The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2022-40982: Fixed transient execution attack called "Gather Data
Sampling" (bsc#1206418).
* CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec
(bsc#1211738).
* CVE-2023-20569: Fixed side channel attack âInceptionâ or âRAS Poisoningâ
(bsc#1213287).
* CVE-2023-20593: Fixed a ZenBleed issue in "Zen 2" CPUs that could allow an
attacker to potentially access sensitive information (bsc#1213286).
* CVE-2023-2156: Fixed a flaw in the networking subsystem within the handling
of the RPL protocol (bsc#1211131).
* CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in
fs/hfsplus/super.c that could allow a local user to cause a denial of
service (bsc#1211867).
* CVE-2023-3117: Fixed an use-after-free vulnerability in the netfilter
subsystem when processing named and anonymous sets in...
Read the Full Advisory## Patch Instructions:
To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3391=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2023-3391=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP3
zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2023-3391=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3391=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3391=1
* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.4 (nosrc)
* dtb-aarch64-5.3.18-150300.59.130.1
* openSUSE Leap 15.4 (aarch64)
* dtb-al-5.3.18-150300.59.130.1
* dtb-zte-5.3.18-150300.59.130.1
* SUSE Linux Enterprise Live Patching 15-SP3 (nosrc)
* kernel-default-5.3.18-150300.59.130.1
* SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64)
* kernel-default-livepatch-5.3.18-150300.59.130.1
* kernel-default-debuginfo-5.3.18-150300.59.130.1
* kernel-default-debugsource-5.3.18-150300.59.130.1
* kernel-default-livepatch-devel-5.3.18-150300.59.130.1
* kernel-livepatch-5_3_18-150300_59_130-default-1-150300.7.3.1
* SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le
s390x x86_64)
* kernel-default-debuginfo-5.3.18-150300.59.130.1
* cluster-md-kmp-default-debuginfo-5.3.18-150300.59.130.1
* ocfs2-kmp-default-debuginfo-5.3.18-150300.59.130.1
* cluster-md-kmp-default-5.3.18-150300.59.130.1
* gfs2-kmp-default-5.3.18-150300.59.130.1
* gfs2-kmp-default-debuginfo-5.3.18-150300.59.130.1
*...
Read the Full Advisory* #1199304
* #1206418
* #1207270
* #1210584
* #1211131
* #1211738
* #1211867
* #1212301
* #1212741
* #1212835
* #1212846
* #1213059
* #1213061
* #1213167
* #1213245
* #1213286
* #1213287
* #1213354
* #1213543
* #1213585
* #1213586
* #1213588
* #1213653
* #1213868
* PED-4567
## References:
* https://www.suse.com/security/cve/CVE-2022-40982.html
* https://www.suse.com/security/cve/CVE-2023-0459.html
* https://www.suse.com/security/cve/CVE-2023-20569.html
* https://www.suse.com/security/cve/CVE-2023-20593.html
* https://www.suse.com/security/cve/CVE-2023-2156.html
* https://www.suse.com/security/cve/CVE-2023-2985.html
* https://www.suse.com/security/cve/CVE-2023-3117.html
* https://www.suse.com/security/cve/CVE-2023-31248.html
* https://www.suse.com/security/cve/CVE-2023-3390.html
* https://www.suse.com/security/cve/CVE-2023-35001.html
* https://www.suse.com/security/cve/CVE-2023-3567.html
* https://www.suse.com/security/cve/CVE-2023-3609.html
* https://www.suse.com/security/cve/CVE-2023-3611.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.