SUSE-SU-2023:2611-1

    Dashboard / Vulnerabilities / SUSE-SU-2023:2611-1

    SUSE-SU-2023:2611-1

    Published: 22 Jun 2023Last Modified: 4 Feb 2026

    Summary: Security update for the Linux Kernel

    Details: The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2023-2156: Fixed a flaw in the networking subsystem within the handling of the RPL protocol (bsc#1211131). - CVE-2023-1637: Fixed vulnerability that could lead to unauthorized access to CPU memory after resuming CPU from suspend-to-RAM (bsc#1209779). - CVE-2022-3566: Fixed race condition in the TCP Handler (bsc#1204405). - CVE-2021-29650: Fixed an issue where the netfilter subsystem allowed attackers to cause a denial of service (bsc#1184208). - CVE-2020-36694: Fixed an use-after-free issue in netfilter in the packet processing context (bsc#1211596). - CVE-2023-1079: Fixed a use-after-free problem that could have been triggered in asus_kbd_backlight_set when plugging/disconnecting a malicious USB device (bsc#1208604). - CVE-2023-33288: Fixed a use-after-free in bq24190_remove in drivers/power/supply/bq24190_charger.c (bsc#1211590). - CVE-2022-45886: Fixed a .disconnect versus dvb_device_open race condition in dvb_net.c that lead to a use-after-free (bsc#1205760). - CVE-2022-45885: Fixed a race condition in dvb_frontend.c that could cause a use-after-free when a device is disconnected (bsc#1205758). - CVE-2022-45887: Fixed a memory leak in ttusb_dec.c caused by the lack of a dvb_frontend_detach call (bsc#1205762). - CVE-2022-45919: Fixed a use-after-free in dvb_ca_en50221.c that could occur if there is a disconnect after an open, because of the lack of a wait_event (bsc#1205803). - CVE-2022-45884: Fixed a use-after-free in dvbdev.c, related to dvb_register_device dynamically allocating fops (bsc#1205756). - CVE-2023-31084: Fixed a blocking issue in drivers/media/dvb-core/dvb_frontend.c (bsc#1210783). - CVE-2023-31436: Fixed an out-of-bounds write in qfq_change_class() because lmax can exceed QFQ_MIN_LMAX (bsc#1210940). - CVE-2023-2194: Fixed an out-of-bounds write vulnerability in the SLIMpro I2C device driver (bsc#1210715). - CVE-2023-32269: Fixed a use-after-free in af_netrom.c, related to the fact that accept() was also allowed for a successfully connected AF_NETROM socket (bsc#1211186). - CVE-2023-32233: Fixed a use-after-free in Netfilter nf_tables when processing batch requests (bsc#1211043). - CVE-2022-4269: Fixed a flaw was found inside the Traffic Control (TC) subsystem (bsc#1206024). - CVE-2023-1380: Fixed a slab-out-of-bound read problem in brcmf_get_assoc_ies() (bsc#1209287). - CVE-2023-2513: Fixed a use-after-free vulnerability in the ext4 filesystem (bsc#1211105). - CVE-2023-2483: Fixed a use after free bug in emac_remove caused by a race condition (bsc#1211037). - CVE-2023-23586: Fixed a memory information leak in the io_uring subsystem (bsc#1208474). The following non-security bugs were fixed: - SUNRPC: Ensure the transport backchannel association (bsc#1211203). - hv: vmbus: Optimize vmbus_on_event (bsc#1211622). - ipv6: sr: fix out-of-bounds read when setting HMAC data (bsc#1211592). - s390,dcssblk,dax: Add dax zero_page_range operation to dcssblk driver (bsc#1199636).

    References: https://www.suse.com/support/update/announcement/2023/suse-su-20232611-1/, https://bugzilla.suse.com/1184208, https://bugzilla.suse.com/1199636, https://bugzilla.suse.com/1204405, https://bugzilla.suse.com/1205756, https://bugzilla.suse.com/1205758, https://bugzilla.suse.com/1205760, https://bugzilla.suse.com/1205762, https://bugzilla.suse.com/1205803, https://bugzilla.suse.com/1206024, https://bugzilla.suse.com/1208474, https://bugzilla.suse.com/1208604, https://bugzilla.suse.com/1209287, https://bugzilla.suse.com/1209779, https://bugzilla.suse.com/1210715, https://bugzilla.suse.com/1210783, https://bugzilla.suse.com/1210940, https://bugzilla.suse.com/1211037, https://bugzilla.suse.com/1211043, https://bugzilla.suse.com/1211105, https://bugzilla.suse.com/1211131, https://bugzilla.suse.com/1211186, https://bugzilla.suse.com/1211203, https://bugzilla.suse.com/1211590, https://bugzilla.suse.com/1211592, https://bugzilla.suse.com/1211596, https://bugzilla.suse.com/1211622, https://www.suse.com/security/cve/CVE-2020-36694, https://www.suse.com/security/cve/CVE-2021-29650, https://www.suse.com/security/cve/CVE-2022-3566, https://www.suse.com/security/cve/CVE-2022-4269, https://www.suse.com/security/cve/CVE-2022-45884, https://www.suse.com/security/cve/CVE-2022-45885, https://www.suse.com/security/cve/CVE-2022-45886, https://www.suse.com/security/cve/CVE-2022-45887, https://www.suse.com/security/cve/CVE-2022-45919, https://www.suse.com/security/cve/CVE-2023-1079, https://www.suse.com/security/cve/CVE-2023-1380, https://www.suse.com/security/cve/CVE-2023-1637, https://www.suse.com/security/cve/CVE-2023-2156, https://www.suse.com/security/cve/CVE-2023-2194, https://www.suse.com/security/cve/CVE-2023-23586, https://www.suse.com/security/cve/CVE-2023-2483, https://www.suse.com/security/cve/CVE-2023-2513, https://www.suse.com/security/cve/CVE-2023-31084, https://www.suse.com/security/cve/CVE-2023-31436, https://www.suse.com/security/cve/CVE-2023-32233, https://www.suse.com/security/cve/CVE-2023-32269, https://www.suse.com/security/cve/CVE-2023-33288

    Affected packages

    Package

    Name: kernel-default

    Purl: pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.3.18-150300.59.124.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    SUSE-SU-2023:2611-1 | CVE-DB