Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2025:1451-1 moderate fix for libva escalation risk issue

suse
Calendar Grey May 5, 2025
Dist Suse Esm H88
Tackling privilege amplification in the latest libva update for SUSE clientele. Key security protocols and updates highlighted.
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174

Summary

## This update for libva fixes the following issues: Update to libva version 2.20.0, which includes security fix for: * uncontrolled search path may allow an authenticated user to escalate privilege via local access (CVE-2023-39929, bsc#1224413, jsc#PED-11066) This includes latest version of one of the components needed for Video (processing) hardware support on Intel GPUs (bsc#1217770) Update to version 2.20.0: * av1: Revise offsets comments for av1 encode * drm: * Limit the array size to avoid out of range * Remove no longer used helpers * jpeg: add support for crop and partial decode * trace: * Add trace for vaExportSurfaceHandle * Unlock mutex before return * Fix minor issue about printf data type and value range * va/backend: * Annotate vafool as deprecated * Document the vaGetDriver* APIs

References

* bsc#1202828

* bsc#1217770

* bsc#1224413

* jsc#PED-11066

* jsc#PED-1174

* jsc#SLE-19361

Cross-

* CVE-2023-39929

CVSS scores:

* CVE-2023-39929 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.3

* SUSE Enterprise Storage 7.1

* SUSE Linux Enterprise High Performance Computing 15 SP3

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3

* SUSE Linux Enterprise Server 15 SP3

* SUSE Linux Enterprise Server 15 SP3 LTSS

* SUSE Linux Enterprise Server for SAP Applications 15 SP3

An update that solves one vulnerability, contains three features and has two

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2023-39929.html

* https://bugzilla.suse.com/show_bug.cgi?id=1202828

Announcement ID: SUSE-SU-2025:1451-1
Release Date: 2025-05-05T07:43:42Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here