Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0767-1

Опубликовано: 16 мар. 2023
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2023-26545: Fixed double free in net/mpls/af_mpls.c upon an allocation failure (bsc#1208700).
  • CVE-2023-23559: Fixed integer overflow in rndis_wlan that leads to a buffer overflow (bsc#1207051).
  • CVE-2022-38096: Fixed NULL-ptr deref in vmw_cmd_dx_define_query() (bsc#1203331).
  • CVE-2022-36280: Fixed out-of-bounds memory access vulnerability found in vmwgfx driver (bsc#1203332).
  • CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
kernel-default-4.4.121-92.202.5
kernel-default-base-4.4.121-92.202.5
kernel-default-devel-4.4.121-92.202.5
kernel-devel-4.4.121-92.202.6
kernel-macros-4.4.121-92.202.6
kernel-source-4.4.121-92.202.6
kernel-syms-4.4.121-92.202.6

Описание

An out-of-bounds(OOB) memory access vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_kms.c in GPU component in the Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-base-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-devel-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-devel-4.4.121-92.202.6

Ссылки

Описание

A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain privilege, causing a denial of service(DoS).


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-base-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-devel-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-devel-4.4.121-92.202.6

Ссылки

Описание

A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This flaw leads to a denial of service issue. If patch ebda44da44f6 ("net: sched: fix race condition in qdisc_graft()") not applied yet, then kernel could be affected.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-base-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-devel-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-devel-4.4.121-92.202.6

Ссылки

Описание

In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-base-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-devel-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-devel-4.4.121-92.202.6

Ссылки

Описание

In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-base-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-default-devel-4.4.121-92.202.5
SUSE Linux Enterprise Server 12 SP2-BCL:kernel-devel-4.4.121-92.202.6

Ссылки
Уязвимость SUSE-SU-2023:0767-1