Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15.4: Security Advisory SUSE-SU-2023:4731-1 Critical Threat

opensuse
Calendar Grey December 12, 2023
Dist Opensuse Esm H88
To secure your system, make sure to implement critical patches for the SUSE Linux Kernel, addressing serious vulnerabilities such as privilege escalation and denial of service threats.
The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security and bugfixes

Description

The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various

security and bugfixes.

The following security bugs were fixed:

* CVE-2023-6176: Fixed a denial of service in the cryptographic algorithm

scatterwalk functionality (bsc#1217332).

* CVE-2023-2006: Fixed a race condition in the RxRPC network protocol

(bsc#1210447).

* CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet()

(bsc#1216976).

* CVE-2023-4244: Fixed a use-after-free in the nf_tables component, which

could be exploited to achieve local privilege escalation (bsc#1215420).

* CVE-2023-6039: Fixed a use-after-free in lan78xx_disconnect in

drivers/net/usb/lan78xx.c (bsc#1217068).

* CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path()

(bsc#1216058).

* CVE-2023-5158: Fixed a denial of service in vringh_kiov_advance() in

drivers/vhost/vringh.c in the host side of a virtio ring (bsc#1215710).

* CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap Micro 5.3

zypper in -t patch openSUSE-Leap-Micro-5.3-2023-4731=1

* openSUSE Leap Micro 5.4

zypper in -t patch openSUSE-Leap-Micro-5.4-2023-4731=1

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-4731=1

* SUSE Linux Enterprise Micro for Rancher 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-4731=1

* SUSE Linux Enterprise Micro 5.3

zypper in -t patch SUSE-SLE-Micro-5.3-2023-4731=1

* SUSE Linux Enterprise Micro for Rancher 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-4731=1

* SUSE Linux Enterprise Micro 5.4

zypper in -t patch SUSE-SLE-Micro-5.4-2023-4731=1

* SUSE Linux Enterprise Live Patching 15-SP4

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-4731=1

* SUSE Real Time Module 15-SP4

zypper in -t patch SUSE-SLE-Module-RT-15-SP4-2023-4731=1

Package List

* openSUSE Leap Micro 5.3 (nosrc x86_64)

* kernel-rt-5.14.21-150400.15.62.1

* openSUSE Leap Micro 5.3 (x86_64)

* kernel-rt-debuginfo-5.14.21-150400.15.62.1

* kernel-rt-debugsource-5.14.21-150400.15.62.1

* openSUSE Leap Micro 5.4 (nosrc x86_64)

* kernel-rt-5.14.21-150400.15.62.1

* openSUSE Leap Micro 5.4 (x86_64)

* kernel-rt-debuginfo-5.14.21-150400.15.62.1

* kernel-rt-debugsource-5.14.21-150400.15.62.1

* openSUSE Leap 15.4 (x86_64)

* cluster-md-kmp-rt-5.14.21-150400.15.62.1

* dlm-kmp-rt-debuginfo-5.14.21-150400.15.62.1

* kernel-rt-debuginfo-5.14.21-150400.15.62.1

* ocfs2-kmp-rt-5.14.21-150400.15.62.1

* kernel-rt_debug-debuginfo-5.14.21-150400.15.62.1

* kernel-rt-debugsource-5.14.21-150400.15.62.1

* kernel-syms-rt-5.14.21-150400.15.62.1

* kernel-rt_debug-devel-debuginfo-5.14.21-150400.15.62.1

* cluster-md-kmp-rt-debuginfo-5.14.21-150400.15.62.1

* gfs2-kmp-rt-5.14.21-150400.15.62.1

* kernel-rt_debug-debugsource-5.14.21-150400.15.62.1

* kernel-rt-devel-5.14.21-150400.15.62.1

*...

Read the Full Advisory

References

* bsc#1084909

* bsc#1189998

* bsc#1210447

* bsc#1214286

* bsc#1214976

* bsc#1215124

* bsc#1215292

* bsc#1215420

* bsc#1215458

* bsc#1215710

* bsc#1216058

* bsc#1216105

* bsc#1216259

* bsc#1216584

* bsc#1216693

* bsc#1216759

* bsc#1216761

* bsc#1216844

* bsc#1216861

* bsc#1216909

* bsc#1216959

* bsc#1216965

* bsc#1216976

* bsc#1217036

* bsc#1217068

* bsc#1217086

* bsc#1217124

* bsc#1217140

* bsc#1217195

* bsc#1217200

* bsc#1217205

* bsc#1217332

* bsc#1217366

* bsc#1217515

* bsc#1217598

* bsc#1217599

* bsc#1217609

* bsc#1217687

* bsc#1217731

* bsc#1217780

* jsc#PED-3184

* jsc#PED-5021

* jsc#PED-7237

## References:

* https://www.suse.com/security/cve/CVE-2023-2006.html

* https://www.suse.com/security/cve/CVE-2023-25775.html

* https://www.suse.com/security/cve/CVE-2023-39197.html

* https://www.suse.com/security/cve/CVE-2023-39198.html

* https://www.suse.com/security/cve/CVE-2023-4244.html

* https://www.suse.com/security/cve/CVE-2023-45863.html

* https://www.suse.com/security/cve/CVE-2023-45871.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4731-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here