# Security update for kernel-firmware

Announcement ID: SUSE-SU-2023:4665-1  
Rating: important  
References:

  * bsc#1215823
  * bsc#1215831

  
Cross-References:

  * CVE-2021-26345
  * CVE-2021-46766
  * CVE-2021-46774
  * CVE-2022-23820
  * CVE-2022-23830
  * CVE-2023-20519
  * CVE-2023-20521
  * CVE-2023-20526
  * CVE-2023-20533
  * CVE-2023-20566
  * CVE-2023-20592

  
CVSS scores:

  * CVE-2021-26345 ( SUSE ):  1.6 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
  * CVE-2021-26345 ( NVD ):  4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
  * CVE-2021-46766 ( SUSE ):  2.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
  * CVE-2021-46766 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  * CVE-2021-46774 ( SUSE ):  6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L
  * CVE-2021-46774 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-23820 ( SUSE ):  7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  * CVE-2022-23820 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-23830 ( SUSE ):  1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
  * CVE-2022-23830 ( NVD ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2023-20519 ( SUSE ):  6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
  * CVE-2023-20519 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
  * CVE-2023-20521 ( SUSE ):  3.3 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
  * CVE-2023-20521 ( NVD ):  5.7 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
  * CVE-2023-20526 ( SUSE ):  1.9 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
  * CVE-2023-20526 ( NVD ):  4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  * CVE-2023-20533 ( SUSE ):  6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H
  * CVE-2023-20533 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-20566 ( SUSE ):  5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
  * CVE-2023-20566 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  * CVE-2023-20592 ( SUSE ):  5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
  * CVE-2023-20592 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

  
Affected Products:

  * SUSE CaaS Platform 4.0
  * SUSE Linux Enterprise High Performance Computing 15 SP1
  * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
  * SUSE Linux Enterprise High Performance Computing 15 SP2
  * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
  * SUSE Linux Enterprise Server 15 SP1
  * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
  * SUSE Linux Enterprise Server 15 SP2
  * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
  * SUSE Linux Enterprise Server for SAP Applications 15 SP1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP2

  
  
An update that solves 11 vulnerabilities can now be installed.

## Description:

This update for kernel-firmware fixes the following issues:

Update AMD ucode to 20231030 (bsc#1215831):

  * CVE-2022-23820: Failure to validate the AMD SMM communication buffer may
    allow an attacker to corrupt the SMRAM potentially leading to arbitrary code
    execution.
  * CVE-2021-46774: Insufficient input validation in ABL may enable a privileged
    attacker to perform arbitrary DRAM writes, potentially resulting in code
    execution and privilege escalation.
  * CVE-2023-20533: Insufficient DRAM address validation in System Management
    Unit (SMU) may allow an attacker using DMA to read/write from/to invalid
    DRAM address potentially resulting in denial-of-service. 0 CVE-2023-20519: A
    Use-After-Free vulnerability in the management of an SNP guest context page
    may allow a malicious hypervisor to masquerade as the guest's migration
    agent resulting in a potential loss of guest integrity.
  * CVE-2023-20566: Improper address validation in ASP with SNP enabled may
    potentially allow an attacker to compromise guest memory integrity.
  * CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with
    physical access to tamper with SPI ROM records after memory content
    verification, potentially leading to loss of confidentiality or a denial of
    service.
  * CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader
    may expose secret keys to a privileged attacker accessing ASP SRAM,
    potentially leading to a loss of confidentiality.
  * CVE-2022-23830: SMM configuration may not be immutable, as intended, when
    SNP is enabled resulting in a potential limited loss of guest memory
    integrity.
  * CVE-2023-20526: Insufficient input validation in the ASP Bootloader may
    enable a privileged attacker with physical access to expose the contents of
    ASP memory potentially leading to a loss of confidentiality.
  * CVE-2021-26345: Failure to validate the value in APCB may allow an attacker
    with physical access to tamper with the APCB token to force an out-of-bounds
    memory read potentially resulting in a denial of service.
  * CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack
    (bsc#1215823).

## Special Instructions and Notes:

  * Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4665=1

  * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2  
    zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4665=1

  * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4665=1

  * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2  
    zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4665=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP1  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4665=1

  * SUSE Linux Enterprise Server for SAP Applications 15 SP2  
    zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4665=1

  * SUSE CaaS Platform 4.0  
To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform
you if it detects new updates and let you then trigger updating of the complete
cluster in a controlled way.

## Package List:

  * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1
  * SUSE CaaS Platform 4.0 (noarch)
    * kernel-firmware-20200107-150100.3.40.1
    * ucode-amd-20200107-150100.3.40.1

## References:

  * https://www.suse.com/security/cve/CVE-2021-26345.html
  * https://www.suse.com/security/cve/CVE-2021-46766.html
  * https://www.suse.com/security/cve/CVE-2021-46774.html
  * https://www.suse.com/security/cve/CVE-2022-23820.html
  * https://www.suse.com/security/cve/CVE-2022-23830.html
  * https://www.suse.com/security/cve/CVE-2023-20519.html
  * https://www.suse.com/security/cve/CVE-2023-20521.html
  * https://www.suse.com/security/cve/CVE-2023-20526.html
  * https://www.suse.com/security/cve/CVE-2023-20533.html
  * https://www.suse.com/security/cve/CVE-2023-20566.html
  * https://www.suse.com/security/cve/CVE-2023-20592.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1215823
  * https://bugzilla.suse.com/show_bug.cgi?id=1215831

SUSE: 2023:4665-1 important: kernel-firmware

December 14, 2023
* bsc#1215823 * bsc#1215831 Cross-References: * CVE-2021-26345

Summary

## This update for kernel-firmware fixes the following issues: Update AMD ucode to 20231030 (bsc#1215831): * CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. * CVE-2021-46774: Insufficient input validation in ABL may enable a privileged attacker to perform arbitrary DRAM writes, potentially resulting in code execution and privilege escalation. * CVE-2023-20533: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker using DMA to read/write from/to invalid DRAM address potentially resulting in denial-of-service. 0 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity. * CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity. * CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. * CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality. * CVE-2022-23830: SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity. * CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality. * CVE-2021-26345: Failure to validate the value in APCB may allow an attacker with physical access to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service. * CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack (bsc#1215823).

References

* bsc#1215823

* bsc#1215831

Cross-

* CVE-2021-26345

* CVE-2021-46766

* CVE-2021-46774

* CVE-2022-23820

* CVE-2022-23830

* CVE-2023-20519

* CVE-2023-20521

* CVE-2023-20526

* CVE-2023-20533

* CVE-2023-20566

* CVE-2023-20592

CVSS scores:

* CVE-2021-26345 ( SUSE ): 1.6 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L

* CVE-2021-26345 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

* CVE-2021-46766 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

* CVE-2021-46766 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

* CVE-2021-46774 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L

* CVE-2021-46774 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2022-23820 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

* CVE-2022-23820 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2022-23830 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

* CVE-2022-23830 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-20519 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

* CVE-2023-20519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

* CVE-2023-20521 ( SUSE ): 3.3 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L

* CVE-2023-20521 ( NVD ): 5.7 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

* CVE-2023-20526 ( SUSE ): 1.9 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

* CVE-2023-20526 ( NVD ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

* CVE-2023-20533 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H

* CVE-2023-20533 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-20566 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N

* CVE-2023-20566 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2023-20592 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N

* CVE-2023-20592 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected Products:

* SUSE CaaS Platform 4.0

* SUSE Linux Enterprise High Performance Computing 15 SP1

* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1

* SUSE Linux Enterprise High Performance Computing 15 SP2

* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2

* SUSE Linux Enterprise Server 15 SP1

* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1

* SUSE Linux Enterprise Server 15 SP2

* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2

* SUSE Linux Enterprise Server for SAP Applications 15 SP1

* SUSE Linux Enterprise Server for SAP Applications 15 SP2

An update that solves 11 vulnerabilities can now be installed.

##

* https://www.suse.com/security/cve/CVE-2021-26345.html

* https://www.suse.com/security/cve/CVE-2021-46766.html

* https://www.suse.com/security/cve/CVE-2021-46774.html

* https://www.suse.com/security/cve/CVE-2022-23820.html

* https://www.suse.com/security/cve/CVE-2022-23830.html

* https://www.suse.com/security/cve/CVE-2023-20519.html

* https://www.suse.com/security/cve/CVE-2023-20521.html

* https://www.suse.com/security/cve/CVE-2023-20526.html

* https://www.suse.com/security/cve/CVE-2023-20533.html

* https://www.suse.com/security/cve/CVE-2023-20566.html

* https://www.suse.com/security/cve/CVE-2023-20592.html

* https://bugzilla.suse.com/show_bug.cgi?id=1215823

* https://bugzilla.suse.com/show_bug.cgi?id=1215831

Severity
Announcement ID: SUSE-SU-2023:4665-1
Rating: important

Related News

News

Powered By

Footer Logo

Linux Security - Your source for Top Linux News, Advisories, HowTo's and Feature Release.

Powered By

Footer Logo