SUSE-SU-2023:4665-1: important: Security update for kernel-firmware
null at suse.de
null at suse.de
Thu Dec 14 12:32:22 UTC 2023
# Security update for kernel-firmware
Announcement ID: SUSE-SU-2023:4665-1
Rating: important
References:
* bsc#1215823
* bsc#1215831
Cross-References:
* CVE-2021-26345
* CVE-2021-46766
* CVE-2021-46774
* CVE-2022-23820
* CVE-2022-23830
* CVE-2023-20519
* CVE-2023-20521
* CVE-2023-20526
* CVE-2023-20533
* CVE-2023-20566
* CVE-2023-20592
CVSS scores:
* CVE-2021-26345 ( SUSE ): 1.6 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
* CVE-2021-26345 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
* CVE-2021-46766 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
* CVE-2021-46766 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2021-46774 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L
* CVE-2021-46774 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2022-23820 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
* CVE-2022-23820 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2022-23830 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
* CVE-2022-23830 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
* CVE-2023-20519 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
* CVE-2023-20519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
* CVE-2023-20521 ( SUSE ): 3.3 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
* CVE-2023-20521 ( NVD ): 5.7 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2023-20526 ( SUSE ): 1.9 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
* CVE-2023-20526 ( NVD ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
* CVE-2023-20533 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H
* CVE-2023-20533 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2023-20566 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
* CVE-2023-20566 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2023-20592 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
* CVE-2023-20592 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Affected Products:
* SUSE CaaS Platform 4.0
* SUSE Linux Enterprise High Performance Computing 15 SP1
* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
* SUSE Linux Enterprise High Performance Computing 15 SP2
* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
* SUSE Linux Enterprise Server 15 SP1
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
* SUSE Linux Enterprise Server 15 SP2
* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
* SUSE Linux Enterprise Server for SAP Applications 15 SP1
* SUSE Linux Enterprise Server for SAP Applications 15 SP2
An update that solves 11 vulnerabilities can now be installed.
## Description:
This update for kernel-firmware fixes the following issues:
Update AMD ucode to 20231030 (bsc#1215831):
* CVE-2022-23820: Failure to validate the AMD SMM communication buffer may
allow an attacker to corrupt the SMRAM potentially leading to arbitrary code
execution.
* CVE-2021-46774: Insufficient input validation in ABL may enable a privileged
attacker to perform arbitrary DRAM writes, potentially resulting in code
execution and privilege escalation.
* CVE-2023-20533: Insufficient DRAM address validation in System Management
Unit (SMU) may allow an attacker using DMA to read/write from/to invalid
DRAM address potentially resulting in denial-of-service. 0 CVE-2023-20519: A
Use-After-Free vulnerability in the management of an SNP guest context page
may allow a malicious hypervisor to masquerade as the guest's migration
agent resulting in a potential loss of guest integrity.
* CVE-2023-20566: Improper address validation in ASP with SNP enabled may
potentially allow an attacker to compromise guest memory integrity.
* CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with
physical access to tamper with SPI ROM records after memory content
verification, potentially leading to loss of confidentiality or a denial of
service.
* CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader
may expose secret keys to a privileged attacker accessing ASP SRAM,
potentially leading to a loss of confidentiality.
* CVE-2022-23830: SMM configuration may not be immutable, as intended, when
SNP is enabled resulting in a potential limited loss of guest memory
integrity.
* CVE-2023-20526: Insufficient input validation in the ASP Bootloader may
enable a privileged attacker with physical access to expose the contents of
ASP memory potentially leading to a loss of confidentiality.
* CVE-2021-26345: Failure to validate the value in APCB may allow an attacker
with physical access to tamper with the APCB token to force an out-of-bounds
memory read potentially resulting in a denial of service.
* CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack
(bsc#1215823).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1
zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4665=1
* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2
zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4665=1
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1
zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4665=1
* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2
zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4665=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP1
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4665=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP2
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4665=1
* SUSE CaaS Platform 4.0
To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform
you if it detects new updates and let you then trigger updating of the complete
cluster in a controlled way.
## Package List:
* SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP1 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
* SUSE CaaS Platform 4.0 (noarch)
* kernel-firmware-20200107-150100.3.40.1
* ucode-amd-20200107-150100.3.40.1
## References:
* https://www.suse.com/security/cve/CVE-2021-26345.html
* https://www.suse.com/security/cve/CVE-2021-46766.html
* https://www.suse.com/security/cve/CVE-2021-46774.html
* https://www.suse.com/security/cve/CVE-2022-23820.html
* https://www.suse.com/security/cve/CVE-2022-23830.html
* https://www.suse.com/security/cve/CVE-2023-20519.html
* https://www.suse.com/security/cve/CVE-2023-20521.html
* https://www.suse.com/security/cve/CVE-2023-20526.html
* https://www.suse.com/security/cve/CVE-2023-20533.html
* https://www.suse.com/security/cve/CVE-2023-20566.html
* https://www.suse.com/security/cve/CVE-2023-20592.html
* https://bugzilla.suse.com/show_bug.cgi?id=1215823
* https://bugzilla.suse.com/show_bug.cgi?id=1215831
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20231214/aebee156/attachment.htm>
More information about the sle-security-updates
mailing list