SUSE-SU-2023:2537-1: important: Security update for the Linux Kernel

sle-updates at lists.suse.com sle-updates at lists.suse.com
Mon Jun 19 08:30:08 UTC 2023



# Security update for the Linux Kernel

Announcement ID: SUSE-SU-2023:2537-1  
Rating: important  
References:

  * #1204405
  * #1205756
  * #1205758
  * #1205760
  * #1205762
  * #1205803
  * #1206878
  * #1209287
  * #1210629
  * #1210715
  * #1210783
  * #1210940
  * #1211105
  * #1211186
  * #1211260
  * #1211592

  
Cross-References:

  * CVE-2022-3566
  * CVE-2022-45884
  * CVE-2022-45885
  * CVE-2022-45886
  * CVE-2022-45887
  * CVE-2022-45919
  * CVE-2023-1380
  * CVE-2023-2176
  * CVE-2023-2194
  * CVE-2023-2513
  * CVE-2023-31084
  * CVE-2023-31436
  * CVE-2023-32269

  
CVSS scores:

  * CVE-2022-3566 ( SUSE ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-3566 ( NVD ):  7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-45884 ( SUSE ):  4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-45884 ( NVD ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-45885 ( SUSE ):  4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-45885 ( NVD ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-45886 ( SUSE ):  4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-45886 ( NVD ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-45887 ( SUSE ):  4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-45887 ( NVD ):  4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2022-45919 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2022-45919 ( NVD ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-1380 ( SUSE ):  3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  * CVE-2023-1380 ( NVD ):  7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
  * CVE-2023-2176 ( SUSE ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2176 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2194 ( SUSE ):  6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
  * CVE-2023-2194 ( NVD ):  6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2513 ( SUSE ):  6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-2513 ( NVD ):  6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-31084 ( SUSE ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-31084 ( NVD ):  5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-31436 ( SUSE ):  7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-31436 ( NVD ):  7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2023-32269 ( SUSE ):  5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2023-32269 ( NVD ):  6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

  
Affected Products:

  * SUSE Linux Enterprise High Availability Extension 12 SP4
  * SUSE Linux Enterprise High Performance Computing 12 SP4
  * SUSE Linux Enterprise Live Patching 12-SP4
  * SUSE Linux Enterprise Server 12 SP4
  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4
  * SUSE Linux Enterprise Server for SAP Applications 12 SP4
  * SUSE OpenStack Cloud 9
  * SUSE OpenStack Cloud Crowbar 9

  
  
An update that solves 13 vulnerabilities and has three fixes can now be
installed.

## Description:

The SUSE Linux Enterprise 12 SP4 LTSS kernel was updated to receive various
security and bugfixes.

The following security bugs were fixed:

  * CVE-2022-3566: Fixed race condition in the TCP Handler (bsc#1204405).
  * CVE-2022-45886: Fixed a .disconnect versus dvb_device_open race condition in
    dvb_net.c that lead to a use-after-free (bsc#1205760).
  * CVE-2022-45885: Fixed a race condition in dvb_frontend.c that could cause a
    use-after-free when a device is disconnected (bsc#1205758).
  * CVE-2022-45887: Fixed a memory leak in ttusb_dec.c caused by the lack of a
    dvb_frontend_detach call (bsc#1205762).
  * CVE-2022-45919: Fixed a use-after-free in dvb_ca_en50221.c that could occur
    if there is a disconnect after an open, because of the lack of a wait_event
    (bsc#1205803).
  * CVE-2022-45884: Fixed a use-after-free in dvbdev.c, related to
    dvb_register_device dynamically allocating fops (bsc#1205756).
  * CVE-2023-31084: Fixed a blocking issue in drivers/media/dvb-
    core/dvb_frontend.c (bsc#1210783).
  * CVE-2023-31436: Fixed an out-of-bounds write in qfq_change_class() because
    lmax can exceed QFQ_MIN_LMAX (bsc#1210940 bsc#1211260).
  * CVE-2023-2194: Fixed an out-of-bounds write vulnerability in the SLIMpro I2C
    device driver (bsc#1210715).
  * CVE-2023-32269: Fixed a use-after-free in af_netrom.c, related to the fact
    that accept() was also allowed for a successfully connected AF_NETROM socket
    (bsc#1211186).
  * CVE-2023-1380: A slab-out-of-bound read problem was fixed in
    brcmf_get_assoc_ies(), that could lead to a denial of service (bsc#1209287).
  * CVE-2023-2513: A use-after-free vulnerability was fixed in the ext4
    filesystem, related to the way it handled the extra inode size for extended
    attributes (bsc#1211105).
  * CVE-2023-2176: A vulnerability was found in compare_netdev_and_ip in
    drivers/infiniband/core/cma.c in RDMA. The improper cleanup results in out-
    of-boundary read, where a local user can utilize this problem to crash the
    system or escalation of privilege (bsc#1210629).

The following non-security bugs were fixed:

  * ext4: add EXT4_INODE_HAS_XATTR_SPACE macro in xattr.h (bsc#1206878).
  * ipv6: sr: fix out-of-bounds read when setting HMAC data (bsc#1211592).

## Special Instructions and Notes:

  * Please reboot the system after installing this update.

## Patch Instructions:

To install this SUSE Important update use the SUSE recommended installation
methods like YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP Applications 12 SP4  
    zypper in -t patch SUSE-SLE-SAP-12-SP4-2023-2537=1 SUSE-SLE-
HA-12-SP4-2023-2537=1

  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4  
    zypper in -t patch SUSE-SLE-SERVER-12-SP4-ESPOS-2023-2537=1

  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4  
    zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2023-2537=1

  * SUSE OpenStack Cloud 9  
    zypper in -t patch SUSE-OpenStack-Cloud-9-2023-2537=1

  * SUSE OpenStack Cloud Crowbar 9  
    zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2023-2537=1

  * SUSE Linux Enterprise High Availability Extension 12 SP4  
    zypper in -t patch SUSE-SLE-HA-12-SP4-2023-2537=1

  * SUSE Linux Enterprise Live Patching 12-SP4  
    zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2023-2537=1

## Package List:

  * SUSE Linux Enterprise Server for SAP Applications 12 SP4 (nosrc ppc64le
    x86_64)
    * kernel-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP4 (ppc64le x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * cluster-md-kmp-default-4.12.14-95.128.1
    * gfs2-kmp-default-debuginfo-4.12.14-95.128.1
    * kernel-default-base-4.12.14-95.128.1
    * cluster-md-kmp-default-debuginfo-4.12.14-95.128.1
    * kernel-default-devel-4.12.14-95.128.1
    * dlm-kmp-default-4.12.14-95.128.1
    * dlm-kmp-default-debuginfo-4.12.14-95.128.1
    * ocfs2-kmp-default-debuginfo-4.12.14-95.128.1
    * gfs2-kmp-default-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * kernel-default-base-debuginfo-4.12.14-95.128.1
    * kernel-syms-4.12.14-95.128.1
    * ocfs2-kmp-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP4 (noarch)
    * kernel-source-4.12.14-95.128.1
    * kernel-macros-4.12.14-95.128.1
    * kernel-devel-4.12.14-95.128.1
  * SUSE Linux Enterprise Server for SAP Applications 12 SP4 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (aarch64 nosrc x86_64)
    * kernel-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (aarch64 x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * kernel-default-base-4.12.14-95.128.1
    * kernel-default-devel-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * kernel-default-base-debuginfo-4.12.14-95.128.1
    * kernel-syms-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (noarch)
    * kernel-source-4.12.14-95.128.1
    * kernel-macros-4.12.14-95.128.1
    * kernel-devel-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (aarch64 ppc64le s390x
    x86_64 nosrc)
    * kernel-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (aarch64 ppc64le s390x
    x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * kernel-default-base-4.12.14-95.128.1
    * kernel-default-devel-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * kernel-default-base-debuginfo-4.12.14-95.128.1
    * kernel-syms-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (noarch)
    * kernel-source-4.12.14-95.128.1
    * kernel-macros-4.12.14-95.128.1
    * kernel-devel-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (s390x)
    * kernel-default-man-4.12.14-95.128.1
  * SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (x86_64)
    * kernel-default-devel-debuginfo-4.12.14-95.128.1
  * SUSE OpenStack Cloud 9 (nosrc x86_64)
    * kernel-default-4.12.14-95.128.1
  * SUSE OpenStack Cloud 9 (x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * kernel-default-base-4.12.14-95.128.1
    * kernel-default-devel-4.12.14-95.128.1
    * kernel-default-devel-debuginfo-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * kernel-default-base-debuginfo-4.12.14-95.128.1
    * kernel-syms-4.12.14-95.128.1
  * SUSE OpenStack Cloud 9 (noarch)
    * kernel-source-4.12.14-95.128.1
    * kernel-macros-4.12.14-95.128.1
    * kernel-devel-4.12.14-95.128.1
  * SUSE OpenStack Cloud Crowbar 9 (nosrc x86_64)
    * kernel-default-4.12.14-95.128.1
  * SUSE OpenStack Cloud Crowbar 9 (x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * kernel-default-base-4.12.14-95.128.1
    * kernel-default-devel-4.12.14-95.128.1
    * kernel-default-devel-debuginfo-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * kernel-default-base-debuginfo-4.12.14-95.128.1
    * kernel-syms-4.12.14-95.128.1
  * SUSE OpenStack Cloud Crowbar 9 (noarch)
    * kernel-source-4.12.14-95.128.1
    * kernel-macros-4.12.14-95.128.1
    * kernel-devel-4.12.14-95.128.1
  * SUSE Linux Enterprise High Availability Extension 12 SP4 (ppc64le s390x
    x86_64)
    * kernel-default-debuginfo-4.12.14-95.128.1
    * cluster-md-kmp-default-4.12.14-95.128.1
    * gfs2-kmp-default-debuginfo-4.12.14-95.128.1
    * cluster-md-kmp-default-debuginfo-4.12.14-95.128.1
    * dlm-kmp-default-4.12.14-95.128.1
    * ocfs2-kmp-default-debuginfo-4.12.14-95.128.1
    * gfs2-kmp-default-4.12.14-95.128.1
    * kernel-default-debugsource-4.12.14-95.128.1
    * dlm-kmp-default-debuginfo-4.12.14-95.128.1
    * ocfs2-kmp-default-4.12.14-95.128.1
  * SUSE Linux Enterprise High Availability Extension 12 SP4 (nosrc)
    * kernel-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Live Patching 12-SP4 (nosrc)
    * kernel-default-4.12.14-95.128.1
  * SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le s390x x86_64)
    * kernel-default-kgraft-devel-4.12.14-95.128.1
    * kgraft-patch-4_12_14-95_128-default-1-6.3.1
    * kernel-default-kgraft-4.12.14-95.128.1

## References:

  * https://www.suse.com/security/cve/CVE-2022-3566.html
  * https://www.suse.com/security/cve/CVE-2022-45884.html
  * https://www.suse.com/security/cve/CVE-2022-45885.html
  * https://www.suse.com/security/cve/CVE-2022-45886.html
  * https://www.suse.com/security/cve/CVE-2022-45887.html
  * https://www.suse.com/security/cve/CVE-2022-45919.html
  * https://www.suse.com/security/cve/CVE-2023-1380.html
  * https://www.suse.com/security/cve/CVE-2023-2176.html
  * https://www.suse.com/security/cve/CVE-2023-2194.html
  * https://www.suse.com/security/cve/CVE-2023-2513.html
  * https://www.suse.com/security/cve/CVE-2023-31084.html
  * https://www.suse.com/security/cve/CVE-2023-31436.html
  * https://www.suse.com/security/cve/CVE-2023-32269.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1204405
  * https://bugzilla.suse.com/show_bug.cgi?id=1205756
  * https://bugzilla.suse.com/show_bug.cgi?id=1205758
  * https://bugzilla.suse.com/show_bug.cgi?id=1205760
  * https://bugzilla.suse.com/show_bug.cgi?id=1205762
  * https://bugzilla.suse.com/show_bug.cgi?id=1205803
  * https://bugzilla.suse.com/show_bug.cgi?id=1206878
  * https://bugzilla.suse.com/show_bug.cgi?id=1209287
  * https://bugzilla.suse.com/show_bug.cgi?id=1210629
  * https://bugzilla.suse.com/show_bug.cgi?id=1210715
  * https://bugzilla.suse.com/show_bug.cgi?id=1210783
  * https://bugzilla.suse.com/show_bug.cgi?id=1210940
  * https://bugzilla.suse.com/show_bug.cgi?id=1211105
  * https://bugzilla.suse.com/show_bug.cgi?id=1211186
  * https://bugzilla.suse.com/show_bug.cgi?id=1211260
  * https://bugzilla.suse.com/show_bug.cgi?id=1211592

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-updates/attachments/20230619/12d2a28d/attachment.htm>


More information about the sle-updates mailing list