Security update for the Linux Kernel
Announcement ID: | SUSE-SU-2023:2506-1 |
---|---|
Rating: | important |
References: | |
Cross-References: | |
CVSS scores: |
|
Affected Products: |
|
An update that solves 14 vulnerabilities and has one security fix can now be installed.
Description:
The SUSE Linux Enterprise 11 SP4 LTSS EXTREME CORE kernel was updated to receive various security and bugfixes.
The following security bugs were fixed:
- CVE-2023-2162: Fixed an use-after-free flaw in iscsi_sw_tcp_session_create (bsc#1210647).
- CVE-2023-32269: Fixed a use-after-free in af_netrom.c, related to the fact that accept() was also allowed for a successfully connected AF_NETROM socket (bsc#1211186).
- CVE-2023-1989: Fixed a use after free in btsdio_remove (bsc#1210336).
- CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).
- CVE-2023-1670: Fixed a use after free in the Xircom 16-bit PCMCIA Ethernet driver. A local user could use this flaw to crash the system or potentially escalate their privileges on the system (bsc#1209871).
- CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak (bsc#1209532).
- CVE-2023-28328: Fixed a denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c (bsc#1209291).
- CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).
- CVE-2018-9517: Fixed possible memory corruption due to a use after free in pppol2tp_connect (bsc#1108488).
- CVE-2023-1118: Fixed a use-after-free bugs caused by ene_tx_irqsim() in media/rc (bsc#1208837).
- CVE-2023-23559: Fixed integer overflow in rndis_wlan that leads to a buffer overflow (bsc#1207051).
- CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler (bsc#1207036).
- CVE-2023-23455: Fixed a denial of service inside atm_tc_enqueue in net/sched/sch_atm.c because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results) (bsc#1207125).
- CVE-2022-3567: Fixed a to race condition in inet6_stream_ops()/inet6_dgram_ops() (bsc#1204414).
The following non-security bugs were fixed:
- Do not sign the vanilla kernel (bsc#1209008).
- do not fallthrough in cbq_classify and stop on TC_ACT_SHOT
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4
zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2023-2506=1
-
SUSE Linux Enterprise Server 11 SP4
zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2023-2506=1
Package List:
-
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4 (nosrc x86_64)
- kernel-trace-3.0.101-108.141.1
- kernel-ec2-3.0.101-108.141.1
- kernel-xen-3.0.101-108.141.1
- kernel-default-3.0.101-108.141.1
-
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4 (x86_64)
- kernel-ec2-devel-3.0.101-108.141.1
- kernel-xen-base-3.0.101-108.141.1
- kernel-default-base-3.0.101-108.141.1
- kernel-default-devel-3.0.101-108.141.1
- kernel-ec2-base-3.0.101-108.141.1
- kernel-syms-3.0.101-108.141.1
- kernel-xen-devel-3.0.101-108.141.1
- kernel-source-3.0.101-108.141.1
- kernel-trace-base-3.0.101-108.141.1
- kernel-trace-devel-3.0.101-108.141.1
-
SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64)
- kernel-trace-3.0.101-108.141.1
- kernel-ec2-3.0.101-108.141.1
- kernel-xen-3.0.101-108.141.1
- kernel-default-3.0.101-108.141.1
-
SUSE Linux Enterprise Server 11 SP4 (x86_64)
- kernel-ec2-devel-3.0.101-108.141.1
- kernel-xen-base-3.0.101-108.141.1
- kernel-default-base-3.0.101-108.141.1
- kernel-default-devel-3.0.101-108.141.1
- kernel-ec2-base-3.0.101-108.141.1
- kernel-syms-3.0.101-108.141.1
- kernel-xen-devel-3.0.101-108.141.1
- kernel-source-3.0.101-108.141.1
- kernel-trace-base-3.0.101-108.141.1
- kernel-trace-devel-3.0.101-108.141.1
References:
- https://www.suse.com/security/cve/CVE-2017-5753.html
- https://www.suse.com/security/cve/CVE-2018-9517.html
- https://www.suse.com/security/cve/CVE-2022-3567.html
- https://www.suse.com/security/cve/CVE-2023-0590.html
- https://www.suse.com/security/cve/CVE-2023-1118.html
- https://www.suse.com/security/cve/CVE-2023-1513.html
- https://www.suse.com/security/cve/CVE-2023-1670.html
- https://www.suse.com/security/cve/CVE-2023-1989.html
- https://www.suse.com/security/cve/CVE-2023-2162.html
- https://www.suse.com/security/cve/CVE-2023-23454.html
- https://www.suse.com/security/cve/CVE-2023-23455.html
- https://www.suse.com/security/cve/CVE-2023-23559.html
- https://www.suse.com/security/cve/CVE-2023-28328.html
- https://www.suse.com/security/cve/CVE-2023-32269.html
- https://bugzilla.suse.com/show_bug.cgi?id=1108488
- https://bugzilla.suse.com/show_bug.cgi?id=1204414
- https://bugzilla.suse.com/show_bug.cgi?id=1207036
- https://bugzilla.suse.com/show_bug.cgi?id=1207051
- https://bugzilla.suse.com/show_bug.cgi?id=1207125
- https://bugzilla.suse.com/show_bug.cgi?id=1207795
- https://bugzilla.suse.com/show_bug.cgi?id=1208837
- https://bugzilla.suse.com/show_bug.cgi?id=1209008
- https://bugzilla.suse.com/show_bug.cgi?id=1209256
- https://bugzilla.suse.com/show_bug.cgi?id=1209291
- https://bugzilla.suse.com/show_bug.cgi?id=1209532
- https://bugzilla.suse.com/show_bug.cgi?id=1209871
- https://bugzilla.suse.com/show_bug.cgi?id=1210336
- https://bugzilla.suse.com/show_bug.cgi?id=1210647
- https://bugzilla.suse.com/show_bug.cgi?id=1211186