The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2023-2007: Fixed a flaw in the DPT I2O Controller driver that could
allow an attacker to escalate privileges and execute arbitrary code in the
context of the kernel (bsc#1210448).
* CVE-2023-20588: Fixed a division-by-zero error on some AMD processors that
can potentially return speculative data resulting in loss of confidentiality
(bsc#1213927).
* CVE-2023-34319: Fixed buffer overrun triggered by unusual packet in
xen/netback (XSA-432) (bsc#1213546).
* CVE-2023-3610: Fixed use-after-free vulnerability in nf_tables can be
exploited to achieve local privilege escalation (bsc#1213580).
* CVE-2023-37453: Fixed oversight in SuperSpeed initialization (bsc#1213123).
* CVE-2023-3772: Fixed a flaw in XFRM subsystem that may have allowed a
malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL
pointer leading to a...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2023-3969=1 openSUSE-SLE-15.4-2023-3969=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3969=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2023-3969=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3969=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2023-3969=1
* Basesystem Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3969=1
* Development Tools Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3969=1
* Legacy Module 15-SP4
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP4-2023-3969=1
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch...
Read the Full Advisory* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.88.1
* openSUSE Leap 15.4 (noarch)
* kernel-source-5.14.21-150400.24.88.1
* kernel-macros-5.14.21-150400.24.88.1
* kernel-docs-html-5.14.21-150400.24.88.1
* kernel-source-vanilla-5.14.21-150400.24.88.1
* kernel-devel-5.14.21-150400.24.88.1
* openSUSE Leap 15.4 (nosrc ppc64le x86_64)
* kernel-debug-5.14.21-150400.24.88.1
* openSUSE Leap 15.4 (ppc64le x86_64)
* kernel-debug-debugsource-5.14.21-150400.24.88.1
* kernel-debug-livepatch-devel-5.14.21-150400.24.88.1
* kernel-debug-debuginfo-5.14.21-150400.24.88.1
* kernel-debug-devel-debuginfo-5.14.21-150400.24.88.1
* kernel-debug-devel-5.14.21-150400.24.88.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-debugsource-5.14.21-150400.24.88.1
* kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.88.1
* kernel-default-base-5.14.21-150400.24.88.1.150400.24.40.1
* kernel-kvmsmall-livepatch-devel-5.14.21-150400.24.88.1
* kernel-kvmsmall-devel-5.14.21-150400.24.88.1
*...
Read the Full Advisory* #1023051
* #1120059
* #1177719
* #1188885
* #1193629
* #1194869
* #1205462
* #1208902
* #1208949
* #1209284
* #1209799
* #1210048
* #1210448
* #1212091
* #1212142
* #1212526
* #1212857
* #1212873
* #1213026
* #1213123
* #1213546
* #1213580
* #1213601
* #1213666
* #1213757
* #1213759
* #1213916
* #1213921
* #1213927
* #1213946
* #1213968
* #1213970
* #1213971
* #1214000
* #1214019
* #1214120
* #1214149
* #1214180
* #1214238
* #1214285
* #1214297
* #1214299
* #1214350
* #1214368
* #1214370
* #1214371
* #1214372
* #1214380
* #1214386
* #1214392
* #1214393
* #1214397
* #1214428
* #1214451
* #1214635
* #1214659
* #1214661
* #1214729
* #1214742
* #1214743
* #1214756
* #1215522
* #1215523
* #1215552
* #1215553
* PED-4579
* PED-4759
* PED-4927
* PED-4929
* PED-5738
* PED-6003
* PED-6004
## References:
* https://www.suse.com/security/cve/CVE-2023-2007.html
* https://www.suse.com/security/cve/CVE-2023-20588.html
* https://www.suse.com/security/cve/CVE-2023-34319.html
* https://www.suse.com/security/cve/CVE-2023-3610.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.