The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2022-40982: Fixed transient execution attack called "Gather Data
Sampling" (bsc#1206418).
* CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec
(bsc#1211738).
* CVE-2023-20569: Fixed side channel attack âInceptionâ or âRAS Poisoningâ
(bsc#1213287).
* CVE-2023-20593: Fixed a ZenBleed issue in "Zen 2" CPUs that could allow an
attacker to potentially access sensitive information (bsc#1213286).
* CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in
fs/hfsplus/super.c that could allow a local user to cause a denial of
service (bsc#1211867).
* CVE-2023-34319: Fixed buffer overrun triggered by unusual packet in
xen/netback (XSA-432) (bsc#1213546).
* CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder
that could allow a local...
Read the Full Advisory## Patch Instructions:
To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3392=1
* openSUSE Leap 15.5
zypper in -t patch openSUSE-SLE-15.5-2023-3392=1
* SUSE Linux Enterprise Live Patching 15-SP1
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2023-3392=1
* SUSE Linux Enterprise High Availability Extension 15 SP1
zypper in -t patch SUSE-SLE-Product-HA-15-SP1-2023-3392=1
* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-3392=1
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-3392=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP1
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-3392=1
* SUSE CaaS Platform 4.0
To install this update, use the SUSE...
Read the Full Advisory* openSUSE Leap 15.4 (nosrc)
* kernel-kvmsmall-4.12.14-150100.197.154.1
* kernel-default-4.12.14-150100.197.154.1
* kernel-debug-4.12.14-150100.197.154.1
* kernel-zfcpdump-4.12.14-150100.197.154.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-base-debuginfo-4.12.14-150100.197.154.1
* kernel-debug-base-4.12.14-150100.197.154.1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)
* kernel-vanilla-devel-4.12.14-150100.197.154.1
* kernel-vanilla-base-debuginfo-4.12.14-150100.197.154.1
* kernel-vanilla-debuginfo-4.12.14-150100.197.154.1
* kernel-vanilla-livepatch-devel-4.12.14-150100.197.154.1
* kernel-vanilla-debugsource-4.12.14-150100.197.154.1
* kernel-default-base-debuginfo-4.12.14-150100.197.154.1
* kernel-vanilla-devel-debuginfo-4.12.14-150100.197.154.1
* kernel-vanilla-base-4.12.14-150100.197.154.1
* openSUSE Leap 15.4 (x86_64)
* kernel-kvmsmall-base-debuginfo-4.12.14-150100.197.154.1
* kernel-kvmsmall-base-4.12.14-150100.197.154.1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 nosrc)
*...
Read the Full Advisory* #1206418
* #1207088
* #1210584
* #1211738
* #1211867
* #1212301
* #1212741
* #1212835
* #1213059
* #1213167
* #1213286
* #1213287
* #1213546
* #1213585
* #1213586
* #1213588
* #1213970
* #1214019
## References:
* https://www.suse.com/security/cve/CVE-2022-40982.html
* https://www.suse.com/security/cve/CVE-2023-0459.html
* https://www.suse.com/security/cve/CVE-2023-20569.html
* https://www.suse.com/security/cve/CVE-2023-20593.html
* https://www.suse.com/security/cve/CVE-2023-2985.html
* https://www.suse.com/security/cve/CVE-2023-34319.html
* https://www.suse.com/security/cve/CVE-2023-35001.html
* https://www.suse.com/security/cve/CVE-2023-3567.html
* https://www.suse.com/security/cve/CVE-2023-3609.html
* https://www.suse.com/security/cve/CVE-2023-3611.html
* https://www.suse.com/security/cve/CVE-2023-3776.html
* https://www.suse.com/security/cve/CVE-2023-4133.html
* https://www.suse.com/security/cve/CVE-2023-4194.html
* https://bugzilla.suse.com/show_bug.cgi?id=1206418
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.