Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2025:1453-1 moderate: libva privilege escalation fix

suse
Calendar Grey May 5, 2025
Dist Suse Esm H88
The recent security patch from SUSE tackles a privilege escalation vulnerability in libva affecting various distributions. Update promptly!
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066

Summary

## This update for libva fixes the following issues: Update to libva version 2.20.0, which includes security fix for: * CVE-2023-39929: uncontrolled search path may allow an authenticated user to escalate privilege via local access (bsc#1224413, jsc#PED-11066) This includes latest version of one of the components needed for Video (processing) hardware support on Intel GPUs (bsc#1217770) Update to version 2.20.0: * av1: Revise offsets comments for av1 encode * drm: * Limit the array size to avoid out of range * Remove no longer used helpers * jpeg: add support for crop and partial decode * trace: * Add trace for vaExportSurfaceHandle * Unlock mutex before return * Fix minor issue about printf data type and value range * va/backend: * Annotate vafool as deprecated * Document the vaGetDriver* APIs

References

* bsc#1202828

* bsc#1217770

* bsc#1224413

* jsc#PED-11066

Cross-

* CVE-2023-39929

CVSS scores:

* CVE-2023-39929 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* openSUSE Leap 15.5

* SUSE Linux Enterprise High Performance Computing 15 SP5

* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5

* SUSE Linux Enterprise Server 15 SP5

* SUSE Linux Enterprise Server 15 SP5 LTSS

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

An update that solves one vulnerability, contains one feature and has two

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2023-39929.html

* https://bugzilla.suse.com/show_bug.cgi?id=1202828

Announcement ID: SUSE-SU-2025:1453-1
Release Date: 2025-05-05T07:44:16Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here