Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

openSUSE: 2023:3953-1 Moderate: Mdadm Bug Fix for Buffer Overflow

opensuse
Calendar Grey October 3, 2023
Scroller Opensuse
Patch released for mdadm resolving memory vulnerabilities and performance inefficiencies, enhancing overall system reliability.
This update for mdadm fixes the following issues: CVE-2023-28736: Fixed a buffer overflow (bsc#1214244)

Description

This update for mdadm fixes the following issues:

* CVE-2023-28736: Fixed a buffer overflow (bsc#1214244).

* CVE-2023-28938: Fixed uncontrolled resource consumption (bsc#1214245).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3953=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-3953=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-3953=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-3953=1

* Basesystem Module 15-SP4

zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3953=1

* SUSE Manager Proxy 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3953=1

* SUSE Manager Retail Branch Server 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-

Server-4.2-2023-3953=1

* SUSE Manager Server 4.2

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3953=1

* SUSE Linux Enterprise Micro 5.1

zypper in...

Read the Full Advisory

Package List

* SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* SUSE Manager Proxy 4.2 (x86_64)

* mdadm-4.1-150300.24.33.1

* mdadm-debugsource-4.1-150300.24.33.1

* mdadm-debuginfo-4.1-150300.24.33.1

* SUSE Manager Retail Branch Server 4.2 (x86_64)

*...

Read the Full Advisory

References

* #1214244

* #1214245

## References:

* https://www.suse.com/security/cve/CVE-2023-28736.html

* https://www.suse.com/security/cve/CVE-2023-28938.html

* https://bugzilla.suse.com/show_bug.cgi?id=1214244

* https://bugzilla.suse.com/show_bug.cgi?id=1214245

Announcement ID: SUSE-SU-2023:3953-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.