{"schema_version":"1.7.3","id":"SUSE-SU-2024:0129-1","published":"2024-01-16T14:49:00Z","modified":"2026-02-04T02:36:51.786095Z","related":["CVE-2020-26555","CVE-2023-51779","CVE-2023-6121","CVE-2023-6531","CVE-2023-6546","CVE-2023-6606","CVE-2023-6610","CVE-2023-6622","CVE-2023-6931","CVE-2023-6932"],"upstream":["CVE-2020-26555","CVE-2023-51779","CVE-2023-6121","CVE-2023-6531","CVE-2023-6546","CVE-2023-6606","CVE-2023-6610","CVE-2023-6622","CVE-2023-6931","CVE-2023-6932"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2023-6531: Fixed a use-after-free flaw due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on (bsc#1218447).\n- CVE-2023-6610: Fixed an out of bounds read in the SMB client when printing debug information (bsc#1217946).\n- CVE-2023-51779: Fixed a use-after-free because of a bt_sock_ioctl race condition in bt_sock_recvmsg (bsc#1218559).\n- CVE-2020-26555: Fixed an issue during BR/EDR PIN code pairing in the Bluetooth subsystem that would allow replay attacks (bsc#1179610 bsc#1215237).\n- CVE-2023-6606: Fixed an out of bounds read in the SMB client when receiving a malformed length from a server (bsc#1217947).\n- CVE-2023-6546: Fixed a race condition in the GSM 0710 tty multiplexor via the GSMIOC_SETCONF ioctl that could lead to local privilege escalation (bsc#1218335).\n- CVE-2023-6931: Fixed a heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component that could lead to local privilege escalation. (bsc#1218258).\n- CVE-2023-6932: Fixed a use-after-free vulnerability in the Linux kernel's ipv4: igmp component that could lead to local privilege escalation (bsc#1218253).\n- CVE-2023-6622: Fixed a null pointer dereference vulnerability in nft_dynset_init() that could allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service (bsc#1217938).\n- CVE-2023-6121: Fixed an information leak via dmesg when receiving a crafted packet in the NVMe-oF/TCP subsystem (bsc#1217250).\n\nThe following non-security bugs were fixed:\n\n- Reviewed and added more information to README.SUSE (jsc#PED-5021).\n- Build in the correct KOTD repository with multibuild (JSC-SLE#5501, boo#1211226, bsc#1218184) With multibuild setting repository flags is no longer supported for individual spec files - see https://github.com/openSUSE/open-build-service/issues/3574 Add ExclusiveArch conditional that depends on a macro set up by bs-upload-kernel instead. With that each package should build only in one repository - either standard or QA. Note: bs-upload-kernel does not interpret rpm conditionals, and only uses the first ExclusiveArch line to determine the architectures to enable.\n- KVM: s390/mm: Properly reset no-dat (bsc#1218056).\n- KVM: s390: vsie: fix wrong VIR 37 when MSO is used (bsc#1217933).\n- KVM: x86: Mask LVTPC when handling a PMI (jsc#PED-7322).\n- NFS: Fix O_DIRECT locking issues (bsc#1211162).\n- NFS: Fix a few more clear_bit() instances that need release semantics (bsc#1211162).\n- NFS: Fix a potential data corruption (bsc#1211162).\n- NFS: Fix a use after free in nfs_direct_join_group() (bsc#1211162).\n- NFS: Fix error handling for O_DIRECT write scheduling (bsc#1211162).\n- NFS: More O_DIRECT accounting fixes for error paths (bsc#1211162).\n- NFS: More fixes for nfs_direct_write_reschedule_io() (bsc#1211162).\n- NFS: Use the correct commit info in nfs_join_page_group() (bsc#1211162).\n- NLM: Defend against file_lock changes after vfs_test_lock() (bsc#1217692).\n- Updated SPI patches for NVIDIA Grace enablement (bsc#1212584, jsc#PED-3459).\n- block: fix revalidate performance regression (bsc#1216057).\n- bpf: Adjust insufficient default bpf_jit_limit (bsc#1218234).\n- ceph: fix incorrect revoked caps assert in ceph_fill_file_size() (bsc#1217980).\n- ceph: fix type promotion bug on 32bit systems (bsc#1217982).\n- clocksource: Add a Kconfig option for WATCHDOG_MAX_SKEW (bsc#1215885 bsc#1217217).\n- clocksource: Enable TSC watchdog checking of HPET and PMTMR only when requested (bsc#1215885 bsc#1217217).\n- clocksource: Handle negative skews in 'skew is too large' messages (bsc#1215885 bsc#1217217).\n- clocksource: Improve 'skew is too large' messages (bsc#1215885 bsc#1217217).\n- clocksource: Improve read-back-delay message (bsc#1215885 bsc#1217217).\n- clocksource: Loosen clocksource watchdog constraints (bsc#1215885 bsc#1217217).\n- clocksource: Print clocksource name when clocksource is tested unstable (bsc#1215885 bsc#1217217).\n- clocksource: Verify HPET and PMTMR when TSC unverified (bsc#1215885 bsc#1217217).\n- dm_blk_ioctl: implement path failover for SG_IO (bsc#1183045, bsc#1216776).\n- fuse: dax: set fc->dax to NULL in fuse_dax_conn_free() (bsc#1218659).\n- kabi/severities: ignore kABI for asus-wmi drivers Tolerate the kABI changes, as used only locally for asus-wmi stuff\n- libceph: use kernel_connect() (bsc#1217981).\n- mkspec: Add multibuild support (JSC-SLE#5501, boo#1211226, bsc#1218184) When MULTIBUILD option in config.sh is enabled generate a _multibuild file listing all spec files.\n- mm: kmem: drop __GFP_NOFAIL when allocating objcg vectors (bsc#1218515).\n- net/smc: Fix pos miscalculation in statistics (bsc#1218139).\n- net/tg3: fix race condition in tg3_reset_task() (bsc#1217801).\n- nfs: only issue commit in DIO codepath if we have uncommitted data (bsc#1211162).\n- remove unnecessary WARN_ON_ONCE() (bsc#1214823 bsc#1218569).\n- s390/vx: fix save/restore of fpu kernel context (bsc#1218357).\n- scsi: lpfc: use unsigned type for num_sge (bsc#1214747).\n- swiotlb: fix a braino in the alignment check fix (bsc#1216559).\n- swiotlb: fix slot alignment checks (bsc#1216559).\n- tracing: Disable preemption when using the filter buffer (bsc#1217036).\n- tracing: Fix a possible race when disabling buffered events (bsc#1217036).\n- tracing: Fix a warning when allocating buffered events fails (bsc#1217036).\n- tracing: Fix incomplete locking when disabling buffered events (bsc#1217036).\n- tracing: Fix warning in trace_buffered_event_disable() (bsc#1217036).\n- tracing: Use __this_cpu_read() in trace_event_buffer_lock_reserver() (bsc#1217036).\n- uapi: propagate __struct_group() attributes to the container union (jsc#SLE-18978).\n- vsprintf/kallsyms: Prevent invalid data when printing symbol (bsc#1217602).\n- x86/entry/ia32: Ensure s32 is sign extended to s64 (bsc#1193285).\n- x86/platform/uv: Use alternate source for socket to node data (bsc#1215696 bsc#1217790).\n- x86/tsc: Add option to force frequency recalibration with HW timer (bsc#1215885 bsc#1217217).\n- x86/tsc: Be consistent about use_tsc_delay() (bsc#1215885 bsc#1217217).\n- x86/tsc: Extend watchdog check exemption to 4-Sockets platform (bsc#1215885 bsc#1217217).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-livepatch-SLE15-SP4-RT_Update_17","ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP4","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP4-RT_Update_17&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1-150400.1.3.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-5_14_21-150400_15_65-rt":"1-150400.1.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP4","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.14.21-150400.15.65.1","dlm-kmp-rt":"5.14.21-150400.15.65.1","gfs2-kmp-rt":"5.14.21-150400.15.65.1","kernel-devel-rt":"5.14.21-150400.15.65.1","kernel-rt":"5.14.21-150400.15.65.1","kernel-rt-devel":"5.14.21-150400.15.65.1","kernel-rt_debug":"5.14.21-150400.15.65.1","kernel-rt_debug-devel":"5.14.21-150400.15.65.1","kernel-source-rt":"5.14.21-150400.15.65.1","kernel-syms-rt":"5.14.21-150400.15.65.1","ocfs2-kmp-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-rt_debug","ecosystem":"SUSE:Real Time Module 15 SP4","purl":"pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.14.21-150400.15.65.1","dlm-kmp-rt":"5.14.21-150400.15.65.1","gfs2-kmp-rt":"5.14.21-150400.15.65.1","kernel-devel-rt":"5.14.21-150400.15.65.1","kernel-rt":"5.14.21-150400.15.65.1","kernel-rt-devel":"5.14.21-150400.15.65.1","kernel-rt_debug":"5.14.21-150400.15.65.1","kernel-rt_debug-devel":"5.14.21-150400.15.65.1","kernel-source-rt":"5.14.21-150400.15.65.1","kernel-syms-rt":"5.14.21-150400.15.65.1","ocfs2-kmp-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP4","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.14.21-150400.15.65.1","dlm-kmp-rt":"5.14.21-150400.15.65.1","gfs2-kmp-rt":"5.14.21-150400.15.65.1","kernel-devel-rt":"5.14.21-150400.15.65.1","kernel-rt":"5.14.21-150400.15.65.1","kernel-rt-devel":"5.14.21-150400.15.65.1","kernel-rt_debug":"5.14.21-150400.15.65.1","kernel-rt_debug-devel":"5.14.21-150400.15.65.1","kernel-source-rt":"5.14.21-150400.15.65.1","kernel-syms-rt":"5.14.21-150400.15.65.1","ocfs2-kmp-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP4","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.14.21-150400.15.65.1","dlm-kmp-rt":"5.14.21-150400.15.65.1","gfs2-kmp-rt":"5.14.21-150400.15.65.1","kernel-devel-rt":"5.14.21-150400.15.65.1","kernel-rt":"5.14.21-150400.15.65.1","kernel-rt-devel":"5.14.21-150400.15.65.1","kernel-rt_debug":"5.14.21-150400.15.65.1","kernel-rt_debug-devel":"5.14.21-150400.15.65.1","kernel-source-rt":"5.14.21-150400.15.65.1","kernel-syms-rt":"5.14.21-150400.15.65.1","ocfs2-kmp-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"openSUSE:Leap Micro 5.3","purl":"pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"openSUSE:Leap Micro 5.4","purl":"pkg:rpm/opensuse/kernel-rt&distro=openSUSE%20Leap%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.65.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.65.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:0129-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20240129-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1179610"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183045"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211162"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211226"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214823"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215237"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215696"},{"type":"REPORT","url":"https://bugzilla.suse.com/1215885"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216559"},{"type":"REPORT","url":"https://bugzilla.suse.com/1216776"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217602"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217790"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217801"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217938"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217980"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217981"},{"type":"REPORT","url":"https://bugzilla.suse.com/1217982"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218056"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218234"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218253"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218258"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218335"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218357"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218559"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218569"},{"type":"REPORT","url":"https://bugzilla.suse.com/1218659"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-26555"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-51779"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6121"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6531"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6610"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6622"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6931"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6932"}]}