Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE Linux Enterprise 15 SP5: 2023:4035-1 Important: Kernel Security Fixes

suse
Calendar Grey October 10, 2023
Dist Suse Esm H88
Important patch released for the Linux kernel tackling several security flaws to improve overall system integrity. Restart necessary.
* #1152472 * #1202845 * #1206453 * #1213808 * #1214941

Summary

## The SUSE Linux Enterprise 15 SP5 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-39194: Fixed an out of bounds read in the XFRM subsystem (bsc#1215861). * CVE-2023-39193: Fixed an out of bounds read in the xtables subsystem (bsc#1215860). * CVE-2023-39192: Fixed an out of bounds read in the netfilter (bsc#1215858). * CVE-2023-42754: Fixed a NULL pointer dereference in the IPv4 stack that could lead to denial of service (bsc#1215467). * CVE-2023-4389: Fixed a reference counting issue in the Btrfs filesystem that could be exploited in order to leak internal kernel information or crash the system (bsc#1214351). * CVE-2023-5345: fixed an use-after-free vulnerability in the fs/smb/client

References

* #1152472

* #1202845

* #1206453

* #1213808

* #1214941

* #1214942

* #1214943

* #1214944

* #1214950

* #1214951

* #1214954

* #1214957

* #1214986

* #1214992

* #1214993

* #1215322

* #1215523

* #1215877

* #1215894

* #1215895

* #1215896

* #1215911

* #1215915

* #1215916

Cross-

* CVE-2023-1206

* CVE-2023-39192

* CVE-2023-39193

* CVE-2023-39194

* CVE-2023-4155

* CVE-2023-42753

* CVE-2023-42754

* CVE-2023-4389

* CVE-2023-4622

* CVE-2023-4623

* CVE-2023-4921

* CVE-2023-5345

CVSS scores:

* CVE-2023-1206 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-1206 ( NVD ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-39192 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H

* CVE-2023-39192 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4035-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here