File _patchinfo of Package patchinfo.38518

<patchinfo incident="38518">
  <issue id="1233677" tracker="bnc">VUL-0: CVE-2024-53082: kernel live patch: virtio_net: Add hash_key_length check</issue>
  <issue id="1235008" tracker="bnc">VUL-0: CVE-2024-53237: kernel live patch: Bluetooth: fix use-after-free in device_for_each_child()</issue>
  <issue id="1235431" tracker="bnc">VUL-0: CVE-2024-56650: kernel live patch: netfilter: x_tables: fix LED ID check in led_tg_check()</issue>
  <issue id="1240840" tracker="bnc">VUL-0: CVE-2024-8805: kernel live patch: BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability</issue>
  <issue id="2024-53082" tracker="cve" />
  <issue id="2024-53237" tracker="cve" />
  <issue id="2024-56650" tracker="cve" />
  <issue id="2024-8805" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>nstange</packager>
  <description>This update for the Linux Kernel 6.4.0-150600_23_17 fixes several issues.

The following security issues were fixed:

- CVE-2024-53237: Bluetooth: fix use-after-free in device_for_each_child() (bsc#1235008).
- CVE-2024-53082: virtio_net: Add hash_key_length check (bsc#1233677).
- CVE-2024-8805: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE (bsc#1240840).
- CVE-2024-56650: netfilter: x_tables: fix LED ID check in led_tg_check() (bsc#1235431).
</description>
<summary>Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP6)</summary>
</patchinfo>
openSUSE Build Service is sponsored by