<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE1-SA-2025-0002</id>
    <title>An update for kernel is now available for HCE 1.1</title>
    <severity>Important</severity>
    <release>HCE 1.1</release>
    <issued date="2025-03-21 03:30:25"/>
    <updated date="2025-03-21 03:30:25"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-50302" id="CVE-2024-50302" title="CVE-2024-50302 Base Score: 5.5 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-53197" id="CVE-2024-53197" title="CVE-2024-53197 Base Score: 5.8 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-53104" id="CVE-2024-53104" title="CVE-2024-53104 Base Score: 7.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

In the Linux kernel, the following vulnerability has been resolved:

HID: core: zero-initialize the report buffer

Since the report buffer is used by all kinds of drivers in various ways, let_x27;s
zero-initialize it during allocation to make sure that it can_x27;t be ever used
to leak kernel memory via specially-crafted report. (CVE-2024-50302)

In the Linux kernel, the following vulnerability has been resolved:

ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices

A bogus device can provide a bNumConfigurations value that exceeds the
initial value used in usb_get_configuration for allocating dev-&gt;config.

This can lead to out-of-bounds accesses later, e.g. in
usb_destroy_configuration. (CVE-2024-53197)

In the Linux kernel, the following vulnerability has been resolved:

media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format

This can lead to out of bounds writes since frames of this type were not
taken into account when calculating the size of the frames buffer in
uvc_parse_streaming. (CVE-2024-53104)
</description>
    <pkglist>
      <collection short="HCE 1.1" package="kernel">
        <name>HCE 1.1</name>
        <package arch="x86_64" name="bpftool" version="3.10.0" release="1160.122.2.hce1c">
          <filename>bpftool-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="kernel-abi-whitelists" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-abi-whitelists-3.10.0-1160.122.2.hce1c.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel-debug-devel" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-debug-devel-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel-devel" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-devel-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel-headers" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-headers-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel-tools" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-tools-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="kernel-tools-libs" version="3.10.0" release="1160.122.2.hce1c">
          <filename>kernel-tools-libs-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="perf" version="3.10.0" release="1160.122.2.hce1c">
          <filename>perf-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="python-perf" version="3.10.0" release="1160.122.2.hce1c">
          <filename>python-perf-3.10.0-1160.122.2.hce1c.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
