The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2022-40982: Fixed transient execution attack called "Gather Data
Sampling" (bsc#1206418).
* CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec
(bsc#1211738).
* CVE-2023-20569: Fixed side channel attack âInceptionâ or âRAS Poisoningâ
(bsc#1213287).
* CVE-2023-21400: Fixed several memory corruptions due to improper locking in
io_uring (bsc#1213272).
* CVE-2023-2156: Fixed a flaw in the networking subsystem within the handling
of the RPL protocol (bsc#1211131).
* CVE-2023-2166: Fixed NULL pointer dereference in can_rcv_filter
(bsc#1210627).
* CVE-2023-31083: Fixed race condition in hci_uart_tty_ioctl (bsc#1210780).
* CVE-2023-3268: Fixed an out of bounds memory access flaw in
relay_file_read_start_pos in the relayfs (bsc#1212502).
* CVE-2023-3567: Fixed a use-after-free...
Read the Full Advisory## Patch Instructions:
To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2023-3311=1 SUSE-2023-3311=1
* Basesystem Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3311=1
* Development Tools Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-3311=1
* Legacy Module 15-SP5
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2023-3311=1
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2023-3311=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP5
zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2023-3311=1
* SUSE Linux Enterprise Workstation Extension 15...
Read the Full Advisory* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)
* dlm-kmp-default-5.14.21-150500.55.19.1
* kernel-obs-build-debugsource-5.14.21-150500.55.19.1
* kernel-default-optional-debuginfo-5.14.21-150500.55.19.1
* ocfs2-kmp-default-debuginfo-5.14.21-150500.55.19.1
* kernel-default-extra-debuginfo-5.14.21-150500.55.19.1
* kernel-default-livepatch-devel-5.14.21-150500.55.19.1
* dlm-kmp-default-debuginfo-5.14.21-150500.55.19.1
* reiserfs-kmp-default-debuginfo-5.14.21-150500.55.19.1
* kselftests-kmp-default-debuginfo-5.14.21-150500.55.19.1
* kernel-obs-build-5.14.21-150500.55.19.1
* ocfs2-kmp-default-5.14.21-150500.55.19.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.19.1
* kselftests-kmp-default-5.14.21-150500.55.19.1
* gfs2-kmp-default-5.14.21-150500.55.19.1
* kernel-default-livepatch-5.14.21-150500.55.19.1
* kernel-obs-qa-5.14.21-150500.55.19.1
* kernel-default-devel-5.14.21-150500.55.19.1
* reiserfs-kmp-default-5.14.21-150500.55.19.1
* kernel-syms-5.14.21-150500.55.19.1
*...
Read the Full Advisory* #1206418
* #1207129
* #1207948
* #1210627
* #1210780
* #1210825
* #1211131
* #1211738
* #1211811
* #1212445
* #1212502
* #1212604
* #1212766
* #1212901
* #1213167
* #1213272
* #1213287
* #1213304
* #1213417
* #1213578
* #1213585
* #1213586
* #1213588
* #1213601
* #1213620
* #1213632
* #1213653
* #1213713
* #1213715
* #1213747
* #1213756
* #1213759
* #1213777
* #1213810
* #1213812
* #1213856
* #1213857
* #1213863
* #1213867
* #1213870
* #1213871
* #1213872
## References:
* https://www.suse.com/security/cve/CVE-2022-40982.html
* https://www.suse.com/security/cve/CVE-2023-0459.html
* https://www.suse.com/security/cve/CVE-2023-20569.html
* https://www.suse.com/security/cve/CVE-2023-21400.html
* https://www.suse.com/security/cve/CVE-2023-2156.html
* https://www.suse.com/security/cve/CVE-2023-2166.html
* https://www.suse.com/security/cve/CVE-2023-31083.html
* https://www.suse.com/security/cve/CVE-2023-3268.html
* https://www.suse.com/security/cve/CVE-2023-3567.html
* https://www.suse.com/security/cve/CVE-2023-3609.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.