The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various
security and bugfixes.
The following security bugs were fixed:
* CVE-2023-2007: Fixed a flaw in the DPT I2O Controller driver that could
allow an attacker to escalate privileges and execute arbitrary code in the
context of the kernel (bsc#1210448).
* CVE-2023-20588: Fixed a division-by-zero error on some AMD processors that
can potentially return speculative data resulting in loss of confidentiality
(bsc#1213927).
* CVE-2023-34319: Fixed buffer overrun triggered by unusual packet in
xen/netback (XSA-432) (bsc#1213546).
* CVE-2023-3610: Fixed use-after-free vulnerability in nf_tables can be
exploited to achieve local privilege escalation (bsc#1213580).
* CVE-2023-37453: Fixed oversight in SuperSpeed initialization (bsc#1213123).
* CVE-2023-3772: Fixed a flaw in XFRM subsystem that may have allowed a
malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL
pointer leading to a...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3600=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3600=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3600=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3600=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3600=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-3600=1
* SUSE Real Time Module 15-SP4
zypper in -t patch SUSE-SLE-Module-RT-15-SP4-2023-3600=1
* openSUSE Leap 15.4 (x86_64)
* dlm-kmp-rt-debuginfo-5.14.21-150400.15.49.1
* kernel-rt_debug-debuginfo-5.14.21-150400.15.49.1
* kernel-rt-debugsource-5.14.21-150400.15.49.1
* kernel-rt-devel-debuginfo-5.14.21-150400.15.49.1
* kernel-syms-rt-5.14.21-150400.15.49.1
* kernel-rt-devel-5.14.21-150400.15.49.1
* kernel-rt-debuginfo-5.14.21-150400.15.49.1
* cluster-md-kmp-rt-5.14.21-150400.15.49.1
* kernel-rt_debug-devel-debuginfo-5.14.21-150400.15.49.1
* kernel-rt_debug-debugsource-5.14.21-150400.15.49.1
* kernel-rt_debug-devel-5.14.21-150400.15.49.1
* gfs2-kmp-rt-debuginfo-5.14.21-150400.15.49.1
* ocfs2-kmp-rt-5.14.21-150400.15.49.1
* cluster-md-kmp-rt-debuginfo-5.14.21-150400.15.49.1
* dlm-kmp-rt-5.14.21-150400.15.49.1
* ocfs2-kmp-rt-debuginfo-5.14.21-150400.15.49.1
* gfs2-kmp-rt-5.14.21-150400.15.49.1
* openSUSE Leap 15.4 (noarch)
* kernel-devel-rt-5.14.21-150400.15.49.1
* kernel-source-rt-5.14.21-150400.15.49.1
* openSUSE Leap 15.4 (nosrc x86_64)
* kernel-rt-5.14.21-150400.15.49.1
*...
Read the Full Advisory* #1023051
* #1120059
* #1177719
* #1188885
* #1193629
* #1194869
* #1205462
* #1208902
* #1208949
* #1209284
* #1209799
* #1210048
* #1210448
* #1212091
* #1212142
* #1212526
* #1212857
* #1212873
* #1213026
* #1213123
* #1213546
* #1213580
* #1213601
* #1213666
* #1213757
* #1213759
* #1213916
* #1213921
* #1213927
* #1213946
* #1213968
* #1213970
* #1213971
* #1214000
* #1214019
* #1214120
* #1214149
* #1214180
* #1214238
* #1214285
* #1214297
* #1214299
* #1214350
* #1214368
* #1214370
* #1214371
* #1214372
* #1214380
* #1214386
* #1214392
* #1214393
* #1214397
* #1214428
* #1214451
* #1214659
* #1214661
* #1214729
* #1214742
* #1214743
* #1214756
* PED-4579
* PED-4759
* PED-4927
* PED-4929
* PED-5738
* PED-6003
* PED-6004
## References:
* https://www.suse.com/security/cve/CVE-2023-2007.html
* https://www.suse.com/security/cve/CVE-2023-20588.html
* https://www.suse.com/security/cve/CVE-2023-34319.html
* https://www.suse.com/security/cve/CVE-2023-3610.html
* https://www.suse.com/security/cve/CVE-2023-37453.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.