Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2022-36402: Fixed an integer overflow vulnerability in vmwgfx driver in
that allowed a local attacker with a user account on the system to gain
privilege, causing a denial of service (bsc#1203517).
* CVE-2023-2007: Fixed a flaw in the DPT I2O Controller driver that could
allow an attacker to escalate privileges and execute arbitrary code in the
context of the kernel (bsc#1210448).
* CVE-2023-3772: Fixed a flaw in XFRM subsystem that may have allowed a
malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL
pointer leading to a possible kernel crash and denial of service
(bsc#1213666).
* CVE-2023-3863: Fixed a use-after-free flaw was found in nfc_llcp_find_local
that allowed a local user with special privileges to impact a kernel
information leak issue (bsc#1213601).
* CVE-2023-4128: Fixed a use-after-free flaw...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-3684=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2023-3684=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP3
zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2023-3684=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3684=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-3684=1
* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.4 (nosrc)
* dtb-aarch64-5.3.18-150300.59.133.1
* openSUSE Leap 15.4 (aarch64)
* dtb-zte-5.3.18-150300.59.133.1
* dtb-al-5.3.18-150300.59.133.1
* SUSE Linux Enterprise Live Patching 15-SP3 (nosrc)
* kernel-default-5.3.18-150300.59.133.1
* SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64)
* kernel-default-livepatch-5.3.18-150300.59.133.1
* kernel-default-debuginfo-5.3.18-150300.59.133.1
* kernel-default-debugsource-5.3.18-150300.59.133.1
* kernel-livepatch-5_3_18-150300_59_133-default-1-150300.7.3.1
* kernel-default-livepatch-devel-5.3.18-150300.59.133.1
* SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le
s390x x86_64)
* gfs2-kmp-default-5.3.18-150300.59.133.1
* cluster-md-kmp-default-debuginfo-5.3.18-150300.59.133.1
* dlm-kmp-default-debuginfo-5.3.18-150300.59.133.1
* cluster-md-kmp-default-5.3.18-150300.59.133.1
* ocfs2-kmp-default-5.3.18-150300.59.133.1
* kernel-default-debuginfo-5.3.18-150300.59.133.1
*...
Read the Full Advisory* #1023051
* #1203517
* #1210448
* #1213272
* #1213546
* #1213601
* #1213666
* #1213916
* #1213927
* #1213968
* #1213969
* #1213970
* #1213971
* #1214019
* #1214120
* #1214149
* #1214275
* #1214297
* #1214348
* #1214350
* #1214451
* PED-4579
* PED-5738
## References:
* https://www.suse.com/security/cve/CVE-2022-36402.html
* https://www.suse.com/security/cve/CVE-2023-2007.html
* https://www.suse.com/security/cve/CVE-2023-20588.html
* https://www.suse.com/security/cve/CVE-2023-21400.html
* https://www.suse.com/security/cve/CVE-2023-34319.html
* https://www.suse.com/security/cve/CVE-2023-3772.html
* https://www.suse.com/security/cve/CVE-2023-3863.html
* https://www.suse.com/security/cve/CVE-2023-4128.html
* https://www.suse.com/security/cve/CVE-2023-4132.html
* https://www.suse.com/security/cve/CVE-2023-4133.html
* https://www.suse.com/security/cve/CVE-2023-4134.html
* https://www.suse.com/security/cve/CVE-2023-4147.html
* https://www.suse.com/security/cve/CVE-2023-4194.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.