{"schema_version":"1.7.3","id":"SUSE-SU-2023:4733-1","published":"2023-12-12T14:15:30Z","modified":"2025-05-02T04:34:55.981005Z","related":["CVE-2023-31083","CVE-2023-39197","CVE-2023-39198","CVE-2023-45863","CVE-2023-45871","CVE-2023-5717","CVE-2023-6176"],"upstream":["CVE-2023-31083","CVE-2023-39197","CVE-2023-39198","CVE-2023-45863","CVE-2023-45871","CVE-2023-5717","CVE-2023-6176"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security and bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2023-39197: Fixed a out-of-bounds read in nf_conntrack_dccp_packet() (bsc#1216976).\n- CVE-2023-6176: Fixed a denial of service in the cryptographic algorithm scatterwalk functionality (bsc#1217332).\n- CVE-2023-45863: Fixed a out-of-bounds write in fill_kobj_path() (bsc#1216058).\n- CVE-2023-45871: Fixed an issue in the IGB driver, where the buffer size may not be adequate for frames larger than the MTU (bsc#1216259).\n- CVE-2023-39198: Fixed a race condition leading to use-after-free in qxl_mode_dumb_create() (bsc#1216965).\n- CVE-2023-31083: Fixed race condition in hci_uart_tty_ioctl (bsc#1210780).\n- CVE-2023-5717: Fixed a heap out-of-bounds write vulnerability in the Performance Events component (bsc#1216584).\n\nThe following non-security bugs were fixed:\n\n- ALSA: hda: Disable power-save on KONTRON SinglePC (bsc#1217140).\n- Call flush_delayed_fput() from nfsd main-loop (bsc#1217408).\n- net: mana: Configure hwc timeout from hardware (bsc#1214037).\n- net: mana: Fix MANA VF unload when hardware is unresponsive (bsc#1214764).\n- powerpc: Do not clobber f0/vs0 during fp|altivec register save (bsc#1217780).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.1","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.152.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.152.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4733-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.2","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-150300.152.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-150300.152.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4733-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234733-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1084909"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210780"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215371"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216058"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216259"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216965"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216976"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217140"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217408"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-31083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-39197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-39198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45863"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-45871"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-5717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6176"}]}