SUSE-SU-2023:2506-1: important: Security update for the Linux Kernel

sle-updates at lists.suse.com sle-updates at lists.suse.com
Wed Jun 14 08:30:23 UTC 2023



# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2023:2506-1  
Rating: important  
References:

  * #1108488
  * #1204414
  * #1207036
  * #1207051
  * #1207125
  * #1207795
  * #1208837
  * #1209008
  * #1209256
  * #1209291
  * #1209532
  * #1209871
  * #1210336
  * #1210647
  * #1211186

  
Cross-References:

  * CVE-2017-5753
  * CVE-2018-9517
  * CVE-2022-3567
  * CVE-2023-0590
  * CVE-2023-1118
  * CVE-2023-1513
  * CVE-2023-1670
  * CVE-2023-1989
  * CVE-2023-2162
  * CVE-2023-23454
  * CVE-2023-23455
  * CVE-2023-23559
  * CVE-2023-28328
  * CVE-2023-32269

  
CVSS scores:

  * CVE-2017-5753 ( SUSE ):  5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2017-5753 ( SUSE ):  7.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  * CVE-2017-5753 ( NVD ):  5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2017-5753 ( NVD ):  5.6 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
  * CVE-2018-9517 ( SUSE ):  2.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2018-9517 ( NVD ):  6.7 CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-3567 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-3567 ( NVD ):  4.6 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
  * CVE-2023-0590 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-0590 ( NVD ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-1118 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1118 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1513 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
  * CVE-2023-1513 ( NVD ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2023-1670 ( SUSE ):  4.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H
  * CVE-2023-1670 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1989 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1989 ( NVD ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2162 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2162 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  * CVE-2023-23454 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-23454 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-23455 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-23455 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-23559 ( SUSE ):  6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L
  * CVE-2023-23559 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-28328 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-28328 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-32269 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-32269 ( NVD ):  6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise Server 11 SP4
  * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4

  
  
An update that solves 14 vulnerabilities and has one fix can now be installed.

## Description:

The SUSE Linux Enterprise 11 SP4 LTSS EXTREME CORE kernel was updated to receive
various security and bugfixes.

The following security bugs were fixed:

  * CVE-2023-2162: Fixed an use-after-free flaw in iscsi_sw_tcp_session_create
    (bsc#1210647).
  * CVE-2023-32269: Fixed a use-after-free in af_netrom.c, related to the fact
    that accept() was also allowed for a successfully connected AF_NETROM socket
    (bsc#1211186).
  * CVE-2023-1989: Fixed a use after free in btsdio_remove (bsc#1210336).
  * CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).
  * CVE-2023-1670: Fixed a use after free in the Xircom 16-bit PCMCIA Ethernet
    driver. A local user could use this flaw to crash the system or potentially
    escalate their privileges on the system (bsc#1209871).
  * CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs
    structure that could be copied to userspace, causing an information leak
    (bsc#1209532).
  * CVE-2023-28328: Fixed a denial of service issue in az6027 driver in
    drivers/media/usb/dev-usb/az6027.c (bsc#1209291).
  * CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).
  * CVE-2018-9517: Fixed possible memory corruption due to a use after free in
    pppol2tp_connect (bsc#1108488).
  * CVE-2023-1118: Fixed a use-after-free bugs caused by ene_tx_irqsim() in
    media/rc (bsc#1208837).
  * CVE-2023-23559: Fixed integer overflow in rndis_wlan that leads to a buffer
    overflow (bsc#1207051).
  * CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler
    (bsc#1207036).
  * CVE-2023-23455: Fixed a denial of service inside atm_tc_enqueue in
    net/sched/sch_atm.c because of type confusion (non-negative numbers can
    sometimes indicate a TC_ACT_SHOT condition rather than valid classification
    results) (bsc#1207125).
  * CVE-2022-3567: Fixed a to race condition in
    inet6_stream_ops()/inet6_dgram_ops() (bsc#1204414).

The following non-security bugs were fixed:

  * Do not sign the vanilla kernel (bsc#1209008).
  * do not fallthrough in cbq_classify and stop on TC_ACT_SHOT

## Special Instructions and Notes:

  * Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4  
    zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2023-2506=1

  * SUSE Linux Enterprise Server 11 SP4  
    zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2023-2506=1

## Package List:

  * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4 (nosrc x86_64)
    * kernel-default-3.0.101-108.141.1
    * kernel-trace-3.0.101-108.141.1
    * kernel-xen-3.0.101-108.141.1
    * kernel-ec2-3.0.101-108.141.1
  * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE 11-SP4 (x86_64)
    * kernel-ec2-devel-3.0.101-108.141.1
    * kernel-trace-devel-3.0.101-108.141.1
    * kernel-xen-devel-3.0.101-108.141.1
    * kernel-syms-3.0.101-108.141.1
    * kernel-trace-base-3.0.101-108.141.1
    * kernel-xen-base-3.0.101-108.141.1
    * kernel-source-3.0.101-108.141.1
    * kernel-default-base-3.0.101-108.141.1
    * kernel-ec2-base-3.0.101-108.141.1
    * kernel-default-devel-3.0.101-108.141.1
  * SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64)
    * kernel-default-3.0.101-108.141.1
    * kernel-trace-3.0.101-108.141.1
    * kernel-xen-3.0.101-108.141.1
    * kernel-ec2-3.0.101-108.141.1
  * SUSE Linux Enterprise Server 11 SP4 (x86_64)
    * kernel-ec2-devel-3.0.101-108.141.1
    * kernel-trace-devel-3.0.101-108.141.1
    * kernel-xen-devel-3.0.101-108.141.1
    * kernel-syms-3.0.101-108.141.1
    * kernel-trace-base-3.0.101-108.141.1
    * kernel-xen-base-3.0.101-108.141.1
    * kernel-source-3.0.101-108.141.1
    * kernel-default-base-3.0.101-108.141.1
    * kernel-ec2-base-3.0.101-108.141.1
    * kernel-default-devel-3.0.101-108.141.1

## References:

  * https://www.suse.com/security/cve/CVE-2017-5753.html
  * https://www.suse.com/security/cve/CVE-2018-9517.html
  * https://www.suse.com/security/cve/CVE-2022-3567.html
  * https://www.suse.com/security/cve/CVE-2023-0590.html
  * https://www.suse.com/security/cve/CVE-2023-1118.html
  * https://www.suse.com/security/cve/CVE-2023-1513.html
  * https://www.suse.com/security/cve/CVE-2023-1670.html
  * https://www.suse.com/security/cve/CVE-2023-1989.html
  * https://www.suse.com/security/cve/CVE-2023-2162.html
  * https://www.suse.com/security/cve/CVE-2023-23454.html
  * https://www.suse.com/security/cve/CVE-2023-23455.html
  * https://www.suse.com/security/cve/CVE-2023-23559.html
  * https://www.suse.com/security/cve/CVE-2023-28328.html
  * https://www.suse.com/security/cve/CVE-2023-32269.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1108488
  * https://bugzilla.suse.com/show_bug.cgi?id=1204414
  * https://bugzilla.suse.com/show_bug.cgi?id=1207036
  * https://bugzilla.suse.com/show_bug.cgi?id=1207051
  * https://bugzilla.suse.com/show_bug.cgi?id=1207125
  * https://bugzilla.suse.com/show_bug.cgi?id=1207795
  * https://bugzilla.suse.com/show_bug.cgi?id=1208837
  * https://bugzilla.suse.com/show_bug.cgi?id=1209008
  * https://bugzilla.suse.com/show_bug.cgi?id=1209256
  * https://bugzilla.suse.com/show_bug.cgi?id=1209291
  * https://bugzilla.suse.com/show_bug.cgi?id=1209532
  * https://bugzilla.suse.com/show_bug.cgi?id=1209871
  * https://bugzilla.suse.com/show_bug.cgi?id=1210336
  * https://bugzilla.suse.com/show_bug.cgi?id=1210647
  * https://bugzilla.suse.com/show_bug.cgi?id=1211186

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20230614/a6429b16/attachment.htm>


More information about the sle-updates mailing list