The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in
fs/hfsplus/super.c that could allow a local user to cause a denial of
service (bsc#1211867).
* CVE-2023-3117: Fixed an use-after-free vulnerability in the netfilter
subsystem when processing named and anonymous sets in batch requests that
could allow a local user with CAP_NET_ADMIN capability to crash or
potentially escalate their privileges on the system (bsc#1213245).
* CVE-2023-3390: Fixed an use-after-free vulnerability in the netfilter
subsystem in net/netfilter/nf_tables_api.c that could allow a local attacker
with user access to cause a privilege escalation issue (bsc#1212846).
* CVE-2023-3812: Fixed an out-of-bounds memory access flaw in the TUN/TAP
device driver functionality that could allow a local user to crash or
...
Read the Full Advisory## Patch Instructions:
To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2023-3171=1 openSUSE-SLE-15.4-2023-3171=1
* openSUSE Leap Micro 5.3
zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3171=1
* openSUSE Leap Micro 5.4
zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3171=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3171=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3171=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3171=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3171=1
* Basesystem Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3171=1
* Development Tools Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3171=1
*...
Read the Full Advisory* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.74.1
* openSUSE Leap 15.4 (noarch)
* kernel-devel-5.14.21-150400.24.74.1
* kernel-source-vanilla-5.14.21-150400.24.74.1
* kernel-macros-5.14.21-150400.24.74.1
* kernel-docs-html-5.14.21-150400.24.74.1
* kernel-source-5.14.21-150400.24.74.1
* openSUSE Leap 15.4 (nosrc ppc64le x86_64)
* kernel-debug-5.14.21-150400.24.74.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-debugsource-5.14.21-150400.24.74.1
* kernel-debug-debuginfo-5.14.21-150400.24.74.1
* kernel-debug-livepatch-devel-5.14.21-150400.24.74.1
* kernel-debug-devel-5.14.21-150400.24.74.1
* kernel-debug-devel-debuginfo-5.14.21-150400.24.74.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-devel-5.14.21-150400.24.74.1
* kernel-default-base-5.14.21-150400.24.74.1.150400.24.33.3
* kernel-default-base-rebuild-5.14.21-150400.24.74.1.150400.24.33.3
* kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.74.1
* kernel-kvmsmall-livepatch-devel-5.14.21-150400.24.74.1
*...
Read the Full Advisory* #1150305
* #1193629
* #1194869
* #1207894
* #1208788
* #1210565
* #1210584
* #1210853
* #1211243
* #1211811
* #1211867
* #1212301
* #1212846
* #1212905
* #1213010
* #1213011
* #1213012
* #1213013
* #1213014
* #1213015
* #1213016
* #1213017
* #1213018
* #1213019
* #1213020
* #1213021
* #1213024
* #1213025
* #1213032
* #1213034
* #1213035
* #1213036
* #1213037
* #1213038
* #1213039
* #1213040
* #1213041
* #1213059
* #1213061
* #1213087
* #1213088
* #1213089
* #1213090
* #1213092
* #1213093
* #1213094
* #1213095
* #1213096
* #1213098
* #1213099
* #1213100
* #1213102
* #1213103
* #1213104
* #1213105
* #1213106
* #1213107
* #1213108
* #1213109
* #1213110
* #1213111
* #1213112
* #1213113
* #1213114
* #1213134
* #1213245
* #1213247
* #1213252
* #1213258
* #1213259
* #1213263
* #1213264
* #1213286
* #1213523
* #1213524
* #1213543
* #1213705
## References:
* https://www.suse.com/security/cve/CVE-2023-20593.html
* https://www.suse.com/security/cve/CVE-2023-2985.html
* https://www.suse.com/security/cve/CVE-2023-3117.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.