The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security
and bugfixes.
The following security bugs were fixed:
* CVE-2023-31085: Fixed a divide-by-zero error in do_div(sz,mtd->erasesize)
that could cause a local DoS. (bsc#1210778)
* CVE-2023-45862: Fixed an issue in the ENE UB6250 reader driver whwere an
object could potentially extend beyond the end of an allocation causing.
(bsc#1216051)
* CVE-2023-2163: Fixed an incorrect verifier pruning in BPF that could lead to
unsafe code paths being incorrectly marked as safe, resulting in arbitrary
read/write in kernel memory, lateral privilege escalation, and container
escape. (bsc#1215518)
* CVE-2023-3777: Fixed a use-after-free vulnerability in netfilter: nf_tables
component can be exploited to achieve local privilege escalation.
(bsc#1215095)
* CVE-2023-34324: Fixed a possible deadlock in Linux kernel event handling.
(bsc#1215745).
* CVE-2023-39189: Fixed a flaw in...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.3
zypper in -t patch SUSE-2023-4348=1
* openSUSE Leap 15.4
zypper in -t patch openSUSE-SLE-15.4-2023-4348=1
* SUSE Linux Enterprise Live Patching 15-SP3
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2023-4348=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP3
zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2023-4348=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4348=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3
zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4348=1
* SUSE Linux Enterprise Server 15 SP3 LTSS...
Read the Full Advisory* openSUSE Leap 15.3 (noarch nosrc)
* kernel-docs-5.3.18-150300.59.141.2
* openSUSE Leap 15.3 (noarch)
* kernel-devel-5.3.18-150300.59.141.1
* kernel-source-vanilla-5.3.18-150300.59.141.1
* kernel-source-5.3.18-150300.59.141.1
* kernel-macros-5.3.18-150300.59.141.1
* kernel-docs-html-5.3.18-150300.59.141.2
* openSUSE Leap 15.3 (nosrc ppc64le x86_64)
* kernel-debug-5.3.18-150300.59.141.2
* kernel-kvmsmall-5.3.18-150300.59.141.2
* openSUSE Leap 15.3 (ppc64le x86_64)
* kernel-kvmsmall-devel-debuginfo-5.3.18-150300.59.141.2
* kernel-debug-devel-debuginfo-5.3.18-150300.59.141.2
* kernel-debug-devel-5.3.18-150300.59.141.2
* kernel-debug-debuginfo-5.3.18-150300.59.141.2
* kernel-debug-livepatch-devel-5.3.18-150300.59.141.2
* kernel-kvmsmall-debuginfo-5.3.18-150300.59.141.2
* kernel-kvmsmall-devel-5.3.18-150300.59.141.2
* kernel-debug-debugsource-5.3.18-150300.59.141.2
* kernel-kvmsmall-livepatch-devel-5.3.18-150300.59.141.2
* kernel-kvmsmall-debugsource-5.3.18-150300.59.141.2
* openSUSE Leap 15.3 (aarch64 ppc64le...
Read the Full Advisory* bsc#1210778
* bsc#1210853
* bsc#1212051
* bsc#1214842
* bsc#1215095
* bsc#1215467
* bsc#1215518
* bsc#1215745
* bsc#1215858
* bsc#1215860
* bsc#1215861
* bsc#1216046
* bsc#1216051
* bsc#1216134
## References:
* https://www.suse.com/security/cve/CVE-2023-2163.html
* https://www.suse.com/security/cve/CVE-2023-31085.html
* https://www.suse.com/security/cve/CVE-2023-3111.html
* https://www.suse.com/security/cve/CVE-2023-34324.html
* https://www.suse.com/security/cve/CVE-2023-3777.html
* https://www.suse.com/security/cve/CVE-2023-39189.html
* https://www.suse.com/security/cve/CVE-2023-39192.html
* https://www.suse.com/security/cve/CVE-2023-39193.html
* https://www.suse.com/security/cve/CVE-2023-39194.html
* https://www.suse.com/security/cve/CVE-2023-42754.html
* https://www.suse.com/security/cve/CVE-2023-45862.html
* https://bugzilla.suse.com/show_bug.cgi?id=1210778
* https://bugzilla.suse.com/show_bug.cgi?id=1210853
* https://bugzilla.suse.com/show_bug.cgi?id=1212051
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.