Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2025:1477-1 moderate: escalation issue with libva detected

suse
Calendar Grey May 7, 2025
Dist Suse Esm H88
SUSE has released an update tackling significant vulnerabilities in libva, providing essential security improvements and optimizations specifically designed for Intel graphics processors.
* bsc#1202828 * bsc#1217770 * bsc#1224413 * jsc#PED-11066 * jsc#PED-1174

Summary

## This update for libva fixes the following issues: Update to libva version 2.20.0, which includes security fix for: * uncontrolled search path may allow an authenticated user to escalate privilege via local access (CVE-2023-39929, bsc#1224413, jsc#PED-11066) This includes latest version of one of the components needed for Video (processing) hardware support on Intel GPUs (bsc#1217770) Update to version 2.20.0: * av1: Revise offsets comments for av1 encode * drm: * Limit the array size to avoid out of range * Remove no longer used helpers * jpeg: add support for crop and partial decode * trace: * Add trace for vaExportSurfaceHandle * Unlock mutex before return * Fix minor issue about printf data type and value range * va/backend: * Annotate vafool as deprecated * Document the vaGetDriver* APIs

References

* bsc#1202828

* bsc#1217770

* bsc#1224413

* jsc#PED-11066

* jsc#PED-1174

* jsc#PM-1623

* jsc#SLE-12712

* jsc#SLE-19361

* jsc#SLE-8838

Cross-

* CVE-2023-39929

CVSS scores:

* CVE-2023-39929 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise High Performance Computing 12 SP5

* SUSE Linux Enterprise Server 12 SP5

* SUSE Linux Enterprise Server 12 SP5 LTSS

* SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security

* SUSE Linux Enterprise Server for SAP Applications 12 SP5

An update that solves one vulnerability, contains six features and has two

security fixes can now be installed.

##

* https://www.suse.com/security/cve/CVE-2023-39929.html

* https://bugzilla.suse.com/show_bug.cgi?id=1202828

* https://bugzilla.suse.com/show_bug.cgi?id=1217770

Announcement ID: SUSE-SU-2025:1477-1
Release Date: 2025-05-06T09:17:19Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here