Описание
Security update for kernel-firmware
This update for kernel-firmware fixes the following issues:
Update AMD ucode to 20231030 (bsc#1215831):
- CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
- CVE-2021-46774: Insufficient input validation in ABL may enable a privileged attacker to perform arbitrary DRAM writes, potentially resulting in code execution and privilege escalation.
- CVE-2023-20533: Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker using DMA to read/write from/to invalid DRAM address potentially resulting in denial-of-service. 0 CVE-2023-20519: A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
- CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
- CVE-2023-20521: TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
- CVE-2021-46766: Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
- CVE-2022-23830: SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
- CVE-2023-20526: Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
- CVE-2021-26345: Failure to validate the value in APCB may allow an attacker with physical access to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
- CVE-2023-20592: Issue with INVD instruction aka CacheWarpAttack (bsc#1215823).
Список пакетов
Container rancher/elemental-teal-rt/5.4:latest
Container rancher/elemental-teal/5.4:latest
Container suse/sle-micro-rancher/5.3:latest
Container suse/sle-micro-rancher/5.4:latest
Image SLES15-SP4-SAP-Azure-LI-BYOS
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
Image SLES15-SP4-SAP-Azure-VLI-BYOS
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
SUSE Linux Enterprise Micro 5.3
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Module for Basesystem 15 SP4
openSUSE Leap 15.4
openSUSE Leap Micro 5.3
openSUSE Leap Micro 5.4
Ссылки
- Link for SUSE-SU-2023:4664-1
- E-Mail link for SUSE-SU-2023:4664-1
- SUSE Security Ratings
- SUSE Bug 1215823
- SUSE Bug 1215831
- SUSE CVE CVE-2021-26345 page
- SUSE CVE CVE-2021-46766 page
- SUSE CVE CVE-2021-46774 page
- SUSE CVE CVE-2022-23820 page
- SUSE CVE CVE-2022-23830 page
- SUSE CVE CVE-2023-20519 page
- SUSE CVE CVE-2023-20521 page
- SUSE CVE CVE-2023-20526 page
- SUSE CVE CVE-2023-20533 page
- SUSE CVE CVE-2023-20566 page
- SUSE CVE CVE-2023-20592 page
Описание
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
Затронутые продукты
Ссылки
- CVE-2021-26345
- SUSE Bug 1215831
Описание
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
Затронутые продукты
Ссылки
- CVE-2021-46766
- SUSE Bug 1215831
Описание
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
Затронутые продукты
Ссылки
- CVE-2021-46774
- SUSE Bug 1215831
Описание
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Затронутые продукты
Ссылки
- CVE-2022-23820
- SUSE Bug 1215831
- SUSE Bug 1217557
- SUSE Bug 1220057
- SUSE Bug 1220058
- SUSE Bug 1221588
Описание
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
Затронутые продукты
Ссылки
- CVE-2022-23830
- SUSE Bug 1215831
Описание
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
Затронутые продукты
Ссылки
- CVE-2023-20519
- SUSE Bug 1215831
Описание
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Затронутые продукты
Ссылки
- CVE-2023-20521
- SUSE Bug 1215831
Описание
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Затронутые продукты
Ссылки
- CVE-2023-20526
- SUSE Bug 1215831
Описание
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
Затронутые продукты
Ссылки
- CVE-2023-20533
- SUSE Bug 1215831
Описание
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
Затронутые продукты
Ссылки
- CVE-2023-20566
- SUSE Bug 1215831
Описание
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
Затронутые продукты
Ссылки
- CVE-2023-20592
- SUSE Bug 1215823