac97_codec.c:2354 snd_ac97_mixer() error: we previously assumed 'rac97' could be null (see line 2072) remove redundant a | |
| CVE-2023-53644 | Med | 5.5 | < 5.14.21-150400.24.184.1.150400.24.94.2 | 5.14.21-150400.24.184.1.150400.24.94.2 | Oct 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: media: radio-shark: Add endpoint checks The syzbot fuzzer was able to provoke a WARNING from the radio-shark2 driver: ------------[ cut here ]------------ usb 1-1: BOGUS urb xfer, pipe 1 != type 3 WARNING: CPU |
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: xfrm: xfrm_alloc_spi shouldn't use 0 as SPI x->id.spi == 0 means "no SPI assigned", but since commit 94f39804d891 ("xfrm: Duplicate SPI Handling"), we now create states and add them to the byspi list with this
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: tty: serial: samsung_tty: Fix a memory leak in s3c24xx_serial_getclk() when iterating clk When the best clk is searched, we iterate over all possible clk. If we find a better match, the previous one, if any, n
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode() syzbot is hitting WARN_ON() in hfsplus_cat_{read,write}_inode(), for crafted filesystem image can contain bogus length. There conditions are n
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: bcache: Fix __bch_btree_node_alloc to make the failure behavior consistent In some specific situations, the return value of __bch_btree_node_alloc may be NULL. This may lead to a potential NULL pointer derefere
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL OPDESC() simply indexes into nfsd4_ops[] by the op's operation number, without range checking that value. It assumes callers are careful to avoid calli
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: wifi: mt7601u: fix an integer underflow Fix an integer underflow that leads to a null pointer dereference in 'mt7601u_rx_skb_from_seg()'. The variable 'dma_len' in the URB packet could be manipulated, which cou
- affected < 5.14.21-150400.24.187.3.150400.24.96.3fixed 5.14.21-150400.24.187.3.150400.24.96.3
In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() The function lio_target_nacl_info_show() uses sprintf() in a loop to print details for every iSCSI connection in a session without checkin
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: scsi: ses: Fix possible desc_ptr out-of-bounds accesses Sanitize possible desc_ptr out-of-bounds accesses in ses_enclosure_data_process().
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: clk: Fix memory leak in devm_clk_notifier_register() devm_clk_notifier_register() allocates a devres resource for clk notifier but didn't register that to the device, so the notifier didn't get unregistered on
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: call disconnect callback before deleting conn In hci_cs_disconnect, we do hci_conn_del even if disconnection failed. ISO, L2CAP and SCO connections refer to the hci_conn without hci_conn_
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: nvme-core: fix dev_pm_qos memleak Call dev_pm_qos_hide_latency_tolerance() in the error unwind patch to avoid following kmemleak:- blktests (master) # kmemleak-clear; ./check nvme/044; blktests (master) # kmem
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix deadloop issue on reading trace_pipe Soft lockup occurs when reading file 'trace_pipe': watchdog: BUG: soft lockup - CPU#6 stuck for 22s! [cat:4488] [...] RIP: 0010:ring_buffer_empty_cpu
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: net: cdc_ncm: Deal with too low values of dwNtbOutMaxSize Currently in cdc_ncm_check_tx_max(), if dwNtbOutMaxSize is lower than the calculated "min" value, but greater than zero, the logic sets tx_max to dwNtbO
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: ext4: fix memory leaks in ext4_fname_{setup_filename,prepare_lookup} If the filename casefolding fails, we'll be leaking memory from the fscrypt_name struct, namely from the 'crypto_buf.name' member. Make sure
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: iavf: Fix out-of-bounds when setting channels on remove If we set channels greater during iavf_remove(), and waiting reset done would be timeout, then returned with error but changed num_active_queues directly,
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: spi: bcm-qspi: return error if neither hif_mspi nor mspi is available If neither a "hif_mspi" nor "mspi" resource is present, the driver will just early exit in probe but still return success. Apart from not do
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: Input: exc3000 - properly stop timer on shutdown We need to stop the timer on driver unbind or probe failures, otherwise we get UAF/Oops.
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: fbdev: omapfb: lcd_mipid: Fix an error handling path in mipid_spi_probe() If 'mipid_detect()' fails, we must free 'md' to avoid a memory leak.
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer smatch error: sound/pci/ac97/ac97_codec.c:2354 snd_ac97_mixer() error: we previously assumed 'rac97' could be null (see line 2072) remove redundant a
- affected < 5.14.21-150400.24.184.1.150400.24.94.2fixed 5.14.21-150400.24.184.1.150400.24.94.2
In the Linux kernel, the following vulnerability has been resolved: media: radio-shark: Add endpoint checks The syzbot fuzzer was able to provoke a WARNING from the radio-shark2 driver: ------------[ cut here ]------------ usb 1-1: BOGUS urb xfer, pipe 1 != type 3 WARNING: CPU
Page 22 of 143