SUSE-SU-2023:4030-1

Advisory lineage Upstream: 13 Downstream: 0
Published: 10 Oct 2023, 12:14
Last modified:04 Feb 2026, 03:20

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Oct 2023, 12:14
Published
Vulnerability first disclosed
04 Feb 2026, 03:20
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP2 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2023-4389: Fixed a reference counting issue in the Btrfs filesystem that could be exploited in order to leak internal kernel information or crash the system (bsc#1214351). - CVE-2023-42753: Fixed an array indexing vulnerability in the netfilter subsystem. This issue may have allowed a local user to crash the system or potentially escalate their privileges (bsc#1215150). - CVE-2023-1206: Fixed a hash collision flaw in the IPv6 connection lookup table which could be exploited by network adjacent attackers, increasing CPU usage by 95% (bsc#1212703). - CVE-2023-4921: Fixed a use-after-free vulnerability in the QFQ network scheduler which could be exploited to achieve local privilege escalatio (bsc#1215275). - CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler (bsc#1207036). - CVE-2023-4622: Fixed a use-after-free vulnerability in the Unix domain sockets component which could be exploited to achieve local privilege escalation (bsc#1215117). - CVE-2023-4623: Fixed a use-after-free issue in the HFSC network scheduler which could be exploited to achieve local privilege escalation (bsc#1215115). - CVE-2020-36766: Fixed a potential information leak in in the CEC driver (bsc#1215299). - CVE-2023-1859: Fixed a use-after-free flaw in Xen transport for 9pfs which could be exploited to crash the system (bsc#1210169). - CVE-2023-2177: Fixed a null pointer dereference issue in the sctp network protocol which could allow a user to crash the system (bsc#1210643). - CVE-2023-4881: Fixed an out-of-bounds write flaw in the netfilter subsystem that could lead to information disclosure or denial of service (bsc#1215221). - CVE-2023-40283: Fixed a use-after-free issue in the Bluetooth subsystem (bsc#1214233). - CVE-2023-1192: Fixed a use-after-free in the CIFS subsystem (bsc#1208995). The following non-security bugs were fixed: - check-for-config-changes: ignore BUILTIN_RETURN_ADDRESS_STRIPS_PAC (bsc#1214380). - mkspec: Allow unsupported KMPs (bsc#1214386) - rpm/mkspec-dtb: support for nested subdirs. - x86/srso: Do not probe microcode in a guest (git-fixes). - x86/srso: Fix SBPB enablement for spec_rstack_overflow=off (git-fixes). - x86/srso: Fix srso_show_state() side effect (git-fixes). - x86/srso: Set CPUID feature bits independently of bug or mitigation status (git-fixes).

Affected Systems

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1.150200.9.83.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1.150200.9.83.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1.150200.9.83.1

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.2

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.2

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.2

  • susekernel-livepatch-SLE15-SP2_Update_41&distro=SUSE Linux Enterprise Live Patching 15 SP2

    < 1-150200.5.3.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-preempt&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-preempt&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-preempt&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15 SP2-LTSS

    < 5.3.18-150200.24.166.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP2

    < 5.3.18-150200.24.166.1

References (29)