{"schema_version":"1.7.3","id":"SUSE-SU-2023:1801-1","published":"2023-04-10T08:26:05Z","modified":"2026-02-04T04:40:30.217077Z","related":["CVE-2017-5753","CVE-2021-3923","CVE-2022-20567","CVE-2023-0590","CVE-2023-1076","CVE-2023-1095","CVE-2023-1281","CVE-2023-1390","CVE-2023-1513","CVE-2023-23454","CVE-2023-23455","CVE-2023-28328","CVE-2023-28464","CVE-2023-28772"],"upstream":["CVE-2017-5753","CVE-2021-3923","CVE-2022-20567","CVE-2023-0590","CVE-2023-1076","CVE-2023-1095","CVE-2023-1281","CVE-2023-1390","CVE-2023-1513","CVE-2023-23454","CVE-2023-23455","CVE-2023-28328","CVE-2023-28464","CVE-2023-28772"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2017-5753: Fixed spectre V1 vulnerability on netlink (bsc#1209547).\n- CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).\n- CVE-2021-3923: Fixed stack information leak vulnerability that could lead to kernel protection bypass in infiniband RDMA (bsc#1209778).\n- CVE-2022-20567: Fixed use after free that could lead to a local privilege escalation in pppol2tp_create of l2tp_ppp.c (bsc#1208850).\n- CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).\n- CVE-2023-1076: Fixed incorrect UID assigned to tun/tap sockets (bsc#1208599).\n- CVE-2023-1095: Fixed a NULL pointer dereference in nf_tables due to zeroed list head (bsc#1208777).\n- CVE-2023-1281: Fixed use after free that could lead to privilege escalation in tcindex (bsc#1209634).\n- CVE-2023-1390: Fixed remote DoS vulnerability in tipc_link_xmit() (bsc#1209289).\n- CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak (bsc#1209532).\n- CVE-2023-23454: Fixed a type-confusion in the CBQ network scheduler (bsc#1207036).\n- CVE-2023-23455: Fixed a denial of service inside atm_tc_enqueue in net/sched/sch_atm.c because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results) (bsc#1207125).\n- CVE-2023-28328: Fixed a denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c (bsc#1209291).\n- CVE-2023-28464: Fixed user-after-free that could lead to privilege escalation in hci_conn_cleanup in net/bluetooth/hci_conn.c (bsc#1209052).\n- CVE-2023-28772: Fixed buffer overflow in seq_buf_putmem_hex in lib/seq_buf.c (bsc#1209549).\n\nThe following non-security bugs were fixed:\n\n- ARM: 8702/1: head-common.S: Clear lr before jumping to start_kernel() (git-fixes)\n- Bluetooth: btusb: Add VID:PID 13d3:3529 for Realtek RTL8821CE (git-fixes).\n- Bluetooth: btusb: do not call kfree_skb() under spin_lock_irqsave() (git-fixes).\n- Input: atmel_mxt_ts - fix double free in mxt_read_info_block (git-fixes).\n- KVM: arm64: Hide system instruction access to Trace registers (git-fixes)\n- NFSv4: Fix hangs when recovering open state after a server reboot (git-fixes).\n- PCI/MSI: Enforce MSI entry updates to be visible (git-fixes).\n- PCI/MSI: Enforce that MSI-X table entry is masked for update (git-fixes).\n- PCI/MSI: Mask all unused MSI-X entries (git-fixes).\n- PCI/MSI: Skip masking MSI-X on Xen PV (git-fixes).\n- PCI/PM: Always return devices to D0 when thawing (git-fixes).\n- PCI/PM: Avoid using device_may_wakeup() for runtime PM (git-fixes).\n- PCI: Add ACS quirk for Intel Root Complex Integrated Endpoints (git-fixes).\n- PCI: Add ACS quirk for iProc PAXB (git-fixes).\n- PCI: Avoid FLR for AMD Matisse HD Audio & USB 3.0 (git-fixes).\n- PCI: Avoid FLR for AMD Starship USB 3.0 (git-fixes).\n- PCI: Make ACS quirk implementations more uniform (git-fixes).\n- PCI: PM: Avoid forcing PCI_D0 for wakeup reasons inconsistently (git-fixes).\n- PCI: PM: Avoid skipping bus-level PM on platforms without ACPI (git-fixes).\n- PCI: Unify ACS quirk desired vs provided checking (git-fixes).\n- PCI: Use pci_update_current_state() in pci_enable_device_flags() (git-fixes).\n- PCI: aardvark: Do not blindly enable ASPM L0s and do not write to read-only register (git-fixes).\n- PCI: aardvark: Do not rely on jiffies while holding spinlock (git-fixes).\n- PCI: aardvark: Do not touch PCIe registers if no card connected (git-fixes).\n- PCI: aardvark: Fix a leaked reference by adding missing of_node_put() (git-fixes).\n- PCI: aardvark: Fix checking for PIO Non-posted Request (git-fixes).\n- PCI: aardvark: Fix kernel panic during PIO transfer (git-fixes).\n- PCI: aardvark: Improve link training (git-fixes).\n- PCI: aardvark: Indicate error in 'val' when config read fails (git-fixes).\n- PCI: aardvark: Introduce an advk_pcie_valid_device() helper (git-fixes).\n- PCI: aardvark: Remove PCIe outbound window configuration (git-fixes).\n- PCI: aardvark: Train link immediately after enabling training (git-fixes).\n- PCI: aardvark: Wait for endpoint to be ready before training link (git-fixes).\n- PCI: endpoint: Cast the page number to phys_addr_t (git-fixes).\n- PCI: endpoint: Fix for concurrent memory allocation in OB address region (git-fixes).\n- PCI: hv: Add a per-bus mutex state_lock (bsc#1207001).\n- PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic (bsc#1207001).\n- PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev (bsc#1207001).\n- PCI: hv: fix a race condition bug in hv_pci_query_relations() (bsc#1207001).\n- PCI: qcom: Use PHY_REFCLK_USE_PAD only for ipq8064 (git-fixes).\n- PCI: tegra: Fix OF node reference leak (git-fixes).\n- PCI: xgene-msi: Fix race in installing chained irq handler (git-fixes).\n- PM: hibernate: flush swap writer after marking (git-fixes).\n- README.BRANCH: Adding myself to the maintainer list\n- Revert 'PCI: hv: Fix a timing issue which causes kdump to fail occasionally' (bsc#1207001).\n- Revert 'arm64: dts: juno: add dma-ranges property' (git-fixes)\n- Revert 'mei: me: enable asynchronous probing' (bsc#1208048, bsc#1209126).\n- SUNRPC: Fix a server shutdown leak (git-fixes).\n- applicom: Fix PCI device refcount leak in applicom_init() (git-fixes).\n- arm64/alternatives: do not patch up internal branches (git-fixes)\n- arm64/alternatives: move length validation inside the subsection (git-fixes)\n- arm64/alternatives: use subsections for replacement sequences (git-fixes)\n- arm64/cpufeature: Fix field sign for DIT hwcap detection (git-fixes)\n- arm64/mm: fix variable 'pud' set but not used (git-fixes)\n- arm64/mm: return cpu_all_mask when node is NUMA_NO_NODE (git-fixes)\n- arm64/vdso: Discard .note.gnu.property sections in vDSO (git-fixes)\n- arm64: Discard .note.GNU-stack section (bsc#1203693 bsc#1209798).\n- arm64: Do not forget syscall when starting a new thread. (git-fixes)\n- arm64: Fix compiler warning from pte_unmap() with (git-fixes)\n- arm64: Mark __stack_chk_guard as __ro_after_init (git-fixes)\n- arm64: Use test_tsk_thread_flag() for checking TIF_SINGLESTEP (git-fixes)\n- arm64: cmpxchg_double*: hazard against entire exchange variable (git-fixes)\n- arm64: cpu_ops: fix a leaked reference by adding missing of_node_put (git-fixes)\n- arm64: fix oops in concurrently setting insn_emulation sysctls (git-fixes)\n- arm64: kaslr: Reserve size of ARM64_MEMSTART_ALIGN in linear region (git-fixes)\n- arm64: kprobe: make page to RO mode when allocate it (git-fixes)\n- arm64: kpti: ensure patched kernel text is fetched from PoU (git-fixes)\n- arm64: psci: Avoid printing in cpu_psci_cpu_die() (git-fixes)\n- arm64: psci: Reduce the waiting time for cpu_psci_cpu_kill() (git-fixes)\n- arm64: unwind: Prohibit probing on return_address() (git-fixes)\n- crypto: arm64 - Fix unused variable compilation warnings of (git-fixes)\n- dt-bindings: reset: meson8b: fix duplicate reset IDs (git-fixes).\n- ftrace: Fix invalid address access in lookup_rec() when index is 0 (git-fixes).\n- ima: Fix function name error in comment (git-fixes).\n- ipv4: route: fix inet_rtm_getroute induced crash (git-fixes).\n- kabi: PCI: endpoint: Fix for concurrent memory allocation in OB address region (git-fixes).\n- kfifo: fix ternary sign extension bugs (git-fixes).\n- kgdb: Drop malformed kernel doc comment (git-fixes).\n- net: usb: lan78xx: Limit packet length to skb->len (git-fixes).\n- net: usb: qmi_wwan: Adding support for Cinterion MV31 (git-fixes).\n- net: usb: smsc75xx: Limit packet length to skb->len (git-fixes).\n- net: usb: smsc75xx: Move packet length check to prevent kernel panic in skb_pull (git-fixes).\n- net: usb: smsc95xx: Limit packet length to skb->len (git-fixes).\n- powerpc/btext: add missing of_node_put (bsc#1065729).\n- powerpc/powernv/ioda: Skip unallocated resources when mapping to PE (bsc#1065729).\n- powerpc/pseries/lpar: add missing RTAS retry status handling (bsc#1109158 ltc#169177 git-fixes).\n- powerpc/pseries/lparcfg: add missing RTAS retry status handling (bsc#1065729).\n- powerpc/rtas: ensure 4KB alignment for rtas_data_buf (bsc#1065729).\n- powerpc/xics: fix refcount leak in icp_opal_init() (bsc#1065729).\n- ppc64le: HWPOISON_INJECT=m (bsc#1209572).\n- ring-buffer: remove obsolete comment for free_buffer_page() (git-fixes).\n- s390/vfio-ap: fix memory leak in vfio_ap device driver (git-fixes).\n- sbitmap: Avoid lockups when waker gets preempted (bsc#1209118).\n- scsi: lpfc: Return DID_TRANSPORT_DISRUPTED instead of DID_REQUEUE (bsc#1199837).\n- scsi: qla2xxx: Synchronize the IOCB count to be in order (bsc#1209292 bsc#1209684 bsc#1209556).\n- timers/sched_clock: Prevent generic sched_clock wrap caused by tick_freeze() (git-fixes).\n- timers: Clear timer_base::must_forward_clk with (bsc#1207890)\n- tracing/hwlat: Replace sched_setaffinity with set_cpus_allowed_ptr (git-fixes).\n- tracing: Add NULL checks for buffer in ring_buffer_free_read_page() (git-fixes).\n- usb: chipidea: fix deadlock in ci_otg_del_timer (git-fixes).\n- usb: dwc3: exynos: Fix remove() function (git-fixes).\n- usb: dwc3: gadget: Stop processing more requests on IMI (git-fixes).\n- usb: misc: iowarrior: fix up header size for USB_DEVICE_ID_CODEMERCS_IOW100 (git-fixes).\n- usb: typec: altmodes/displayport: Fix probe pin assign check (git-fixes).\n- x86/PCI: Fix PCI IRQ routing table memory leak (git-fixes).\n- x86/apic: Add name to irq chip (bsc#1206010).\n- x86/apic: Deinline x2apic functions (bsc#1181001 jsc#ECO-3191).\n- x86/atomic: Fix smp_mb__{before,after}_atomic() (git-fixes).\n- x86/build: Add 'set -e' to mkcapflags.sh to delete broken capflags.c (git-fixes).\n- x86/ia32: Fix ia32_restore_sigcontext() AC leak (git-fixes).\n- x86/ioapic: Force affinity setup before startup (bsc#1193231).\n- x86/irq/64: Limit IST stack overflow check to #DB stack (git-fixes).\n- x86/mm: Remove in_nmi() warning from 64-bit implementation of vmalloc_fault() (git-fixes).\n- x86/paravirt: Fix callee-saved function ELF sizes (git-fixes).\n- x86/power: Fix 'nosmt' vs hibernation triple fault during resume (git-fixes).\n- x86/stacktrace: Prevent infinite loop in arch_stack_walk_user() (git-fixes).\n- x86/uaccess, signal: Fix AC=1 bloat (git-fixes).\n- x86/x2apic: Mark set_x2apic_phys_mode() as __init (bsc#1181001 jsc#ECO-3191).\n- x86/xen: Fix memory leak in xen_init_lock_cpu() (git-fixes).\n- x86/xen: Fix memory leak in xen_smp_intr_init{_pv}() (git-fixes).\n- xen-netfront: Fix NULL sring after live migration (git-fixes).\n- xen-netfront: Fix mismatched rtnl_unlock (git-fixes).\n- xen-netfront: Fix race between device setup and open (git-fixes).\n- xen-netfront: Update features after registering netdev (git-fixes).\n- xen-netfront: enable device after manual module load (git-fixes).\n- xen-netfront: fix potential deadlock in xennet_remove() (git-fixes).\n- xen-netfront: wait xenbus state change when load module manually (git-fixes).\n- xen/netfront: fix waiting for xenbus state change (git-fixes).\n- xen/netfront: stop tx queues during live migration (git-fixes).\n- xen/platform-pci: add missing free_irq() in error path (git-fixes).\n","affected":[{"package":{"name":"kernel-azure","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}},{"package":{"name":"kernel-source-azure","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}},{"package":{"name":"kernel-syms-azure","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}},{"package":{"name":"kernel-azure","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}},{"package":{"name":"kernel-source-azure","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/kernel-source-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}},{"package":{"name":"kernel-syms-azure","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/kernel-syms-azure&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-16.130.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-azure":"4.12.14-16.130.1","kernel-azure-base":"4.12.14-16.130.1","kernel-azure-devel":"4.12.14-16.130.1","kernel-devel-azure":"4.12.14-16.130.1","kernel-source-azure":"4.12.14-16.130.1","kernel-syms-azure":"4.12.14-16.130.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1801-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20231801-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1065729"},{"type":"REPORT","url":"https://bugzilla.suse.com/1076830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1109158"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199837"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203693"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207125"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207795"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207890"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208599"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208777"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209118"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209291"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209292"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209532"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209547"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209549"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209556"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209778"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209798"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-20567"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0590"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1390"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1513"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-23454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-23455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28772"}]}