Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

openSUSE 15.5: 2023-4734 critical: Kernel Local Escalation Fix

suse
Calendar Grey December 14, 2023
Dist Suse Esm H88
A significant update for the Linux Kernel has been issued, addressing a multitude of security flaws, particularly those that could lead to unauthorized local privilege escalation.
* bsc#1084909 * bsc#1207948 * bsc#1210447 * bsc#1214286 * bsc#1214700

Summary

## The SUSE Linux Enterprise 15 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2023-2006: Fixed a race condition in the RxRPC network protocol (bsc#1210447). * CVE-2023-25775: Fixed improper access control in the Intel Ethernet Controller RDMA driver (bsc#1216959). * CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976). * CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965). * CVE-2023-4244: Fixed a use-after-free in the nf_tables component, which could be exploited to achieve local privilege escalation (bsc#1215420). * CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058).

References

* bsc#1084909

* bsc#1207948

* bsc#1210447

* bsc#1214286

* bsc#1214700

* bsc#1214840

* bsc#1214976

* bsc#1215123

* bsc#1215124

* bsc#1215292

* bsc#1215420

* bsc#1215458

* bsc#1215710

* bsc#1215802

* bsc#1215931

* bsc#1216058

* bsc#1216105

* bsc#1216259

* bsc#1216527

* bsc#1216584

* bsc#1216687

* bsc#1216693

* bsc#1216759

* bsc#1216788

* bsc#1216844

* bsc#1216861

* bsc#1216909

* bsc#1216959

* bsc#1216965

* bsc#1216976

* bsc#1217036

* bsc#1217068

* bsc#1217086

* bsc#1217095

* bsc#1217124

* bsc#1217140

* bsc#1217147

* bsc#1217195

* bsc#1217196

* bsc#1217200

* bsc#1217205

* bsc#1217332

* bsc#1217366

* bsc#1217511

* bsc#1217515

* bsc#1217598

* bsc#1217599

* bsc#1217609

* bsc#1217687

* bsc#1217731

* bsc#1217780

* jsc#PED-3184

* jsc#PED-5021

* jsc#PED-7237

Cross-

* CVE-2023-2006

* CVE-2023-25775

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2023:4734-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here