Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

openSUSE 15.4/15.5: 2023:3822-1 Moderate: Supportutils Security Fix

opensuse
Calendar Grey September 27, 2023
Scroller Opensuse
The latest supportutils revision addresses the security vulnerability CVE-2022-45154 categorized with moderate severity affecting openSUSE systems. Ensure you update immediately.
This update for supportutils fixes the following issues: Security fixes:

Description

This update for supportutils fixes the following issues:

Security fixes:

* CVE-2022-45154: Removed iSCSI passwords (bsc#1207598).

Other Fixes:

* Changes in version 3.1.26

* powerpc plugin to collect the slots and active memory (bsc#1210950)

* A Cleartext Storage of Sensitive Information vulnerability CVE-2022-45154

* supportconfig: collect BPF information (pr#154)

* Added additional iscsi information (pr#155)

* Added run time detection (bsc#1213127)

* Changes for supportutils version 3.1.25

* Removed iSCSI passwords CVE-2022-45154 (bsc#1207598)

* powerpc: Collect lsslot,amsstat, and opal elogs (pr#149)

* powerpc: collect invscout logs (pr#150)

* powerpc: collect RMC status logs (pr#151)

* Added missing nvme nbft commands (bsc#1211599)

* Fixed invalid nvme commands (bsc#1211598)

* Added missing podman information (PED-1703, bsc#1181477)

* Removed dependency on sysfstools

* Check for systool use (bsc#1210015)

* Added selinux checking (bsc#1209979)

* Updated...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-3822=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-3822=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3822=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3822=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-3822=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-3822=1

* Basesystem Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3822=1

* Basesystem Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3822=1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3

zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-3822=1

*...

Read the Full Advisory

Package List

* openSUSE Leap 15.4 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* openSUSE Leap 15.5 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Micro 5.3 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Micro 5.4 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* Basesystem Module 15-SP4 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* Basesystem Module 15-SP5 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch)

* supportutils-3.1.26-150300.7.35.21.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP3...

Read the Full Advisory

References

* #1181477

* #1196933

* #1204942

* #1205533

* #1206402

* #1206608

* #1207543

* #1207598

* #1208928

* #1209979

* #1210015

* #1210950

* #1211598

* #1211599

* #1213127

* PED-1703

## References:

* https://www.suse.com/security/cve/CVE-2022-45154.html

* https://bugzilla.suse.com/show_bug.cgi?id=1181477

* https://bugzilla.suse.com/show_bug.cgi?id=1196933

* https://bugzilla.suse.com/show_bug.cgi?id=1204942

* https://bugzilla.suse.com/show_bug.cgi?id=1205533

* https://bugzilla.suse.com/show_bug.cgi?id=1206402

* https://bugzilla.suse.com/show_bug.cgi?id=1206608

* https://bugzilla.suse.com/show_bug.cgi?id=1207543

* https://bugzilla.suse.com/show_bug.cgi?id=1207598

* https://bugzilla.suse.com/show_bug.cgi?id=1208928

* https://bugzilla.suse.com/show_bug.cgi?id=1209979

* https://bugzilla.suse.com/show_bug.cgi?id=1210015

* https://bugzilla.suse.com/show_bug.cgi?id=1210950

* https://bugzilla.suse.com/show_bug.cgi?id=1211598

* https://bugzilla.suse.com/show_bug.cgi?id=1211599

* https://bugzilla.suse.com/show_bug.cgi?id=1213127

*

Announcement ID: SUSE-SU-2023:3822-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.