Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2025:1452-1 moderate: libva privilege escalation fix

suse
Calendar Grey May 5, 2025
Dist Suse Esm H88
SUSE has issued a notice regarding a minor severity enhancement for libva which mitigates an issue related to local privilege escalation vulnerabilities.
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174

Summary

## This update for libva fixes the following issues: Update to libva version 2.20.0, which includes security fix for: * CVE-2023-39929: Uncontrolled search path may allow an authenticated user to escalate privilege via local access (bsc#1224413, jsc#PED-11066) This includes latest version of one of the components needed for Video (processing) hardware support on Intel GPUs (bsc#1217770) Update to version 2.20.0: * av1: Revise offsets comments for av1 encode * drm: * Limit the array size to avoid out of range * Remove no longer used helpers * jpeg: add support for crop and partial decode * trace: * Add trace for vaExportSurfaceHandle * Unlock mutex before return * Fix minor issue about printf data type and value range * va/backend: * Annotate vafool as deprecated * Document the vaGetDriver* APIs

References

* bsc#1202828

* bsc#1217770

* bsc#1224413

* jsc#PED-11066

* jsc#PED-1174

Cross-

* CVE-2023-39929

CVSS scores:

* CVE-2023-39929 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.4

* SUSE Linux Enterprise High Performance Computing 15 SP4

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4

* SUSE Linux Enterprise Server 15 SP4

* SUSE Linux Enterprise Server 15 SP4 LTSS

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

An update that solves one vulnerability, contains two features and has two

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2023-39929.html

* https://bugzilla.suse.com/show_bug.cgi?id=1202828

Announcement ID: SUSE-SU-2025:1452-1
Release Date: 2025-05-05T07:44:00Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here