Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

SUSE 15 SP4 2023:4093-1 Important: Kernel Security Fixes and Threats

suse
Calendar Grey October 17, 2023
Dist Suse Esm H88
The latest patch enhances the Linux Kernel for SUSE by addressing several vulnerabilities, safeguarding against privilege escalation and Denial of Service (DoS) attacks.
* bsc#1202845 * bsc#1213808 * bsc#1214928 * bsc#1214940 * bsc#1214941

Summary

## The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-39194: Fixed an out of bounds read in the XFRM subsystem (bsc#1215861). * CVE-2023-39193: Fixed an out of bounds read in the xtables subsystem (bsc#1215860). * CVE-2023-39192: Fixed an out of bounds read in the netfilter (bsc#1215858). * CVE-2023-42754: Fixed a NULL pointer dereference in the IPv4 stack that could lead to denial of service (bsc#1215467). * CVE-2023-4389: Fixed a reference counting issue in the Btrfs filesystem that could be exploited in order to leak internal kernel information or crash the system (bsc#1214351). * CVE-2023-5345: fixed an use-after-free vulnerability in the fs/smb/client

References

* bsc#1202845

* bsc#1213808

* bsc#1214928

* bsc#1214940

* bsc#1214941

* bsc#1214942

* bsc#1214943

* bsc#1214944

* bsc#1214950

* bsc#1214951

* bsc#1214954

* bsc#1214957

* bsc#1214986

* bsc#1214988

* bsc#1214992

* bsc#1214993

* bsc#1215322

* bsc#1215877

* bsc#1215894

* bsc#1215895

* bsc#1215896

* bsc#1215911

* bsc#1215915

* bsc#1215916

Cross-

* CVE-2023-1192

* CVE-2023-1206

* CVE-2023-1859

* CVE-2023-2177

* CVE-2023-39192

* CVE-2023-39193

* CVE-2023-39194

* CVE-2023-4155

* CVE-2023-42753

* CVE-2023-42754

* CVE-2023-4389

* CVE-2023-4563

* CVE-2023-4622

* CVE-2023-4623

* CVE-2023-4881

* CVE-2023-4921

* CVE-2023-5345

CVSS scores:

* CVE-2023-1192 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-1206 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4093-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here