Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15 SP3: 2023:2859-1 Important: Kernel Memory Issues Fix

opensuse
Calendar Grey July 17, 2023
Dist Opensuse Esm H88
Essential kernel patches have been released for openSUSE, targeting numerous issues and improving system security.
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes

Description

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security

and bugfixes.

The following security bugs were fixed:

* CVE-2023-1077: Fixed a type confusion in pick_next_rt_entity(), that could

cause memory corruption (bsc#1208600).

* CVE-2023-1249: Fixed a use-after-free flaw in the core dump subsystem that

allowed a local user to crash the system (bsc#1209039).

* CVE-2023-2002: Fixed a flaw that allowed an attacker to unauthorized

execution of management commands, compromising the confidentiality,

integrity, and availability of Bluetooth communication (bsc#1210533).

* CVE-2023-3090: Fixed a heap out-of-bounds write in the ipvlan network driver

(bsc#1212842).

* CVE-2023-3141: Fixed a use-after-free flaw in r592_remove in

drivers/memstick/host/r592.c, that allowed local attackers to crash the

system at device disconnect (bsc#1212129).

* CVE-2023-3159: Fixed use-after-free issue in driver/firewire in

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation

methods like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Manager Server 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-2859=1

* SUSE Enterprise Storage 7.1

zypper in -t patch SUSE-Storage-7.1-2023-2859=1

* SUSE Linux Enterprise Micro 5.1

zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-2859=1

* SUSE Linux Enterprise Micro 5.2

zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-2859=1

* SUSE Linux Enterprise Micro for Rancher 5.2

zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-2859=1

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-2859=1

* SUSE Linux Enterprise Live Patching 15-SP3

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2023-2859=1

Please note that this is the initial kernel livepatch without fixes itself, this

package is later updated by separate standalone kernel livepatch updates.

* SUSE Linux...

Read the Full Advisory

Package List

* SUSE Manager Server 4.2 (nosrc ppc64le s390x x86_64)

* kernel-default-5.3.18-150300.59.127.1

* SUSE Manager Server 4.2 (ppc64le s390x x86_64)

* kernel-default-debuginfo-5.3.18-150300.59.127.1

* kernel-default-devel-debuginfo-5.3.18-150300.59.127.1

* kernel-default-devel-5.3.18-150300.59.127.1

* kernel-default-debugsource-5.3.18-150300.59.127.1

* kernel-default-base-5.3.18-150300.59.127.1.150300.18.74.1

* SUSE Manager Server 4.2 (noarch)

* kernel-macros-5.3.18-150300.59.127.1

* kernel-devel-5.3.18-150300.59.127.1

* SUSE Manager Server 4.2 (nosrc s390x)

* kernel-zfcpdump-5.3.18-150300.59.127.1

* SUSE Manager Server 4.2 (s390x)

* kernel-zfcpdump-debugsource-5.3.18-150300.59.127.1

* kernel-zfcpdump-debuginfo-5.3.18-150300.59.127.1

* SUSE Manager Server 4.2 (nosrc x86_64)

* kernel-preempt-5.3.18-150300.59.127.1

* SUSE Manager Server 4.2 (x86_64)

* kernel-preempt-debugsource-5.3.18-150300.59.127.1

* kernel-preempt-debuginfo-5.3.18-150300.59.127.1

* SUSE Enterprise Storage 7.1 (aarch64 nosrc)

*...

Read the Full Advisory

References

* #1160435

* #1172073

* #1187829

* #1191731

* #1199046

* #1200217

* #1205758

* #1208600

* #1209039

* #1209342

* #1210533

* #1210791

* #1211089

* #1211519

* #1211796

* #1212128

* #1212129

* #1212154

* #1212158

* #1212494

* #1212501

* #1212502

* #1212504

* #1212513

* #1212606

* #1212842

## References:

* https://www.suse.com/security/cve/CVE-2023-1077.html

* https://www.suse.com/security/cve/CVE-2023-1249.html

* https://www.suse.com/security/cve/CVE-2023-2002.html

* https://www.suse.com/security/cve/CVE-2023-3090.html

* https://www.suse.com/security/cve/CVE-2023-3141.html

* https://www.suse.com/security/cve/CVE-2023-3159.html

* https://www.suse.com/security/cve/CVE-2023-3161.html

* https://www.suse.com/security/cve/CVE-2023-3268.html

* https://www.suse.com/security/cve/CVE-2023-3358.html

* https://www.suse.com/security/cve/CVE-2023-35788.html

* https://www.suse.com/security/cve/CVE-2023-35823.html

* https://www.suse.com/security/cve/CVE-2023-35824.html

* https://www.suse.com/security/cve/CVE-2023-35828.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:2859-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here