An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2025:4281-1 Release Date: 2025-11-27T15:04:07Z Rating: important References: * bsc#1251983 Cross-References: * CVE-2023-53673 CVSS scores: * CVE-2023-53673 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53673 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 5.14.21-150400.24.173 fixes one security issue The following security issue was fixed: * CVE-2023-53673: Bluetooth: hci_event: call disconnect callback before deleting conn (bsc#1251983). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-4281=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-4281=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-5-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-5-150400.2.1 *kernel-livepatch-5_14_21-150400_24_173-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-5-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53673.html * https://bugzilla.suse.com/show_bug.cgi?id=1251983 . Update for openSUSE addresses a critical security issue in Bluetooth kernel interactions, enhancing system safety.. openSUSE, kernel, Bluetooth, security patch, SUSE Linux. . Severity: Important. LinuxSecurity.com Team
* bsc#1251983 Cross-References: * CVE-2023-53673 . # Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2025:4242-1 Release Date: 2025-11-25T21:11:36Z Rating: important References: * bsc#1251983 Cross-References: * CVE-2023-53673 CVSS scores: * CVE-2023-53673 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53673 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 5.14.21-150400.24.179 fixes one security issue The following security issue was fixed: * CVE-2023-53673: Bluetooth: hci_event: call disconnect callback before deleting conn (bsc#1251983). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-4242=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2025-4242=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-2-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-2-150400.2.1 *kernel-livepatch-5_14_21-150400_24_179-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53673.html * https://bugzilla.suse.com/show_bug.cgi?id=1251983 . SUSE Linux Kernel Security Update addresses CVE-2023-53673, ensuring critical fixes for Bluetooth connection failures.. SUSE security update, Linux kernel patch, Bluetooth security, system vulnerabilities, enterprise Linux security. . Severity: Important. LinuxSecurity.com Team
Security fix for CVE-2019-16275. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2bdcccee3c 2019-11-17 01:12:46.786636 --------------------------------------------------------------------------------Name : wpa_supplicant Product : Fedora 30 Version : 2.8 Release : 3.fc30 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-16275 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 30 2019 Davide Caratti - 1:2.8-3 - fix AP mode PMF disconnection protection bypass (CVE-2019-16275, rh #1767026) * Fri May 10 2019 Davide Caratti - 1:2.8-2 - fix changelog for version 2.8-1 * Thu May 2 2019 Davide Caratti - 1:2.8-1 - Update to 2.8 upstream release, to include latest fix for NULL pointer dereference when EAP-PWD peer receives unexpected EAP fragments (CVE-2019-11555, rh #1701759) --------------------------------------------------------------------------------References: [ 1 ] Bug #1767023 - CVE-2019-16275 wpa_supplicant: AP mode PMF disconnection protection bypass https://bugzilla.redhat.com/show_bug.cgi?id=1767023 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2bdcccee3c' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
wpa_supplicant could be made to be disconnected and require reconnection to the network if it received a specially crafted management frame.. =========================================================================Ubuntu Security Notice USN-4136-2 September 18, 2019 wpa, wpasupplicant vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: wpa_supplicant could be made to be disconnected and require reconnection to the network if it received a specially crafted management frame. Software Description: - wpa: client support for WPA and WPA2 - wpasupplicant: client support for WPA and WPA2 Details: USN-4136-1 fixed a vulnerability in wpa_supplicant. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that wpa_supplicant incorrectly handled certain management frames. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: hostapd 1:2.1-0ubuntu1.7+esm2 wpasupplicant 2.1-0ubuntu1.7+esm2 Ubuntu 12.04 ESM: wpasupplicant 0.7.3-6ubuntu2.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4136-2 https://ubuntu.com/security/notices/USN-4136-1 CVE-2019-16275 . The Ubuntu Security Notice USN-4136-2 addresses a vulnerability in wpa_supplicant that may lead to problems with disconnecting and reconnecting to networks.. wpa_supplicant, network connection, denial of service. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.