Update to Samba 4.22.6 - Security fix for CVE-2025-9640 and CVE-2025-10230. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7d890563f6 2025-11-03 01:05:58.219447+00:00 -------------------------------------------------------------------------------- Name : samba Product : Fedora 42 Version : 4.22.6 Release : 1.fc42 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. -------------------------------------------------------------------------------- Update Information: Update to Samba 4.22.6 - Security fix for CVE-2025-9640 and CVE-2025-10230 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 17 2025 Gnther Deschner - 2:4.22.6-1 - Update to Samba 4.22.6 * Fri Oct 17 2025 Gnther Deschner - 2:4.22.5-1 - Update to Samba 4.22.5 - resolves: rhbz#2391698 - Security fix for CVE-2025-9640 - resolves: rhbz#2394377 - Security fix for CVE-2025-10230 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2391698 - CVE-2025-9640 samba: vfs_streams_xattr uninitialized memory write possible https://bugzilla.redhat.com/show_bug.cgi?id=2391698 [ 2 ] Bug #2394377 - CVE-2025-10230 samba: Command Injection in WINS Server Hook Script https://bugzilla.redhat.com/show_bug.cgi?id=2394377 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7d890563f6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Samba 4.22.6 update for Fedora 42 addresses critical CVE-2025-9640 and CVE-2025-10230 security issues. Update recommended.. Samba update Fedora security patch command injection uninitialized memory. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-3668 http://linux.oracle.com/errata/ELSA-2024-3668.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: ruby-3.1.5-144.module+el9.4.0+90348+c2ef46bf.i686.rpm ruby-3.1.5-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm ruby-bundled-gems-3.1.5-144.module+el9.4.0+90348+c2ef46bf.i686.rpm ruby-bundled-gems-3.1.5-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm ruby-default-gems-3.1.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm ruby-devel-3.1.5-144.module+el9.4.0+90348+c2ef46bf.i686.rpm ruby-devel-3.1.5-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm ruby-doc-3.1.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-bigdecimal-3.1.1-144.module+el9.4.0+90348+c2ef46bf.i686.rpm rubygem-bigdecimal-3.1.1-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm rubygem-bundler-2.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-io-console-0.5.11-144.module+el9.4.0+90348+c2ef46bf.i686.rpm rubygem-io-console-0.5.11-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm rubygem-irb-1.4.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-json-2.6.1-144.module+el9.4.0+90348+c2ef46bf.i686.rpm rubygem-json-2.6.1-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm rubygem-minitest-5.15.0-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-mysql2-0.5.4-1.module+el9.1.0+20815+286161bd.x86_64.rpm rubygem-mysql2-doc-0.5.4-1.module+el9.1.0+20815+286161bd.noarch.rpm rubygem-pg-1.3.5-1.module+el9.1.0+20815+286161bd.x86_64.rpm rubygem-pg-doc-1.3.5-1.module+el9.1.0+20815+286161bd.noarch.rpm rubygem-power_assert-2.0.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-psych-4.0.4-144.module+el9.4.0+90348+c2ef46bf.i686.rpm rubygem-psych-4.0.4-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm rubygem-rake-13.0.6-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rbs-2.7.0-144.module+el9.4.0+90348+c2ef46bf.i686.rpm rubygem-rbs-2.7.0-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm rubygem-rdoc-6.4.1.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rexml-3.2.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rss-0.2.9-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygems-3.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygems-devel-3.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-test-unit-3.5.3-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-typeprof-0.21.3-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm ruby-libs-3.1.5-144.module+el9.4.0+90348+c2ef46bf.i686.rpm ruby-libs-3.1.5-144.module+el9.4.0+90348+c2ef46bf.x86_64.rpm aarch64: ruby-3.1.5-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm ruby-bundled-gems-3.1.5-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm ruby-default-gems-3.1.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm ruby-devel-3.1.5-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm ruby-doc-3.1.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-bigdecimal-3.1.1-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm rubygem-bundler-2.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-io-console-0.5.11-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm rubygem-irb-1.4.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-json-2.6.1-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm rubygem-minitest-5.15.0-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-mysql2-0.5.4-1.module+el9.1.0+20815+286161bd.aarch64.rpm rubygem-mysql2-doc-0.5.4-1.module+el9.1.0+20815+286161bd.noarch.rpm rubygem-pg-1.3.5-1.module+el9.1.0+20815+286161bd.aarch64.rpm rubygem-pg-doc-1.3.5-1.module+el9.1.0+20815+286161bd.noarch.rpm rubygem-power_assert-2.0.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-psych-4.0.4-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm rubygem-rake-13.0.6-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rbs-2.7.0-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm rubygem-rdoc-6.4.1.1-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rexml-3.2.5-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-rss-0.2.9-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygems-3.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygems-devel-3.3.27-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-test-unit-3.5.3-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm rubygem-typeprof-0.21.3-144.module+el9.4.0+90348+c2ef46bf.noarch.rpm ruby-libs-3.1.5-144.module+el9.4.0+90348+c2ef46bf.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//ruby-3.1.5-144.module+el9.4.0+90348+c2ef46bf.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//rubygem-mysql2-0.5.4-1.module+el9.1.0+20815+286161bd.src.rpm http://oss.oracle.com/ol9/SRPMS-updates//rubygem-pg-1.3.5-1.module+el9.1.0+20815+286161bd.src.rpm Related CVEs: CVE-2024-27280 CVE-2024-27281 CVE-2024-27282 Description of changes: ruby [3.1.5-144] - Upgrade to Ruby 3.1.5. Resolves: RHEL-33978 - Fix buffer overread vulnerability in StringIO. Resolves: RHEL-34129 - Fix RCE vulnerability with .rdoc_options in RDoc. Resolves: RHEL-34121 - Fix arbitrary memory address read vulnerability with Regex search. Resolves: RHEL-33871 [3.1.4-143] - Upgrade to Ruby 3.1.4. Resolves: RHEL-5586 - Fix HTTP response splitting in CGI. Resolves: RHEL-5591 - Fix ReDos vulnerability in URI. Resolves: RHEL-28919 Resolves: RHEL-5612 - Fix ReDos vulnerability in Time. Resolves: RHEL-28920 - Make RDoc soft dependency in IRB. Resolves: RHEL-5613 [3.1.2-142] - Bypass git submodule test failure on Git > = 2.38.1. - Fix tests with Europe/Amsterdam pre-1970 time on tzdata version 2022b. - Fix for tzdata-2022g. - Fix OpenSSL.fips_mode and OpenSSL::PKey.read in OpenSSL 3 FIPS. Resolves: RHEL-5590 - ssl: use ffdhe2048 from RFC 7919 as the default DH group parameters Related: RHEL-5590 - Disable fiddle tests that use FFI closures. Related: RHEL-5590 [3.1.2-141] - Upgrade to Ruby 3.1.2 by merging Fedora Rawhide branch (commit: b7b5473). Resolves: rhbz#2063773 rubygem-mysql2 [0.5.4-1] - New upstream release 0.5.4 by merging Fedora rawhide branch (commit: e21b5b9) Resolves: rhbz#2063773 [0.5.3-1] - New upstream release 0.5.3 by merging Fedora master branch (commit: 674d475) Resolves: rhbz#1817135 rubygem-pg * Thu May 26 2022 Jarek Prokop - 1.3.5-1 - Update to pg 1.3.5 Related: rhbz#2063773 [1.2.3-1] - Update to pg 1.2.3 by merging Fedora master branch (commit: 5db4d26) Resolves:rhbz#1817135 _______________________________________________ El-errata mailing list
This update for xorg-x11-server fixes the following issues: CVE-2023-6377: Fixed out-of-bounds memory write in XKB button actions (bsc#1217765).. # Security update for xorg-x11-server Announcement ID: SUSE-SU-2023:4791-1 Rating: important References: * bsc#1217765 * bsc#1217766 Cross-References: * CVE-2023-6377 * CVE-2023-6478 CVSS scores: * CVE-2023-6377 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6478 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP4 * Development Tools Module 15-SP4 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues: * CVE-2023-6377: Fixed out-of-bounds memory write in XKB button actions (bsc#1217765). * CVE-2023-6478: Fixed out-of-bounds memory read in RRChangeOutputProperty and RRChangeProviderProperty (bsc#1217766). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4791=1 openSUSE-SLE-15.4-2023-4791=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4791=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4791=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * xorg-x11-server-source-1.20.3-150400.38.32.1 *xorg-x11-server-debugsource-1.20.3-150400.38.32.1 * xorg-x11-server-1.20.3-150400.38.32.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.32.1 * xorg-x11-server-extra-1.20.3-150400.38.32.1 * xorg-x11-server-sdk-1.20.3-150400.38.32.1 * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.32.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-1.20.3-150400.38.32.1 * xorg-x11-server-1.20.3-150400.38.32.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.32.1 * xorg-x11-server-extra-1.20.3-150400.38.32.1 * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.32.1 * Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-1.20.3-150400.38.32.1 * xorg-x11-server-sdk-1.20.3-150400.38.32.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.32.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6377.html * https://www.suse.com/security/cve/CVE-2023-6478.html * https://bugzilla.suse.com/show_bug.cgi?id=1217765 * https://bugzilla.suse.com/show_bug.cgi?id=1217766 . Essential xorg-x11-server patch addresses serious out-of-bounds memory vulnerabilities on openSUSE platforms. Ensure your system's security.. xorg-x11-server update, openSUSE security, memory exploit fix. . Severity: Important. LinuxSecurity.com Team
This update for the Linux Kernel 5.14.21-150400_24_63 fixes several issues. The following security issues were fixed:. # Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP4) Announcement ID: SUSE-SU-2023:3648-1 Rating: important References: * #1208839 * #1211187 * #1211395 * #1212849 * #1213063 Cross-References: * CVE-2023-1077 * CVE-2023-2156 * CVE-2023-3090 * CVE-2023-32233 * CVE-2023-35001 CVSS scores: * CVE-2023-1077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-1077 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-2156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-2156 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-3090 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-3090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32233 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-32233 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-35001 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.14.21-150400_24_63 fixes several issues. The following security issues were fixed: * CVE-2023-32233: Fixed a use-after-free in Netfilter nf_tables when processing batch requests (bsc#1211187). * CVE-2023-2156: Fixed a flaw in the networking subsystem within the handling of the RPL protocol(bsc#1211395). * CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213063). * CVE-2023-1077: Fixed a type confusion in pick_next_rt_entity(), that could cause memory corruption (bsc#1208839). * CVE-2023-3090: Fixed a heap out-of-bounds write in the ipvlan network driver (bsc#1212849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-3648=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2023-3648=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_12-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_63-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_63-default-5-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_12-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_63-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_63-default-5-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2023-1077.html * https://www.suse.com/security/cve/CVE-2023-2156.html * https://www.suse.com/security/cve/CVE-2023-3090.html * https://www.suse.com/security/cve/CVE-2023-32233.html * https://www.suse.com/security/cve/CVE-2023-35001.html * https://bugzilla.suse.com/show_bug.cgi?id=1208839 * https://bugzilla.suse.com/show_bug.cgi?id=1211187 * https://bugzilla.suse.com/show_bug.cgi?id=1211395 * https://bugzilla.suse.com/show_bug.cgi?id=1212849 * https://bugzilla.suse.com/show_bug.cgi?id=1213063 . A security update for the Linux Kernel fixes various vulnerabilities, including out-of-bounds errors and memory corruption..Linux Kernel Patch, openSUSE Update, Memory Exploit, Network Issues. . Severity: Important. LinuxSecurity.com Team
Multiple security vulnerabilities have been discovered in Apache HTTP server. CVE-2006-20001 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3351-1
Several security issues were fixed in LibBPF.. =========================================================================Ubuntu Security Notice USN-5759-1 December 05, 2022 libbpf vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in LibBPF. Software Description: - libbpf: eBPF helper library (development files) Details: It was discovered that LibBPF incorrectly handled certain memory operations under certain circumstances. An attacker could possibly use this issue to cause LibBPF to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.10. (CVE-2021-45940, CVE-2021-45941, CVE-2022-3533) It was discovered that LibBPF incorrectly handled certain memory operations under certain circumstances. An attacker could possibly use this issue to cause LibBPF to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2022-3534, CVE-2022-3606) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libbpf-dev 1:0.8.0-1ubuntu22.10.1 Ubuntu 22.04 LTS: libbpf-dev 1:0.5.0-1ubuntu22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5759-1 CVE-2021-45940, CVE-2021-45941, CVE-2022-3533, CVE-2022-3534, CVE-2022-3606 Package Information: https://launchpad.net/ubuntu/+source/libbpf/0.8.0-1ubuntu22.10.1 . LibBPF encountered serious vulnerabilities patched in Ubuntu versions 22.04 and 22.10. Users at risk are urged to perform updates.. LibBPF Exploit, Ubuntu Security, Memory Management Issues. . Severity: Critical. LinuxSecurity.com Team
Jan-Niklas Sohn discovered two out of bound memory writes in X.Org Server's ProcXkbSetGeometry and ProcXkbSetDeviceInfo Xkb extensions. These issues could be exploited by an attacker to cause denial of service, privilege escalation or arbitrary code execution. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3068-1
An update that solves 9 vulnerabilities and has 9 fixes is now available. . SUSE Security Update: Security update for the Linux Kernel ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2423-1 Rating: important References: #1194013 #1195775 #1196901 #1197362 #1199487 #1199489 #1199657 #1200263 #1200442 #1200571 #1200599 #1200604 #1200605 #1200608 #1200619 #1200692 #1201050 #1201080 Cross-References: CVE-2021-26341 CVE-2021-4157 CVE-2022-1679 CVE-2022-20132 CVE-2022-20141 CVE-2022-20154 CVE-2022-29900 CVE-2022-29901 CVE-2022-33981 CVSS scores: CVE-2021-26341 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N CVE-2021-26341 (SUSE): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N CVE-2021-4157 (NVD) : 8 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-4157 (SUSE): 3.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L CVE-2022-1679 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-1679 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-20132 (NVD) : 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2022-20132 (SUSE): 4.9 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L CVE-2022-20141 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-20141 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-20154 (NVD) : 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-20154 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-29900 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2022-29901 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2022-33981 (NVD) : 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVE-2022-33981 (SUSE): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Availability 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise Module for Live Patching 15-SP2 SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP2 SUSE Linux Enterprise Storage 7 SUSE Manager Proxy 4.1 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 ______________________________________________________________________________ An update that solves 9 vulnerabilities and has 9 fixes is now available. Description: The SUSE Linux Enterprise 15 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-29900, CVE-2022-29901: Fixed the RETBLEED attack, a new Spectre like Branch Target Buffer attack, that can leak arbitrary kernel information (bsc#1199657). - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages (bsc#1199487). - CVE-2022-20132: Fixed out of bounds read due to improper input validation in lg_probe and related functions of hid-lg.c (bsc#1200619). - CVE-2022-33981: Fixed use-after-free in floppy driver(bsc#1200692) - CVE-2022-20141: Fixed a possible use after free due to improper locking in ip_check_mc_rcu() (bsc#1200604). - CVE-2021-4157: Fixed an out of memory bounds write flaw in the NFS subsystem, related to the replication of files with NFS. A user could potentially crash the system or escalate privileges on the system (bsc#1194013). - CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed (bsc#1200599). - CVE-2021-26341: Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage (bsc#1201050). The following non-security bugs were fixed: - bcache: avoid unnecessary soft lockup in kworker update_writeback_rate() (bsc#1197362). - blk-mq: Fix wrong wakeup batch configuration which will cause hang (bsc#1200263). - blk-mq: clear active_queues before clearing BLK_MQ_F_TAG_QUEUE_SHARED (bsc#1200263). - blk-mq: fix tag_get wait task can't be awakened (bsc#1200263). - exec: Force single empty string when argv is empty (bsc#1200571). - vmxnet3: fix minimum vectors alloc issue (bsc#1199489). Special Instructions and Notes: Please reboot the system after installing this update. Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-2423=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-2423=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-2423=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP2-2022-2423=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-2423=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-2423=1 - SUSE Linux Enterprise Module for Live Patching 15-SP2: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2022-2423=1 Please note that this is the initial kernel livepatch without fixes itself, this livepatch package is later updated by seperate standalone livepatch updates. - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-2423=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-2423=1 - SUSE Linux Enterprise High Availability 15-SP2: zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2022-2423=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-2423=1 Package List: - SUSE Manager Server 4.1 (ppc64le s390x x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Manager Server 4.1 (x86_64): kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 -SUSE Manager Server 4.1 (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Manager Retail Branch Server 4.1 (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Manager Proxy 4.1 (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Manager Proxy 4.1 (x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (x86_64): kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 x86_64): kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server 15-SP2-BCL (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 - SUSE Linux Enterprise Module for Live Patching 15-SP2 (ppc64le s390x x86_64): kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-livepatch-5.3.18-150200.24.120.1 kernel-default-livepatch-devel-5.3.18-150200.24.120.1 kernel-livepatch-5_3_18-150200_24_120-default-1-150200.5.5.1 kernel-livepatch-5_3_18-150200_24_120-default-debuginfo-1-150200.5.5.1 kernel-livepatch-SLE15-SP2_Update_28-debugsource-1-150200.5.5.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 - SUSE Linux Enterprise High Availability 15-SP2 (aarch64 ppc64le s390x x86_64): cluster-md-kmp-default-5.3.18-150200.24.120.1 cluster-md-kmp-default-debuginfo-5.3.18-150200.24.120.1 dlm-kmp-default-5.3.18-150200.24.120.1 dlm-kmp-default-debuginfo-5.3.18-150200.24.120.1 gfs2-kmp-default-5.3.18-150200.24.120.1 gfs2-kmp-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 ocfs2-kmp-default-5.3.18-150200.24.120.1 ocfs2-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): kernel-default-5.3.18-150200.24.120.1 kernel-default-base-5.3.18-150200.24.120.1.150200.9.56.2 kernel-default-debuginfo-5.3.18-150200.24.120.1 kernel-default-debugsource-5.3.18-150200.24.120.1 kernel-default-devel-5.3.18-150200.24.120.1 kernel-default-devel-debuginfo-5.3.18-150200.24.120.1 kernel-obs-build-5.3.18-150200.24.120.1 kernel-obs-build-debugsource-5.3.18-150200.24.120.1 kernel-preempt-5.3.18-150200.24.120.1 kernel-preempt-debuginfo-5.3.18-150200.24.120.1 kernel-preempt-debugsource-5.3.18-150200.24.120.1 kernel-preempt-devel-5.3.18-150200.24.120.1 kernel-preempt-devel-debuginfo-5.3.18-150200.24.120.1 kernel-syms-5.3.18-150200.24.120.1 reiserfs-kmp-default-5.3.18-150200.24.120.1 reiserfs-kmp-default-debuginfo-5.3.18-150200.24.120.1 - SUSE Enterprise Storage 7 (noarch): kernel-devel-5.3.18-150200.24.120.1 kernel-docs-5.3.18-150200.24.120.1 kernel-macros-5.3.18-150200.24.120.1 kernel-source-5.3.18-150200.24.120.1 References: https://www.suse.com/security/cve/CVE-2021-26341.html https://www.suse.com/security/cve/CVE-2021-4157.html https://www.suse.com/security/cve/CVE-2022-1679.html https://www.suse.com/security/cve/CVE-2022-20132.html https://www.suse.com/security/cve/CVE-2022-20141.html https://www.suse.com/security/cve/CVE-2022-20154.html https://www.suse.com/security/cve/CVE-2022-29900.html https://www.suse.com/security/cve/CVE-2022-29901.html https://www.suse.com/security/cve/CVE-2022-33981.html https://bugzilla.suse.com/1194013 https://bugzilla.suse.com/1195775 https://bugzilla.suse.com/1196901 https://bugzilla.suse.com/1197362 https://bugzilla.suse.com/1199487 https://bugzilla.suse.com/1199489 https://bugzilla.suse.com/1199657 https://bugzilla.suse.com/1200263 https://bugzilla.suse.com/1200442 https://bugzilla.suse.com/1200571 https://bugzilla.suse.com/1200599 https://bugzilla.suse.com/1200604 https://bugzilla.suse.com/1200605 https://bugzilla.suse.com/1200608 https://bugzilla.suse.com/1200619 https://bugzilla.suse.com/1200692 https://bugzilla.suse.com/1201050 https://bugzilla.suse.com/1201080 . Critical SUSE patch resolves several security concerns in the Linux Kernel, addressing both retbleed and memory-related flaws.. SUSE Update, Kernel Exploit Fix, Security Issues, Linux Patch. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.