File _patchinfo of Package patchinfo.35773
<patchinfo incident="35773">
<issue id="1223683" tracker="bnc">VUL-0: CVE-2024-26923: kernel live patch: af_unix: fix garbage collector racing against connect()</issue>
<issue id="1224991" tracker="bnc">VUL-0: CVE-2023-52772: kernel live patch: af_unix: fix use-after-free in unix_stream_read_actor()</issue>
<issue id="1225013" tracker="bnc">VUL-0: CVE-2024-27398: kernel live patch: Bluetooth: fix use-after-free bugs caused by sco_sock_timeout</issue>
<issue id="1225099" tracker="bnc">VUL-0: CVE-2023-52846: kernel live patch: hsr: Prevent use after free in prp_create_tagged_frame()</issue>
<issue id="1225310" tracker="bnc">VUL-0: CVE-2024-35950: kernel live patch: drm/client: Fully protect modes[] with dev->mode_config.mutex</issue>
<issue id="1225313" tracker="bnc">VUL-0: CVE-2024-35817: kernel live patch: drm/amdgpu: amdgpu_ttm_gart_bind set gtt bound flag</issue>
<issue id="1225850" tracker="bnc">VUL-0: CVE-2024-36921: kernel live patch: wifi: iwlwifi: mvm: guard against invalid STA ID on removal</issue>
<issue id="2023-52772" tracker="cve" />
<issue id="2023-52846" tracker="cve" />
<issue id="2024-26923" tracker="cve" />
<issue id="2024-27398" tracker="cve" />
<issue id="2024-35817" tracker="cve" />
<issue id="2024-35950" tracker="cve" />
<issue id="2024-36921" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 6.4.0-150600_21 fixes several issues.
The following security issues were fixed:
- CVE-2023-52846: Prevent use after free in prp_create_tagged_frame() (bsc#1225099).
- CVE-2024-35817: Set gtt bound flag in amdgpu_ttm_gart_bind (bsc#1225313).
- CVE-2024-36921: Guard against invalid STA ID on removal. (bsc#1225769)
- CVE-2023-52772: Fixed use-after-free in unix_stream_read_actor() (bsc#1224991).
- CVE-2024-26923: Fixed false-positive lockdep splat for spin_lock() in __unix_gc() (bsc#1223683).
- CVE-2024-27398: Fixed use-after-free bugs caused by sco_sock_timeout (bsc#1225013).
- CVE-2024-35950: Fully protect modes with dev->mode_config.mutex (bsc#1225310).
</description>
<summary>Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP6)</summary>
</patchinfo>