Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Debian 10 Buster: DLA-3512-1 Critical: Linux Kernel Security Update

debian lts
Calendar Grey August 2, 2023
Dist Debian Esm H88
Important Debian LTS notice DLA-3513-1 addresses several vulnerabilities in the Linux kernel to improve system security.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2023-2156

It was discovered that a flaw in the handling of the RPL protocol
may allow an unauthenticated remote attacker to cause a denial of
service if RPL is enabled (not by default in Debian).

CVE-2023-3390

A use-after-free flaw in the netfilter subsystem caused by
incorrect error path handling may result in denial of service or
privilege escalation.

CVE-2023-3610

A use-after-free flaw in the netfilter subsystem caused by
incorrect refcount handling on the table and chain destroy path
may result in denial of service or privilege escalation.

CVE-2023-20593

Tavis Ormandy discovered that under specific microarchitectural
circumstances, a vector register in AMD "Zen 2" CPUs may not be
written to 0 correctly. This flaw allows an attacker to leak
sensitive information across concurrent processes, hyper threads
and virtualized guests.

For details please refer to
and
.

This issue can also be mitigated by a microcode update through the

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux-5.10
Version: 5.10.179-3~deb10u1
CVE ID: CVE-2023-2156 CVE-2023-3390 CVE-2023-3610 CVE-2023-20593

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here