SUSE-SU-2023:4733-1
Vulnerability Summary
Timeline
Description
Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976). - CVE-2023-6176: Fixed a denial of service in the cryptographic algorithm scatterwalk functionality (bsc#1217332). - CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058). - CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may not be adequate for frames larger than the MTU (bsc#1216259). - CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965). - CVE-2023-31083: Fixed race condition in hci_uart_tty_ioctl (bsc#1210780). - CVE-2023-5717: Fixed a heap out-of-bounds write vulnerability in the Performance Events component (bsc#1216584). The following non-security bugs were fixed: - ALSA: hda: Disable power-save on KONTRON SinglePC (bsc#1217140). - Call flush_delayed_fput() from nfsd main-loop (bsc#1217408). - net: mana: Configure hwc timeout from hardware (bsc#1214037). - net: mana: Fix MANA VF unload when hardware is unresponsive (bsc#1214764). - powerpc: Do not clobber f0/vs0 during fp|altivec register save (bsc#1217780).
Affected Systems
- suse•kernel-rt&distro=SUSE Linux Enterprise Micro 5.1
< 5.3.18-150300.152.1
- suse•kernel-rt&distro=SUSE Linux Enterprise Micro 5.2
< 5.3.18-150300.152.1
References (23)
- https://www.suse.com/support/update/announcement/2023/suse-su-20234733-1/
- https://bugzilla.suse.com/1084909
- https://bugzilla.suse.com/1210780
- https://bugzilla.suse.com/1214037
- https://bugzilla.suse.com/1214344
- https://bugzilla.suse.com/1214764
- https://bugzilla.suse.com/1215371
- https://bugzilla.suse.com/1216058
- https://bugzilla.suse.com/1216259
- https://bugzilla.suse.com/1216584
- https://bugzilla.suse.com/1216965
- https://bugzilla.suse.com/1216976
- https://bugzilla.suse.com/1217140
- https://bugzilla.suse.com/1217332
- https://bugzilla.suse.com/1217408
- https://bugzilla.suse.com/1217780
- https://www.suse.com/security/cve/CVE-2023-31083
- https://www.suse.com/security/cve/CVE-2023-39197
- https://www.suse.com/security/cve/CVE-2023-39198
- https://www.suse.com/security/cve/CVE-2023-45863
- https://www.suse.com/security/cve/CVE-2023-45871
- https://www.suse.com/security/cve/CVE-2023-5717
- https://www.suse.com/security/cve/CVE-2023-6176