{"schema_version":"1.7.3","id":"SUSE-SU-2023:1892-1","published":"2023-07-06T01:58:50Z","modified":"2025-05-02T04:29:47.990815Z","related":["CVE-2017-5753","CVE-2021-3923","CVE-2022-4744","CVE-2023-0394","CVE-2023-0461","CVE-2023-1075","CVE-2023-1078","CVE-2023-1281","CVE-2023-1382","CVE-2023-1390","CVE-2023-1513","CVE-2023-1582","CVE-2023-28327","CVE-2023-28328","CVE-2023-28464","CVE-2023-28466","CVE-2023-28772"],"upstream":["CVE-2017-5753","CVE-2021-3923","CVE-2022-4744","CVE-2023-0394","CVE-2023-0461","CVE-2023-1075","CVE-2023-1078","CVE-2023-1281","CVE-2023-1382","CVE-2023-1390","CVE-2023-1513","CVE-2023-1582","CVE-2023-28327","CVE-2023-28328","CVE-2023-28464","CVE-2023-28466","CVE-2023-28772"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security and bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208787).\n- CVE-2023-28772: Fixed buffer overflow in seq_buf_putmem_hex in lib/seq_buf.c (bsc#1209549).\n- CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak (bsc#1209532).\n- CVE-2023-28464: Fixed use-after-free that could lead to privilege escalation in hci_conn_cleanup in net/bluetooth/hci_conn.c (bsc#1209052).\n- CVE-2023-0394: Fixed a null pointer dereference flaw in the network subcomponent in the Linux kernel which could lead to system crash (bsc#1207168).\n- CVE-2023-28466: Fixed race condition that could lead to use-after-free or NULL pointer dereference in do_tls_getsockopt in net/tls/tls_main.c (bsc#1209366).\n- CVE-2021-3923: Fixed stack information leak vulnerability that could lead to kernel protection bypass in infiniband RDMA (bsc#1209778).\n- CVE-2023-1390: Fixed remote DoS vulnerability in tipc_link_xmit() (bsc#1209289).\n- CVE-2022-4744: Fixed double-free that could lead to DoS or privilege escalation in TUN/TAP device driver functionality (bsc#1209635).\n- CVE-2023-1281: Fixed use after free that could lead to privilege escalation in tcindex (bsc#1209634).\n- CVE-2023-1582: Fixed soft lockup in __page_mapcount (bsc#1209636).\n- CVE-2023-28327: Fixed DoS in in_skb in unix_diag_get_exact() (bsc#1209290).\n- CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).\n- CVE-2023-1382: Fixed denial of service in tipc_conn_close (bsc#1209288).\n- CVE-2023-28328: Fixed a denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c (bsc#1209291).\n- CVE-2023-1078: Fixed a heap out-of-bounds write in rds_rm_zerocopy_callback (bsc#1208601).\n- CVE-2023-1075: Fixed a type confusion in tls_is_tx_ready (bsc#1208598).\n- CVE-2017-5753: Fixed spectre V1 vulnerability on netlink (bsc#1209547).\n\nThe following non-security bugs were fixed:\n\n- ipv6: raw: Deduct extension header length in rawv6_push_pending_frames (bsc#1207168).\n- net: ena: optimize data access in fast-path code (bsc#1208137).\n- PCI: hv: Add a per-bus mutex state_lock (bsc#1209785).\n- PCI: hv: fix a race condition bug in hv_pci_query_relations() (bsc#1209785).\n- PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic (bsc#1209785).\n- PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev (bsc#1209785).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP3","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-150300.124.1","dlm-kmp-rt":"5.3.18-150300.124.1","gfs2-kmp-rt":"5.3.18-150300.124.1","kernel-devel-rt":"5.3.18-150300.124.1","kernel-rt":"5.3.18-150300.124.1","kernel-rt-devel":"5.3.18-150300.124.1","kernel-rt_debug-devel":"5.3.18-150300.124.1","kernel-source-rt":"5.3.18-150300.124.1","kernel-syms-rt":"5.3.18-150300.124.1","ocfs2-kmp-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}},{"package":{"name":"kernel-rt_debug","ecosystem":"SUSE:Real Time Module 15 SP3","purl":"pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-150300.124.1","dlm-kmp-rt":"5.3.18-150300.124.1","gfs2-kmp-rt":"5.3.18-150300.124.1","kernel-devel-rt":"5.3.18-150300.124.1","kernel-rt":"5.3.18-150300.124.1","kernel-rt-devel":"5.3.18-150300.124.1","kernel-rt_debug-devel":"5.3.18-150300.124.1","kernel-source-rt":"5.3.18-150300.124.1","kernel-syms-rt":"5.3.18-150300.124.1","ocfs2-kmp-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP3","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-150300.124.1","dlm-kmp-rt":"5.3.18-150300.124.1","gfs2-kmp-rt":"5.3.18-150300.124.1","kernel-devel-rt":"5.3.18-150300.124.1","kernel-rt":"5.3.18-150300.124.1","kernel-rt-devel":"5.3.18-150300.124.1","kernel-rt_debug-devel":"5.3.18-150300.124.1","kernel-source-rt":"5.3.18-150300.124.1","kernel-syms-rt":"5.3.18-150300.124.1","ocfs2-kmp-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP3","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-150300.124.1","dlm-kmp-rt":"5.3.18-150300.124.1","gfs2-kmp-rt":"5.3.18-150300.124.1","kernel-devel-rt":"5.3.18-150300.124.1","kernel-rt":"5.3.18-150300.124.1","kernel-rt-devel":"5.3.18-150300.124.1","kernel-rt_debug-devel":"5.3.18-150300.124.1","kernel-source-rt":"5.3.18-150300.124.1","kernel-syms-rt":"5.3.18-150300.124.1","ocfs2-kmp-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.124.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.124.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:1892-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207168"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208137"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208601"},{"type":"REPORT","url":"https://bugzilla.suse.com/1208787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209052"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209290"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209291"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209532"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209547"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209549"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209635"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209636"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209778"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5753"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-4744"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0394"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1075"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1390"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1513"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1582"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-28772"}]}