* bsc#1216826 Cross-References: * CVE-2023-31022 . # Security update for kernel-firmware-nvidia-gspx-G06, nvidia-open- driver-G06-signed Announcement ID: SUSE-SU-2023:4429-1 Rating: moderate References: * bsc#1216826 Cross-References: * CVE-2023-31022 CVSS scores: * CVE-2023-31022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-31022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for kernel-firmware-nvidia-gspx-G06, nvidia-open-driver-G06-signed fixes the following issues: Security issues fixed: * CVE-2023-31022: Fixed NULL ptr deref in kernel module layer Changes in kernel-firmware-nvidia-gspx-G06: * update firmware to version 535.129.03 Changes in nvidia-open-driver-G06-signed: * Update to version 535.129.03 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patchSUSE-2023-4429=1 openSUSE-SLE-15.4-2023-4429=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4429=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-4429=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4429=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-4429=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4429=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-4429=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2023-4429=1 ## Package List: * openSUSE Leap 15.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * openSUSE Leap 15.4 (x86_64) * nvidia-open-driver-G06-signed-azure-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-debuginfo-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * openSUSE Leap 15.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-default-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * openSUSE Leap 15.4 (aarch64) * nvidia-open-driver-G06-signed-kmp-64kb-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-64kb-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-64kb-devel-535.129.03-150400.9.27.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3(aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * Basesystem Module 15-SP4 (aarch64 nosrc x86_64) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * Basesystem Module 15-SP4 (aarch64) * nvidia-open-driver-G06-signed-kmp-64kb-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-64kb-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 *nvidia-open-driver-G06-signed-64kb-devel-535.129.03-150400.9.27.1 * Basesystem Module 15-SP4 (aarch64 x86_64) * nvidia-open-driver-G06-signed-debugsource-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-default-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-debuginfo-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-default-535.129.03_k5.14.21_150400.24.92-150400.9.27.1 * Basesystem Module 15-SP5 (aarch64 nosrc) * kernel-firmware-nvidia-gspx-G06-535.129.03-150400.9.12.1 * Public Cloud Module 15-SP4 (x86_64) * nvidia-open-driver-G06-signed-azure-devel-535.129.03-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 * nvidia-open-driver-G06-signed-kmp-azure-debuginfo-535.129.03_k5.14.21_150400.14.72-150400.9.27.1 ## References: * https://www.suse.com/security/cve/CVE-2023-31022.html * https://bugzilla.suse.com/show_bug.cgi?id=1216826 . Recent security patch resolves NULL pointer dereference vulnerabilities in NVIDIA kernel driver firmware specifically for SUSE versions.. nvidia driver, kernel firmware, SUSE update, firmware security, system patch. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12655 https://linux.oracle.com/errata/ELSA-2023-12655.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: iwl1000-firmware-39.31.5.1-999.20.el8.noarch.rpm iwl100-firmware-39.31.5.1-999.20.el8.noarch.rpm iwl105-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl135-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl2000-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl2030-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl3160-firmware-25.30.13.0-999.20.el8.noarch.rpm iwl3945-firmware-15.32.2.9-999.20.el8.noarch.rpm iwl4965-firmware-228.61.2.24-999.20.el8.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.20.el8.noarch.rpm iwl5150-firmware-8.24.2.2-999.20.el8.noarch.rpm iwl6000-firmware-9.221.4.1-999.20.el8.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl6050-firmware-41.28.5.1-999.20.el8.noarch.rpm iwl7260-firmware-25.30.13.0-999.20.el8.noarch.rpm iwlax2xx-firmware-20230516-999.20.el8.noarch.rpm libertas-sd8686-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-sd8787-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-usb8388-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-usb8388-olpc-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm linux-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm linux-firmware-core-20230516-999.20.git6c9e0ed5.el8.noarch.rpm aarch64: iwl1000-firmware-39.31.5.1-999.20.el8.noarch.rpm iwl100-firmware-39.31.5.1-999.20.el8.noarch.rpm iwl105-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl135-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl2000-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl2030-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl3160-firmware-25.30.13.0-999.20.el8.noarch.rpm iwl3945-firmware-15.32.2.9-999.20.el8.noarch.rpm iwl4965-firmware-228.61.2.24-999.20.el8.noarch.rpm iwl5000-firmware-8.83.5.1_1-999.20.el8.noarch.rpm iwl5150-firmware-8.24.2.2-999.20.el8.noarch.rpm iwl6000-firmware-9.221.4.1-999.20.el8.noarch.rpm iwl6000g2a-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl6000g2b-firmware-18.168.6.1-999.20.el8.noarch.rpm iwl6050-firmware-41.28.5.1-999.20.el8.noarch.rpm iwl7260-firmware-25.30.13.0-999.20.el8.noarch.rpm iwlax2xx-firmware-20230516-999.20.el8.noarch.rpm libertas-sd8686-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-sd8787-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-usb8388-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm libertas-usb8388-olpc-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm linux-firmware-20230516-999.20.git6c9e0ed5.el8.noarch.rpm linux-firmware-core-20230516-999.20.git6c9e0ed5.el8.noarch.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//linux-firmware-20230516-999.20.git6c9e0ed5.el8.src.rpm Related CVEs: CVE-2023-20593 Description of changes: [20230516-999.20.git6c9e0ed5.el8] - cd72938cb480 linux-firmware: Update AMD fam17h cpu microcode - 92624e57af69 linux-firmware: Update AMD cpu microcode [20230516-999.19.git6c9e0ed5.el8] - Rebase to upstream - Revert removal of old iwlwifi firmwares (Orabug: 35260375) _______________________________________________ El-errata mailing list
- Updated bcm 4339 4354 4356 4358 firmware, new bcm 43430 - Fixes CVE-2016-0801 CVE-2017-0561 CVE-2017-9417 ---- - Updated Intel GPU, amdgpu, iwlwifi, mvebu wifi, liquidio, QCom a530 & Venus, mlxsw, qed - Add iwlwifi 9000 series. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a253644369 2017-12-09 21:09:01.032645 --------------------------------------------------------------------------------Name : linux-firmware Product : Fedora 26 Version : 20171126 Release : 80.git17e62881.fc26 URL : https://www.kernel.org/ Summary : Firmware files used by the Linux kernel Description : This package includes firmware files required for some devices to operate. --------------------------------------------------------------------------------Update Information: - Updated bcm 4339 4354 4356 4358 firmware, new bcm 43430 - Fixes CVE-2016-0801 CVE-2017-0561 CVE-2017-9417 ---- - Updated Intel GPU, amdgpu, iwlwifi, mvebu wifi, liquidio, QCom a530 & Venus, mlxsw, qed - Add iwlwifi 9000 series --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade linux-firmware' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.