Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE 15 SP4: 2023:4072-1 Important Kernel Security Update

suse
Calendar Grey October 13, 2023
Dist Suse Esm H88
An essential update to the Linux kernel in SUSE resolves a number of significant security flaws. A system reboot is necessary for all machines.
* #1202845 * #1213808 * #1214928 * #1214940 * #1214941

Summary

## The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-4563: Fixed an use-after-free flaw in the nftables sub-component. This vulnerability could allow a local attacker to crash the system or lead to a kernel information leak problem. (bsc#1214727) * CVE-2023-39194: Fixed a flaw in the processing of state filters which could allow a local attackers to disclose sensitive information. (bsc#1215861) * CVE-2023-39193: Fixed a flaw in the processing of state filters which could allow a local attackers to disclose sensitive information. (bsc#1215860) * CVE-2023-39192: Fixed a flaw in the u32_match_it function which could allow a local attackers to disclose sensitive information. (bsc#1215858)

References

* #1202845

* #1213808

* #1214928

* #1214940

* #1214941

* #1214942

* #1214943

* #1214944

* #1214950

* #1214951

* #1214954

* #1214957

* #1214986

* #1214988

* #1214992

* #1214993

* #1215322

* #1215877

* #1215894

* #1215895

* #1215896

* #1215911

* #1215915

* #1215916

Cross-

* CVE-2023-1192

* CVE-2023-1206

* CVE-2023-1859

* CVE-2023-2177

* CVE-2023-39192

* CVE-2023-39193

* CVE-2023-39194

* CVE-2023-4155

* CVE-2023-42753

* CVE-2023-42754

* CVE-2023-4389

* CVE-2023-4563

* CVE-2023-4622

* CVE-2023-4623

* CVE-2023-4881

* CVE-2023-4921

* CVE-2023-5345

CVSS scores:

* CVE-2023-1192 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-1206 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-1206 ( NVD ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4072-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here