[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2023:4414-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T14:53:31.930Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":36,"duplicates":37,"related":38,"reserved_at":9,"published_at":50,"modified_at":51,"state":9,"summary":52,"references_raw":54,"kevs":196,"epss":9,"epss_history":197,"metrics":198,"affected":199},"SUSE-SU-2023:4414-1","Security update for the Linux Kernel\n\nThe SUSE Linux Enterprise 15 SP5 Azure kernel was updated to receive various security and bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2023-3777: Fixed a use-after-free vulnerability in netfilter: nf_tables component can be exploited to achieve local privilege escalation. (bsc#1215095)\n- CVE-2023-46813: Fixed a local privilege escalation with user-space programs that have access to MMIO regions (bsc#1212649).\n- CVE-2023-31085: Fixed a divide-by-zero error in do_div(sz,mtd->erasesize) that could cause a local DoS. (bsc#1210778)\n- CVE-2023-45862: Fixed an issue in the ENE UB6250 reader driver whwere an object could potentially extend beyond the end of an allocation causing. (bsc#1216051)\n- CVE-2023-39193: Fixed an out of bounds read in the xtables subsystem (bsc#1215860).\n- CVE-2023-5178: Fixed an UAF in queue intialization setup.  (bsc#1215768)\n- CVE-2023-2163: Fixed an incorrect verifier pruning in BPF that could lead to unsafe code paths being incorrectly marked as safe, resulting in arbitrary read/write in kernel memory, lateral privilege escalation, and container escape. (bsc#1215518)\n- CVE-2023-34324: Fixed a possible deadlock in Linux kernel event handling. (bsc#1215745).\n- CVE-2023-39189: Fixed a flaw in the Netfilter subsystem that could allow a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure. (bsc#1216046)\n- CVE-2023-39191: Fixed a lack of validation of dynamic pointers within user-supplied eBPF programs that may have allowed an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code. (bsc#1215863)\n- CVE-2023-2860: Fixed an out-of-bounds read vulnerability in the processing of seg6 attributes. This flaw allowed a privileged local user to disclose sensitive information. (bsc#1211592)\n\nThe following non-security bugs were fixed:\n\n- 9p: virtio: make sure 'offs' is initialized in zc_request (git-fixes).\n- ACPI: irq: Fix incorrect return value in acpi_register_gsi() (git-fixes).\n- ACPI: resource: Skip IRQ override on ASUS ExpertBook B1402CBA (git-fixes).\n- ALSA: hda/realtek - ALC287 I2S speaker platform support (git-fixes).\n- ALSA: hda/realtek - ALC287 merge RTK codec with CS CS35L41 AMP (git-fixes).\n- ALSA: hda/realtek - Fixed ASUS platform headset Mic issue (git-fixes).\n- ALSA: hda/realtek - Fixed two speaker platform (git-fixes).\n- ALSA: hda/realtek: Add quirk for ASUS ROG GU603ZV (git-fixes).\n- ALSA: hda/realtek: Change model for Intel RVP board (git-fixes).\n- ALSA: hda/relatek: Enable Mute LED on HP Laptop 15s-fq5xxx (git-fixes).\n- ALSA: hda: Disable power save for solving pop issue on Lenovo ThinkCentre M70q (git-fixes).\n- ALSA: hda: intel-dsp-cfg: add LunarLake support (git-fixes).\n- ALSA: hda: intel-sdw-acpi: Use u8 type for link index (git-fixes).\n- ALSA: usb-audio: Fix microphone sound on Nexigo webcam (git-fixes).\n- ALSA: usb-audio: Fix microphone sound on Opencomm2 Headset (git-fixes).\n- ASoC: amd: yc: Fix non-functional mic on Lenovo 82YM (git-fixes).\n- ASoC: codecs: wcd938x-sdw: fix runtime PM imbalance on probe errors (git-fixes).\n- ASoC: codecs: wcd938x-sdw: fix use after free on driver unbind (git-fixes).\n- ASoC: codecs: wcd938x: drop bogus bind error handling (git-fixes).\n- ASoC: codecs: wcd938x: fix unbind tear down order (git-fixes).\n- ASoC: fsl: imx-pcm-rpmsg: Add SNDRV_PCM_INFO_BATCH flag (git-fixes).\n- ASoC: imx-rpmsg: Set ignore_pmdown_time for dai_link (git-fixes).\n- ASoC: pxa: fix a memory leak in probe() (git-fixes).\n- Bluetooth: Avoid redundant authentication (git-fixes).\n- Bluetooth: Fix a refcnt underflow problem for hci_conn (git-fixes).\n- Bluetooth: ISO: Fix handling of listen for unicast (git-fixes).\n- Bluetooth: Reject connection with the device which has same BD_ADDR (git-fixes).\n- Bluetooth: avoid memcmp() out of bounds warning (git-fixes).\n- Bluetooth: btusb: add shutdown function for QCA6174 (git-fixes).\n- Bluetooth: hci_codec: Fix leaking content of local_codecs (git-fixes).\n- Bluetooth: hci_event: Fix coding style (git-fixes).\n- Bluetooth: hci_event: Fix using memcmp when comparing keys (git-fixes).\n- Bluetooth: hci_event: Ignore NULL link key (git-fixes).\n- Bluetooth: hci_sock: Correctly bounds check and pad HCI_MON_NEW_INDEX name (git-fixes).\n- Bluetooth: hci_sock: fix slab oob read in create_monitor_event (git-fixes).\n- Bluetooth: vhci: Fix race when opening vhci device (git-fixes).\n- Documentation: qat: change kernel version (PED-6401).\n- Documentation: qat: rewrite description (PED-6401).\n- Drivers: hv: vmbus: Call hv_synic_free() if hv_synic_alloc() fails (git-fixes).\n- Drivers: hv: vmbus: Fix vmbus_wait_for_unload() to scan present CPUs (git-fixes).\n- Drop amdgpu patch causing spamming (bsc#1215523).\n- HID: holtek: fix slab-out-of-bounds Write in holtek_kbd_input_event (git-fixes).\n- HID: intel-ish-hid: ipc: Disable and reenable ACPI GPE bit (git-fixes).\n- HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect (git-fixes).\n- HID: multitouch: Add required quirk for Synaptics 0xcd7e device (git-fixes).\n- HID: sony: Fix a potential memory leak in sony_probe() (git-fixes).\n- HID: sony: remove duplicate NULL check before calling usb_free_urb() (git-fixes).\n- IB/mlx4: Fix the size of a buffer in add_port_entries() (git-fixes)\n- Input: goodix - ensure int GPIO is in input for gpio_count == 1 && gpio_int_idx == 0 case (git-fixes).\n- Input: powermate - fix use-after-free in powermate_config_complete (git-fixes).\n- Input: psmouse - fix fast_reconnect function for PS/2 mode (git-fixes).\n- Input: xpad - add PXN V900 support (git-fixes).\n- KVM: SVM: Do not kill SEV guest if SMAP erratum triggers in usermode (git-fixes).\n- KVM: SVM: INTERCEPT_RDTSCP is never intercepted anyway (git-fixes).\n- KVM: s390: fix gisa destroy operation might lead to cpu stalls (git-fixes bsc#1216512).\n- KVM: x86/mmu: Reconstruct shadow page root if the guest PDPTEs is changed (git-fixes).\n- KVM: x86: Fix clang -Wimplicit-fallthrough in do_host_cpuid() (git-fixes).\n- KVM: x86: Move open-coded CPUID leaf 0x80000021 EAX bit propagation code (bsc#1213772).\n- KVM: x86: Propagate the AMD Automatic IBRS feature to the guest (bsc#1213772).\n- KVM: x86: add support for CPUID leaf 0x80000021 (bsc#1213772).\n- KVM: x86: synthesize CPUID leaf 0x80000021h if useful (bsc#1213772).\n- KVM: x86: work around QEMU issue with synthetic CPUID leaves (git-fixes).\n- NFS: Fix O_DIRECT locking issues (bsc#1211162).\n- NFS: Fix a few more clear_bit() instances that need release semantics (bsc#1211162).\n- NFS: Fix a potential data corruption (bsc#1211162).\n- NFS: Fix a use after free in nfs_direct_join_group() (bsc#1211162).\n- NFS: Fix error handling for O_DIRECT write scheduling (bsc#1211162).\n- NFS: More O_DIRECT accounting fixes for error paths (bsc#1211162).\n- NFS: More fixes for nfs_direct_write_reschedule_io() (bsc#1211162).\n- NFS: Use the correct commit info in nfs_join_page_group() (bsc#1211162).\n- NFSD: Never call nfsd_file_gc() in foreground paths (bsc#1215545).\n- RDMA/cma: Fix truncation compilation warning in make_cma_ports (git-fixes)\n- RDMA/cma: Initialize ib_sa_multicast structure to 0 when join (git-fixes)\n- RDMA/core: Require admin capabilities to set system parameters (git-fixes)\n- RDMA/cxgb4: Check skb value for failure to allocate (git-fixes)\n- RDMA/mlx5: Fix NULL string error (git-fixes)\n- RDMA/mlx5: Fix mutex unlocking on error flow for steering anchor creation (git-fixes)\n- RDMA/siw: Fix connection failure handling (git-fixes)\n- RDMA/srp: Do not call scsi_done() from srp_abort() (git-fixes)\n- RDMA/uverbs: Fix typo of sizeof argument (git-fixes)\n- Revert 'pinctrl: avoid unsafe code pattern in find_pinctrl()' (git-fixes).\n- Revert 'tty: n_gsm: fix UAF in gsm_cleanup_mux' (git-fixes).\n- USB: serial: option: add Fibocom to DELL custom modem FM101R-GL (git-fixes).\n- USB: serial: option: add Telit LE910C4-WWX 0x1035 composition (git-fixes).\n- USB: serial: option: add entry for Sierra EM9191 with new firmware (git-fixes).\n- arm64/smmu: use TLBI ASID when invalidating entire range (bsc#1215921)\n- ata: libata-core: Do not register PM operations for SAS ports (git-fixes).\n- ata: libata-core: Fix ata_port_request_pm() locking (git-fixes).\n- ata: libata-core: Fix port and device removal (git-fixes).\n- ata: libata-sata: increase PMP SRST timeout to 10s (git-fixes).\n- ata: libata-scsi: ignore reserved bits for REPORT SUPPORTED OPERATION CODES (git-fixes).\n- blk-cgroup: Fix NULL deref caused by blkg_policy_data being installed before init (bsc#1216062).\n- blk-cgroup: support to track if policy is online (bsc#1216062).\n- bonding: Fix extraction of ports from the packet headers (bsc#1214754).\n- bonding: Return pointer to data after pull on skb (bsc#1214754).\n- bonding: do not assume skb mac_header is set (bsc#1214754).\n- bpf: Add copy_map_value_long to copy to remote percpu memory (git-fixes).\n- bpf: Add missing btf_put to register_btf_id_dtor_kfuncs (git-fixes).\n- bpf: Add override check to kprobe multi link attach (git-fixes).\n- bpf: Add zero_map_value to zero map value with special fields (git-fixes).\n- bpf: Cleanup check_refcount_ok (git-fixes).\n- bpf: Fix max stack depth check for async callbacks (git-fixes).\n- bpf: Fix offset calculation error in __copy_map_value and zero_map_value (git-fixes).\n- bpf: Fix ref_obj_id for dynptr data slices in verifier (git-fixes).\n- bpf: Fix resetting logic for unreferenced kptrs (git-fixes).\n- bpf: Fix subprog idx logic in check_max_stack_depth (git-fixes).\n- bpf: Gate dynptr API behind CAP_BPF (git-fixes).\n- bpf: Prevent decl_tag from being referenced in func_proto arg (git-fixes).\n- bpf: Repeat check_max_stack_depth for async callbacks (git-fixes).\n- bpf: Tighten ptr_to_btf_id checks (git-fixes).\n- bpf: fix precision propagation verbose logging (git-fixes).\n- bpf: prevent decl_tag from being referenced in func_proto (git-fixes).\n- bpf: propagate precision across all frames, not just the last one (git-fixes).\n- bpf: propagate precision in ALU/ALU64 operations (git-fixes).\n- btf: Export bpf_dynptr definition (git-fixes).\n- btrfs: do not start transaction for scrub if the fs is mounted read-only (bsc#1214874).\n- bus: ti-sysc: Fix missing AM35xx SoC matching (git-fixes).\n- bus: ti-sysc: Use fsleep() instead of usleep_range() in sysc_reset() (git-fixes).\n- ceph: add base64 endcoding routines for encrypted names (jsc#SES-1880).\n- ceph: add encryption support to writepage and writepages (jsc#SES-1880).\n- ceph: add fscrypt ioctls and ceph.fscrypt.auth vxattr (jsc#SES-1880).\n- ceph: add helpers for converting names for userland presentation (jsc#SES-1880).\n- ceph: add infrastructure for file encryption and decryption (jsc#SES-1880).\n- ceph: add new mount option to enable sparse reads (jsc#SES-1880).\n- ceph: add object version support for sync read (jsc#SES-1880).\n- ceph: add read/modify/write to ceph_sync_write (jsc#SES-1880).\n- ceph: add some fscrypt guardrails (jsc#SES-1880).\n- ceph: add support for encrypted snapshot names (jsc#SES-1880).\n- ceph: add support to readdir for encrypted names (jsc#SES-1880).\n- ceph: add truncate size handling support for fscrypt (jsc#SES-1880).\n- ceph: align data in pages in ceph_sync_write (jsc#SES-1880).\n- ceph: allow encrypting a directory while not having Ax caps (jsc#SES-1880).\n- ceph: create symlinks with encrypted and base64-encoded targets (jsc#SES-1880).\n- ceph: decode alternate_name in lease info (jsc#SES-1880).\n- ceph: do not use special DIO path for encrypted inodes (jsc#SES-1880).\n- ceph: drop messages from MDS when unmounting (jsc#SES-1880).\n- ceph: encode encrypted name in ceph_mdsc_build_path and dentry release (jsc#SES-1880).\n- ceph: fix incorrect revoked caps assert in ceph_fill_file_size() (bsc#1216322).\n- ceph: fix type promotion bug on 32bit systems (bsc#1216324).\n- ceph: fix updating i_truncate_pagecache_size for fscrypt (jsc#SES-1880).\n- ceph: fscrypt_auth handling for ceph (jsc#SES-1880).\n- ceph: handle fscrypt fields in cap messages from MDS (jsc#SES-1880).\n- ceph: implement -o test_dummy_encryption mount option (jsc#SES-1880).\n- ceph: invalidate pages when doing direct/sync writes (jsc#SES-1880).\n- ceph: make ceph_fill_trace and ceph_get_name decrypt names (jsc#SES-1880).\n- ceph: make ceph_msdc_build_path use ref-walk (jsc#SES-1880).\n- ceph: make d_revalidate call fscrypt revalidator for encrypted dentries (jsc#SES-1880).\n- ceph: make ioctl cmds more readable in debug log (jsc#SES-1880).\n- ceph: make num_fwd and num_retry to __u32 (jsc#SES-1880).\n- ceph: mark directory as non-complete after loading key (jsc#SES-1880).\n- ceph: pass the request to parse_reply_info_readdir() (jsc#SES-1880).\n- ceph: plumb in decryption during reads (jsc#SES-1880).\n- ceph: preallocate inode for ops that may create one (jsc#SES-1880).\n- ceph: prevent snapshot creation in encrypted locked directories (jsc#SES-1880).\n- ceph: remove unnecessary check for NULL in parse_longname() (bsc#1216333).\n- ceph: send alternate_name in MClientRequest (jsc#SES-1880).\n- ceph: set DCACHE_NOKEY_NAME flag in ceph_lookup/atomic_open() (jsc#SES-1880).\n- ceph: size handling in MClientRequest, cap updates and inode traces (jsc#SES-1880).\n- ceph: switch ceph_lookup/atomic_open() to use new fscrypt helper (jsc#SES-1880).\n- ceph: use osd_req_op_extent_osd_iter for netfs reads (jsc#SES-1880).\n- ceph: voluntarily drop Xx caps for requests those touch parent mtime (jsc#SES-1880).\n- ceph: wait for OSD requests' callbacks to finish when unmounting (jsc#SES-1880).\n- cgroup/cpuset: Change references of cpuset_mutex to cpuset_rwsem (bsc#1215955).\n- cgroup: Remove duplicates in cgroup v1 tasks file (bsc#1211307).\n- clk: tegra: fix error return case for recalc_rate (git-fixes).\n- counter: microchip-tcb-capture: Fix the use of internal GCLK logic (git-fixes).\n- crypto: qat - Include algapi.h for low-level Crypto API (PED-6401).\n- crypto: qat - Remove unused function declarations (PED-6401).\n- crypto: qat - add fw_counters debugfs file (PED-6401).\n- crypto: qat - add heartbeat counters check (PED-6401).\n- crypto: qat - add heartbeat feature (PED-6401).\n- crypto: qat - add internal timer for qat 4xxx (PED-6401).\n- crypto: qat - add measure clock frequency (PED-6401).\n- crypto: qat - add missing function declaration in adf_dbgfs.h (PED-6401).\n- crypto: qat - add qat_zlib_deflate (PED-6401).\n- crypto: qat - add support for 402xx devices (PED-6401).\n- crypto: qat - change value of default idle filter (PED-6401).\n- crypto: qat - delay sysfs initialization (PED-6401).\n- crypto: qat - do not export adf_init_admin_pm() (PED-6401).\n- crypto: qat - drop log level of msg in get_instance_node() (PED-6401).\n- crypto: qat - drop obsolete heartbeat interface (PED-6401).\n- crypto: qat - drop redundant adf_enable_aer() (PED-6401).\n- crypto: qat - expose pm_idle_enabled through sysfs (PED-6401).\n- crypto: qat - extend buffer list logic interface (PED-6401).\n- crypto: qat - extend configuration for 4xxx (PED-6401).\n- crypto: qat - fix apply custom thread-service mapping for dc service (PED-6401).\n- crypto: qat - fix concurrency issue when device state changes (PED-6401).\n- crypto: qat - fix crypto capability detection for 4xxx (PED-6401).\n- crypto: qat - fix spelling mistakes from 'bufer' to 'buffer' (PED-6401).\n- crypto: qat - make fw images name constant (PED-6401).\n- crypto: qat - make state machine functions static (PED-6401).\n- crypto: qat - move dbgfs init to separate file (PED-6401).\n- crypto: qat - move returns to default case (PED-6401).\n- crypto: qat - refactor device restart logic (PED-6401).\n- crypto: qat - refactor fw config logic for 4xxx (PED-6401).\n- crypto: qat - remove ADF_STATUS_PF_RUNNING flag from probe (PED-6401).\n- crypto: qat - replace state machine calls (PED-6401).\n- crypto: qat - replace the if statement with min() (PED-6401).\n- crypto: qat - set deprecated capabilities as reserved (PED-6401).\n- crypto: qat - unmap buffer before free for DH (PED-6401).\n- crypto: qat - unmap buffers before free for RSA (PED-6401).\n- crypto: qat - update slice mask for 4xxx devices (PED-6401).\n- crypto: qat - use kfree_sensitive instead of memset/kfree() (PED-6401).\n- dmaengine: idxd: use spin_lock_irqsave before wait_event_lock_irq (git-fixes).\n- dmaengine: mediatek: Fix deadlock caused by synchronize_irq() (git-fixes).\n- dmaengine: stm32-mdma: abort resume if no ongoing transfer (git-fixes).\n- drm/amd/display: Do not check registers, if using AUX BL control (git-fixes).\n- drm/amd/display: Do not set dpms_off for seamless boot (git-fixes).\n- drm/amd/pm: add unique_id for gc 11.0.3 (git-fixes).\n- drm/amd: Fix detection of _PR3 on the PCIe root port (git-fixes).\n- drm/amdgpu/nbio4.3: set proper rmmio_remap.reg_offset for SR-IOV (git-fixes).\n- drm/amdgpu/soc21: do not remap HDP registers for SR-IOV (git-fixes).\n- drm/amdgpu: Handle null atom context in VBIOS info ioctl (git-fixes).\n- drm/amdgpu: add missing NULL check (git-fixes).\n- drm/amdkfd: Flush TLB after unmapping for GFX v9.4.3 (git-fixes).\n- drm/amdkfd: Insert missing TLB flush on GFX10 and later (git-fixes).\n- drm/amdkfd: Use gpu_offset for user queue's wptr (git-fixes).\n- drm/atomic-helper: relax unregistered connector check (git-fixes).\n- drm/bridge: ti-sn65dsi83: Do not generate HFP/HBP/HSA and EOT packet (git-fixes).\n- drm/i915/gt: Fix reservation address in ggtt_reserve_guc_top (git-fixes).\n- drm/i915: Retry gtt fault when out of fence registers (git-fixes).\n- drm/mediatek: Correctly free sg_table in gem prime vmap (git-fixes).\n- drm/msm/dp: do not reinitialize phy unless retry during link training (git-fixes).\n- drm/msm/dpu: change _dpu_plane_calc_bw() to use u64 to avoid overflow (git-fixes).\n- drm/msm/dsi: fix irq_of_parse_and_map() error checking (git-fixes).\n- drm/msm/dsi: skip the wait for video mode done if not applicable (git-fixes).\n- drm/vmwgfx: fix typo of sizeof argument (git-fixes).\n- drm: panel-orientation-quirks: Add quirk for One Mix 2S (git-fixes).\n- firmware: arm_ffa: Do not set the memory region attributes for MEM_LEND (git-fixes).\n- firmware: imx-dsp: Fix an error handling path in imx_dsp_setup_channels() (git-fixes).\n- fprobe: Ensure running fprobe_exit_handler() finished before calling rethook_free() (git-fixes).\n- fscrypt: new helper function - fscrypt_prepare_lookup_partial() (jsc#SES-1880).\n- gpio: aspeed: fix the GPIO number passed to pinctrl_gpio_set_config() (git-fixes).\n- gpio: pmic-eic-sprd: Add can_sleep flag for PMIC EIC chip (git-fixes).\n- gpio: pxa: disable pinctrl calls for MMP_GPIO (git-fixes).\n- gpio: tb10x: Fix an error handling path in tb10x_gpio_probe() (git-fixes).\n- gpio: timberdale: Fix potential deadlock on &tgpio->lock (git-fixes).\n- gpio: vf610: set value before the direction to avoid a glitch (git-fixes).\n- gve: Do not fully free QPL pages on prefill errors (git-fixes).\n- i2c: i801: unregister tco_pdev in i801_probe() error path (git-fixes).\n- i2c: mux: Avoid potential false error message in i2c_mux_add_adapter (git-fixes).\n- i2c: mux: demux-pinctrl: check the return value of devm_kstrdup() (git-fixes).\n- i2c: mux: gpio: Add missing fwnode_handle_put() (git-fixes).\n- i2c: mux: gpio:�Replace custom acpi_get_local_address() (git-fixes).\n- i2c: npcm7xx: Fix callback completion ordering (git-fixes).\n- ieee802154: ca8210: Fix a potential UAF in ca8210_probe (git-fixes).\n- iio: pressure: bmp280: Fix NULL pointer exception (git-fixes).\n- iio: pressure: dps310: Adjust Timeout Settings (git-fixes).\n- iio: pressure: ms5611: ms5611_prom_is_valid false negative bug (git-fixes).\n- intel x86 platform vsec kABI workaround (bsc#1216202).\n- io_uring/fs: remove sqe->rw_flags checking from LINKAT (git-fixes).\n- io_uring/rw: defer fsnotify calls to task context (git-fixes).\n- io_uring/rw: ensure kiocb_end_write() is always called (git-fixes).\n- io_uring/rw: remove leftover debug statement (git-fixes).\n- io_uring: Replace 0-length array with flexible array (git-fixes).\n- io_uring: ensure REQ_F_ISREG is set async offload (git-fixes).\n- io_uring: fix fdinfo sqe offsets calculation (git-fixes).\n- io_uring: fix memory leak when removing provided buffers (git-fixes).\n- iommu/amd/io-pgtable: Implement map_pages io_pgtable_ops callback (bsc#1212423).\n- iommu/amd/io-pgtable: Implement unmap_pages io_pgtable_ops callback (bsc#1212423).\n- iommu/amd: Add map/unmap_pages() iommu_domain_ops callback support (bsc#1212423).\n- iommu/arm-smmu-v3: Fix soft lockup triggered by (bsc#1215921)\n- kABI: fix bpf Tighten-ptr_to_btf_id checks (git-fixes).\n- kabi: blkcg_policy_data fix KABI (bsc#1216062).\n- kabi: workaround for enum nft_trans_phase (bsc#1215104).\n- kprobes: Prohibit probing on CFI preamble symbol (git-fixes).\n- leds: Drop BUG_ON check for LED_COLOR_ID_MULTI (git-fixes).\n- libceph: add CEPH_OSD_OP_ASSERT_VER support (jsc#SES-1880).\n- libceph: add new iov_iter-based ceph_msg_data_type and ceph_osd_data_type (jsc#SES-1880).\n- libceph: add sparse read support to OSD client (jsc#SES-1880).\n- libceph: add sparse read support to msgr1 (jsc#SES-1880).\n- libceph: add spinlock around osd->o_requests (jsc#SES-1880).\n- libceph: allow ceph_osdc_new_request to accept a multi-op read (jsc#SES-1880).\n- libceph: define struct ceph_sparse_extent and add some helpers (jsc#SES-1880).\n- libceph: new sparse_read op, support sparse reads on msgr2 crc codepath (jsc#SES-1880).\n- libceph: support sparse reads on msgr2 secure codepath (jsc#SES-1880).\n- libceph: use kernel_connect() (bsc#1216323).\n- mm, memcg: reconsider kmem.limit_in_bytes deprecation (bsc#1208788 bsc#1213705).\n- mmc: core: Capture correct oemid-bits for eMMC cards (git-fixes).\n- mmc: core: sdio: hold retuning if sdio in 1-bit mode (git-fixes).\n- mmc: mtk-sd: Use readl_poll_timeout_atomic in msdc_reset_hw (git-fixes).\n- mtd: physmap-core: Restore map_rom fallback (git-fixes).\n- mtd: rawnand: arasan: Ensure program page operations are successful (git-fixes).\n- mtd: rawnand: marvell: Ensure program page operations are successful (git-fixes).\n- mtd: rawnand: pl353: Ensure program page operations are successful (git-fixes).\n- mtd: rawnand: qcom: Unmap the right resource upon probe failure (git-fixes).\n- mtd: spinand: micron: correct bitmask for ecc status (git-fixes).\n- net/sched: fix netdevice reference leaks in attach_default_qdiscs() (git-fixes).\n- net: mana: Fix TX CQE error handling (bsc#1215986).\n- net: mana: Fix oversized sge0 for GSO packets (bsc#1215986).\n- net: nfc: llcp: Add lock when modifying device list (git-fixes).\n- net: rfkill: gpio: prevent value glitch during probe (git-fixes).\n- net: sched: add barrier to fix packet stuck problem for lockless qdisc (bsc#1216345).\n- net: sched: fixed barrier to prevent skbuff sticking in qdisc backlog (bsc#1216345).\n- net: usb: dm9601: fix uninitialized variable use in dm9601_mdio_read (git-fixes).\n- net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg (git-fixes).\n- net: usb: smsc95xx: Fix an error code in smsc95xx_reset() (git-fixes).\n- net: use sk_is_tcp() in more places (git-fixes).\n- netfilter: nf_tables: add NFT_TRANS_PREPARE_ERROR to deal with bound set/chain (git-fixes).\n- netfilter: nf_tables: unbind non-anonymous set if rule construction fails (git-fixes).\n- nfc: nci: assert requested protocol is valid (git-fixes).\n- nfc: nci: fix possible NULL pointer dereference in send_acknowledge() (git-fixes).\n- nfs: only issue commit in DIO codepath if we have uncommitted data (bsc#1211162).\n- nilfs2: fix potential use after free in nilfs_gccache_submit_read_data() (git-fixes).\n- nvme-fc: Prevent null pointer dereference in nvme_fc_io_getuuid() (bsc#1214842).\n- phy: mapphone-mdm6600: Fix pinctrl_pm handling for sleep pins (git-fixes).\n- phy: mapphone-mdm6600: Fix runtime PM for remove (git-fixes).\n- phy: mapphone-mdm6600: Fix runtime disable on probe (git-fixes).\n- pinctrl: avoid unsafe code pattern in find_pinctrl() (git-fixes).\n- pinctrl: renesas: rzn1: Enable missing PINMUX (git-fixes).\n- platform/surface: platform_profile: Propagate error if profile registration fails (git-fixes).\n- platform/x86/intel/pmt: Ignore uninitialized entries (bsc#1216202).\n- platform/x86/intel/pmt: telemetry: Fix fixed region handling (bsc#1216202).\n- platform/x86/intel/vsec: Rework early hardware code (bsc#1216202).\n- platform/x86/intel: Fix 'rmmod pmt_telemetry' panic (bsc#1216202).\n- platform/x86/intel: Fix pmt_crashlog array reference (bsc#1216202).\n- platform/x86: asus-wmi: Change ASUS_WMI_BRN_DOWN code from 0x20 to 0x2e (git-fixes).\n- platform/x86: asus-wmi: Map 0x2a code, Ignore 0x2b and 0x2c events (git-fixes).\n- platform/x86: think-lmi: Fix reference leak (git-fixes).\n- platform/x86: touchscreen_dmi: Add info for the Positivo C4128B (git-fixes).\n- power: supply: ucs1002: fix error code in ucs1002_get_property() (git-fixes).\n- quota: Fix slow quotaoff (bsc#1216621).\n- r8152: check budget for r8152_poll() (git-fixes).\n- regmap: fix NULL deref on lookup (git-fixes).\n- regmap: rbtree: Fix wrong register marked as in-cache when creating new node (git-fixes).\n- remove unnecessary WARN_ON_ONCE() (bsc#1214823).\n- ring-buffer: Avoid softlockup in ring_buffer_resize() (git-fixes).\n- ring-buffer: Do not attempt to read past 'commit' (git-fixes).\n- ring-buffer: Fix bytes info in per_cpu buffer stats (git-fixes).\n- ring-buffer: Update 'shortest_full' in polling (git-fixes).\n- s390/cio: fix a memleak in css_alloc_subchannel (git-fixes bsc#1216510).\n- s390/pci: fix iommu bitmap allocation (git-fixes bsc#1216511).\n- sched/cpuset: Bring back cpuset_mutex (bsc#1215955).\n- sched/deadline,rt: Remove unused parameter from pick_next_[rt|dl]_entity() (git fixes (sched)).\n- sched/rt: Fix live lock between select_fallback_rq() and RT push (git fixes (sched)).\n- sched/rt: Fix sysctl_sched_rr_timeslice intial value (git fixes (sched)).\n- scsi: be2iscsi: Add length check when parsing nlattrs (git-fixes).\n- scsi: fcoe: Fix potential deadlock on &fip->ctlr_lock (git-fixes).\n- scsi: iscsi: Add length check for nlattr payload (git-fixes).\n- scsi: iscsi: Add strlen() check in iscsi_if_set{_host}_param() (git-fixes).\n- scsi: iscsi_tcp: restrict to TCP sockets (git-fixes).\n- scsi: mpi3mr: Propagate sense data for admin queue SCSI I/O (git-fixes).\n- scsi: mpt3sas: Perform additional retries if doorbell read returns 0 (git-fixes).\n- scsi: pm8001: Setup IRQs on resume (git-fixes).\n- scsi: qedf: Do not touch __user pointer in qedf_dbg_debug_cmd_read() directly (git-fixes).\n- scsi: qedf: Do not touch __user pointer in qedf_dbg_fp_int_cmd_read() directly (git-fixes).\n- scsi: qedf: Do not touch __user pointer in qedf_dbg_stop_io_on_error_cmd_read() directly (git-fixes).\n- scsi: qedi: Fix potential deadlock on &qedi_percpu->p_work_lock (git-fixes).\n- scsi: qla4xxx: Add length check when parsing nlattrs (git-fixes).\n- selftests/bpf: Add more tests for check_max_stack_depth bug (git-fixes).\n- selftests/bpf: Add reproducer for decl_tag in func_proto argument (git-fixes).\n- selftests/bpf: Add reproducer for decl_tag in func_proto return type (git-fixes).\n- selftests/bpf: Add selftest for check_stack_max_depth bug (git-fixes).\n- selftests/bpf: Clean up sys_nanosleep uses (git-fixes).\n- serial: 8250_port: Check IRQ data before use (git-fixes).\n- soc: imx8m: Enable OCOTP clock for imx8mm before reading registers (git-fixes).\n- spi: nxp-fspi: reset the FLSHxCR1 registers (git-fixes).\n- spi: stm32: add a delay before SPI disable (git-fixes).\n- spi: sun6i: fix race between DMA RX transfer completion and RX FIFO drain (git-fixes).\n- spi: sun6i: reduce DMA RX transfer width to single byte (git-fixes).\n- thunderbolt: Check that lane 1 is in CL0 before enabling lane bonding (git-fixes).\n- thunderbolt: Restart XDomain discovery handshake after failure (git-fixes).\n- thunderbolt: Workaround an IOMMU fault on certain systems with Intel Maple Ridge (git-fixes).\n- tracing: Have current_trace inc the trace array ref count (git-fixes).\n- tracing: Have event inject files inc the trace array ref count (git-fixes).\n- tracing: Have option files inc the trace array ref count (git-fixes).\n- tracing: Have tracing_max_latency inc the trace array ref count (git-fixes).\n- tracing: Increase trace array ref count on enable and filter files (git-fixes).\n- tracing: Make trace_marker{,_raw} stream-like (git-fixes).\n- usb: cdnsp: Fixes issue with dequeuing not queued requests (git-fixes).\n- usb: dwc3: Soft reset phy on probe for host (git-fixes).\n- usb: gadget: ncm: Handle decoding of multiple NTB's in unwrap call (git-fixes).\n- usb: gadget: udc-xilinx: replace memcpy with memcpy_toio (git-fixes).\n- usb: hub: Guard against accesses to uninitialized BOS descriptors (git-fixes).\n- usb: musb: Get the musb_qh poniter after musb_giveback (git-fixes).\n- usb: musb: Modify the 'HWVers' register address (git-fixes).\n- usb: typec: altmodes/displayport: Signal hpd low when exiting mode (git-fixes).\n- usb: typec: ucsi: Clear EVENT_PENDING bit if ucsi_send_command fails (git-fixes).\n- usb: xhci: xhci-ring: Use sysdev for mapping bounce buffer (git-fixes).\n- vmbus_testing: fix wrong python syntax for integer value comparison (git-fixes).\n- vringh: do not use vringh_kiov_advance() in vringh_iov_xfer() (git-fixes).\n- watchdog: iTCO_wdt: No need to stop the timer in probe (git-fixes).\n- watchdog: iTCO_wdt: Set NO_REBOOT if the watchdog is not already running (git-fixes).\n- wifi: cfg80211: Fix 6GHz scan configuration (git-fixes).\n- wifi: cfg80211: avoid leaking stack data into trace (git-fixes).\n- wifi: iwlwifi: Ensure ack flag is properly cleared (git-fixes).\n- wifi: iwlwifi: dbg_ini: fix structure packing (git-fixes).\n- wifi: iwlwifi: mvm: Fix a memory corruption issue (git-fixes).\n- wifi: mac80211: allow transmitting EAPOL frames with tainted key (git-fixes).\n- wifi: mt76: mt76x02: fix MT76x0 external LNA gain handling (git-fixes).\n- wifi: mwifiex: Fix oob check condition in mwifiex_process_rx_packet (git-fixes).\n- wifi: mwifiex: Fix tlv_buf_left calculation (git-fixes).\n- wifi: mwifiex: Sanity check tlv_len and tlv_bitmap_len (git-fixes).\n- x86/cpu, kvm: Add the NO_NESTED_DATA_BP feature (bsc#1213772).\n- x86/cpu, kvm: Add the Null Selector Clears Base feature (bsc#1213772).\n- x86/cpu, kvm: Add the SMM_CTL MSR not present feature (bsc#1213772).\n- x86/cpu, kvm: Move X86_FEATURE_LFENCE_RDTSC to its native leaf (bsc#1213772).\n- x86/cpu: Enable STIBP on AMD if Automatic IBRS is enabled (bsc#1213772).\n- x86/cpu: Support AMD Automatic IBRS (bsc#1213772).\n- x86/mm: Print the encryption features correctly when a paravisor is present (bsc#1206453).\n- x86/platform/uv: Use alternate source for socket to node data (bsc#1215696).\n- x86/sev: Check IOBM for IOIO exceptions from user-space (bsc#1212649).\n- x86/sev: Check for user-space IOIO pointing to kernel space (bsc#1212649).\n- x86/sev: Disable MMIO emulation from user mode (bsc#1212649).\n- x86/sev: Make enc_dec_hypercall() accept a size instead of npages (bsc#1214635).\n- xen-netback: use default TX queue size for vifs (git-fixes).\n- xhci: Keep interrupt disabled in initialization until host is running (git-fixes).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34],{"_key":15},"CVE-2023-2163",{"_key":17},"CVE-2023-2860",{"_key":19},"CVE-2023-31085",{"_key":21},"CVE-2023-34324",{"_key":23},"CVE-2023-3777",{"_key":25},"CVE-2023-39189",{"_key":27},"CVE-2023-39191",{"_key":29},"CVE-2023-39193",{"_key":31},"CVE-2023-45862",{"_key":33},"CVE-2023-46813",{"_key":35},"CVE-2023-5178",[],[],[39,40,41,42,43,44,45,46,47,48,49],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},"2023-11-10T17:12:52Z","2026-02-04T02:34:20.795701Z",{"cisa_kev":53,"cisa_ransomware":53,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[55,62,67,71,75,79,83,87,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,156,160,164,168,172,176,180,184,188,192],{"url":56,"sources":57,"tags":60},"https://www.suse.com/support/update/announcement/2023/suse-su-20234414-1/",[58,59],"osv_suse","osv_opensuse",[61],"Advisory",{"url":63,"sources":64,"tags":65},"https://bugzilla.suse.com/1208788",[58,59],[66],"REPORT",{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1211162",[58,59],[66],{"url":72,"sources":73,"tags":74},"https://bugzilla.suse.com/1211307",[58,59],[66],{"url":76,"sources":77,"tags":78},"https://bugzilla.suse.com/1212423",[58,59],[66],{"url":80,"sources":81,"tags":82},"https://bugzilla.suse.com/1213705",[58,59],[66],{"url":84,"sources":85,"tags":86},"https://bugzilla.suse.com/1213772",[58,59],[66],{"url":88,"sources":89,"tags":90},"https://bugzilla.suse.com/1214754",[58,59],[66],{"url":92,"sources":93,"tags":94},"https://bugzilla.suse.com/1214874",[58,59],[66],{"url":96,"sources":97,"tags":98},"https://bugzilla.suse.com/1215104",[58,59],[66],{"url":100,"sources":101,"tags":102},"https://bugzilla.suse.com/1215523",[58,59],[66],{"url":104,"sources":105,"tags":106},"https://bugzilla.suse.com/1215545",[58,59],[66],{"url":108,"sources":109,"tags":110},"https://bugzilla.suse.com/1215921",[58,59],[66],{"url":112,"sources":113,"tags":114},"https://bugzilla.suse.com/1215955",[58,59],[66],{"url":116,"sources":117,"tags":118},"https://bugzilla.suse.com/1215986",[58,59],[66],{"url":120,"sources":121,"tags":122},"https://bugzilla.suse.com/1216062",[58,59],[66],{"url":124,"sources":125,"tags":126},"https://bugzilla.suse.com/1216202",[58,59],[66],{"url":128,"sources":129,"tags":130},"https://bugzilla.suse.com/1216322",[58,59],[66],{"url":132,"sources":133,"tags":134},"https://bugzilla.suse.com/1216323",[58,59],[66],{"url":136,"sources":137,"tags":138},"https://bugzilla.suse.com/1216324",[58,59],[66],{"url":140,"sources":141,"tags":142},"https://bugzilla.suse.com/1216333",[58,59],[66],{"url":144,"sources":145,"tags":146},"https://bugzilla.suse.com/1216345",[58,59],[66],{"url":148,"sources":149,"tags":150},"https://bugzilla.suse.com/1216512",[58,59],[66],{"url":152,"sources":153,"tags":154},"https://www.suse.com/security/cve/CVE-2023-2163",[58,59],[155],"WEB",{"url":157,"sources":158,"tags":159},"https://www.suse.com/security/cve/CVE-2023-2860",[58,59],[155],{"url":161,"sources":162,"tags":163},"https://www.suse.com/security/cve/CVE-2023-31085",[58,59],[155],{"url":165,"sources":166,"tags":167},"https://www.suse.com/security/cve/CVE-2023-34324",[58,59],[155],{"url":169,"sources":170,"tags":171},"https://www.suse.com/security/cve/CVE-2023-3777",[58,59],[155],{"url":173,"sources":174,"tags":175},"https://www.suse.com/security/cve/CVE-2023-39189",[58,59],[155],{"url":177,"sources":178,"tags":179},"https://www.suse.com/security/cve/CVE-2023-39191",[58,59],[155],{"url":181,"sources":182,"tags":183},"https://www.suse.com/security/cve/CVE-2023-39193",[58,59],[155],{"url":185,"sources":186,"tags":187},"https://www.suse.com/security/cve/CVE-2023-45862",[58,59],[155],{"url":189,"sources":190,"tags":191},"https://www.suse.com/security/cve/CVE-2023-46813",[58,59],[155],{"url":193,"sources":194,"tags":195},"https://www.suse.com/security/cve/CVE-2023-5178",[58,59],[155],[],[],[],[200,213,218,223,229,233],{"ecosystem":201,"name":202,"vendor":203,"product":204,"cpe_part":9,"purl_type":205,"purl_namespace":203,"purl_name":204,"source":9,"versions":206},"openSUSE","kernel-azure","opensuse","kernel-azure&distro=openSUSE Leap 15.5","rpm",[207],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9},"lt5_14_21_150500_33_23_1",true,"ecosystem","5.14.21-150500.33.23.1","excluding",{"ecosystem":201,"name":214,"vendor":203,"product":215,"cpe_part":9,"purl_type":205,"purl_namespace":203,"purl_name":215,"source":9,"versions":216},"kernel-source-azure","kernel-source-azure&distro=openSUSE Leap 15.5",[217],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9},{"ecosystem":201,"name":219,"vendor":203,"product":220,"cpe_part":9,"purl_type":205,"purl_namespace":203,"purl_name":220,"source":9,"versions":221},"kernel-syms-azure","kernel-syms-azure&distro=openSUSE Leap 15.5",[222],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9},{"ecosystem":224,"name":202,"vendor":225,"product":226,"cpe_part":9,"purl_type":205,"purl_namespace":225,"purl_name":226,"source":9,"versions":227},"SUSE Linux Enterprise","suse","kernel-azure&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP5",[228],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9},{"ecosystem":224,"name":214,"vendor":225,"product":230,"cpe_part":9,"purl_type":205,"purl_namespace":225,"purl_name":230,"source":9,"versions":231},"kernel-source-azure&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP5",[232],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9},{"ecosystem":224,"name":219,"vendor":225,"product":234,"cpe_part":9,"purl_type":205,"purl_namespace":225,"purl_name":234,"source":9,"versions":235},"kernel-syms-azure&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP5",[236],{"version":208,"is_range":209,"range_type":210,"version_start":9,"version_start_type":9,"version_end":211,"version_end_type":212,"fixed_in":9}]