Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2023-37453: Fixed oversight in SuperSpeed initialization (bsc#1213123).
* CVE-2023-4569: Fixed information leak in nft_set_catchall_flush in
net/netfilter/nf_tables_api.c (bsc#1214729).
* CVE-2023-4134: Fixed use-after-free in cyttsp4_watchdog_work()
(bsc#1213971).
* CVE-2023-20588: Fixed a division-by-zero error on some AMD processors that
can potentially return speculative data resulting in loss of confidentiality
(bsc#1213927).
* CVE-2023-4459: Fixed a NULL pointer dereference flaw in vmxnet3_rq_cleanup
that may have allowed a local attacker with normal user privilege to cause a
denial of service (bsc#1214451).
* CVE-2023-3863: Fixed a use-after-free flaw was found in nfc_llcp_find_local
that allowed a local user with special privileges to impact a kernel
information leak issue (bsc#1213601).
* CVE-2023-3772: Fixed a flaw in...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2023-3683=1 openSUSE-SLE-15.4-2023-3683=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3683=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3683=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3683=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3683=1
* Basesystem Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3683=1
* Development Tools Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3683=1
* Legacy Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP4-2023-3683=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.84.1
* openSUSE Leap 15.4 (noarch)
* kernel-source-5.14.21-150400.24.84.1
* kernel-macros-5.14.21-150400.24.84.1
* kernel-docs-html-5.14.21-150400.24.84.1
* kernel-devel-5.14.21-150400.24.84.1
* kernel-source-vanilla-5.14.21-150400.24.84.1
* openSUSE Leap 15.4 (nosrc ppc64le x86_64)
* kernel-debug-5.14.21-150400.24.84.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-livepatch-devel-5.14.21-150400.24.84.1
* kernel-debug-debuginfo-5.14.21-150400.24.84.1
* kernel-debug-devel-debuginfo-5.14.21-150400.24.84.1
* kernel-debug-devel-5.14.21-150400.24.84.1
* kernel-debug-debugsource-5.14.21-150400.24.84.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-default-base-5.14.21-150400.24.84.1.150400.24.37.1
* kernel-kvmsmall-debugsource-5.14.21-150400.24.84.1
* kernel-kvmsmall-livepatch-devel-5.14.21-150400.24.84.1
* kernel-default-base-rebuild-5.14.21-150400.24.84.1.150400.24.37.1
* kernel-kvmsmall-debuginfo-5.14.21-150400.24.84.1
*...
Read the Full Advisory* #1023051
* #1120059
* #1177719
* #1188885
* #1193629
* #1194869
* #1205462
* #1208902
* #1208949
* #1209284
* #1209799
* #1210048
* #1210448
* #1212091
* #1212142
* #1212526
* #1212857
* #1212873
* #1213026
* #1213123
* #1213546
* #1213580
* #1213601
* #1213666
* #1213757
* #1213759
* #1213916
* #1213921
* #1213927
* #1213946
* #1213968
* #1213970
* #1213971
* #1214000
* #1214019
* #1214120
* #1214149
* #1214180
* #1214238
* #1214285
* #1214297
* #1214299
* #1214350
* #1214368
* #1214370
* #1214371
* #1214372
* #1214380
* #1214386
* #1214392
* #1214393
* #1214397
* #1214428
* #1214451
* #1214659
* #1214661
* #1214729
* #1214742
* #1214743
* #1214756
* PED-4579
* PED-4759
* PED-4927
* PED-4929
* PED-5738
* PED-6003
* PED-6004
## References:
* https://www.suse.com/security/cve/CVE-2023-2007.html
* https://www.suse.com/security/cve/CVE-2023-20588.html
* https://www.suse.com/security/cve/CVE-2023-34319.html
* https://www.suse.com/security/cve/CVE-2023-3610.html
* https://www.suse.com/security/cve/CVE-2023-37453.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.