This update for kernel-firmware-nvidia-gspx-G06, nvidia-open-driver-G06-signed fixes the following issues: Security issues fixed:. # Security update for kernel-firmware-nvidia-gspx-G06, nvidia-open- driver-G06-signed Announcement ID: SUSE-SU-2023:4429-1 Rating: moderate References: * bsc#1216826 Cross-References: * CVE-2023-31022 CVSS scores: * CVE-2023-31022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-31022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for kernel-firmware-nvidia-gspx-G06, nvidia-open-driver-G06-signed fixes the following issues: Security issues fixed: * CVE-2023-31022: Fixed NULL ptr deref in kernel module layer Changes in kernel-firmware-nvidia-gspx-G06: * update firmware to version 535.129.03 Changes in nvidia-open-driver-G06-signed: * Update to version 535.129.03 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4429=1 openSUSE-SLE-15.4-2023-4429=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4429=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4429=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4429=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4429=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4429=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4429=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2023-4429=1 ## Package List: * openSUSE Leap 15.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * openSUSE Leap 15.4 (x86_64) * nvidia-open-driver-G06-signed-azure-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-debuginfo-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * openSUSE Leap 15.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-default-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * openSUSE Leap 15.4 (aarch64) * nvidia-open-driver-G06-signed-kmp-64kb-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-64kb-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-64kb-devel-535.129.03-150400.9.27.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc x86_64) *kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * Basesystem Module 15-SP4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * Basesystem Module 15-SP4 (aarch64) * nvidia-open-driver-G06-signed-kmp-64kb-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 *nvidia-open-driver-G06-signed-kmp-64kb-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-64kb-devel-535.129.03-150400.9.27.1 * Basesystem Module 15-SP4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-default-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * Basesystem Module 15-SP5 (aarch64 nosrc) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * Public Cloud Module 15-SP4 (x86_64) * nvidia-open-driver-G06-signed-azure-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-debuginfo-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 ## References: * https://www.suse.com/security/cve/CVE-2023-31022.html * https://bugzilla.suse.com/show_bug.cgi?id=1216826 . Addresses vulnerabilities in the Nvidia graphics drivers and firmware for openSUSE, classified with a moderate threat level. Discover additional details here.. Nvidia Driver Fix, Kernel Firmware Update, OpenSUSE Security Fix. . LinuxSecurity.com Team
MadWifi is vulnerable to a buffer overflow that could potentially lead to the remote execution of arbitrary code with root privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200612-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: MadWifi: Kernel driver buffer overflow Date: December 10, 2006 Bugs: #157449 ID: 200612-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= MadWifi is vulnerable to a buffer overflow that could potentially lead to the remote execution of arbitrary code with root privileges. Background ========= MadWifi (Multiband Atheros Driver for Wireless Fidelity) provides a Linux kernel device driver for Atheros-based Wireless LAN devices. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.2.1 > = 0.9.2.1 Description ========== Laurent Butti, Jerome Raznieski and Julien Tinnes reported a buffer overflow in the encode_ie() and the giwscan_cb() functions from ieee80211_wireless.c. Impact ===== A remote attacker could send specially crafted wireless WPA packets containing malicious RSN Information Headers (IE) that could potentially lead to the remote execution of arbitrary code as the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.2.1" References ========= [ 1 ] CVE-2006-6332 https://www.cve.org/CVERecord?id=CVE-2006-6332 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200612-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.