[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:0762-1 -- SLES kernel

ID: oval:org.secpod.oval:def:89048545Date: (C)2023-04-11   (M)2024-04-25
Class: PATCHFamily: unix




The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2022-38096: Fixed NULL-ptr deref in vmw_cmd_dx_define_query . * CVE-2022-4129: Fixed a denial of service with the Layer 2 Tunneling Protocol . A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. * CVE-2023-0597: Fixed lack of randomization of per-cpu entry area in x86/mm . * CVE-2023-1118: Fixed a use-after-free bugs caused by ene_tx_irqsim in media/rc . * CVE-2023-23559: Fixed integer overflow in rndis_wlan that leads to a buffer overflow . * CVE-2023-26545: Fixed double free in net/mpls/af_mpls.c upon an allocation failure . The following non-security bugs were fixed: * bonding: fix 802.3ad state sent to partner when unbinding slave . * do not sign the vanilla kernel . * icmp: do not fail on fragment reassembly time exceeded . * ipmi: fix initialization when workqueue allocation fails . * ipmi: msghandler: Make symbol "remove_work_wq" static . * kabi fix for - SUNRPC: Fix priority queue fairness . * kabi fix for: NFS: Pass error information to the pgio error cleanup routine . * kabi/severities: add l2tp local symbols * kernel-module-subpackage: Fix expansion with -b parameter . When -b is specified the script is prefixed with KMP_NEEDS_MKINITRD=1 which sets the variable for a simple command. However, the script is no longer a simple command. Export the variable instead. * media: coda: Add check for dcoda_iram_alloc . * media: coda: Add check for kmalloc . * media: platform: ti: Add missing check for devm_regulator_get . * net: aquantia: fix RSS table and key sizes . * netfilter: ipvs: Fix inappropriate output of procfs . * netfilter: xt_connlimit: do not store address in the conn nodes . * nfs: Fix nfsi-greater than nrequests count error on nfs_inode_remove_request . * nfs: Pass error information to the pgio error cleanup routine . * nfsd: fix handling of readdir in v4root vs. mount upcall timeout . * nfsd: fix race to check ls_layouts . * nfsd: under NFSv4.1, fix double svc_xprt_put on rpc_create failure . * ocfs2: Fix data corruption after failed write . * pNFS/filelayout: Fix coalescing test for single DS . * powerpc/eeh: Fix use-after-release of EEH driver . * powerpc/fscr: Enable interrupts earlier before calling get_user . * powerpc/powernv: Fix build error in opal-imc.c when NUMA=n . * powerpc/powernv: IMC fix out of bounds memory access at shutdown . * scsi: qla2xxx: Add option to disable FC2 Target support . * sunrpc: Fix priority queue fairness . * sunrpc: ensure the matching upcall is in-flight upon downcall . * vlan: Fix out of order vlan headers with reorder header off . * vlan: Fix vlan insertion for packets without ethernet header . * vxlan: Fix error path in __vxlan_dev_create . * vxlan: changelink: Fix handling of default remotes . * xfrm: Copy policy family in clone_policy . ## Special Instructions and Notes: * Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 12 SP5
Product:
kernel
Reference:
SUSE-SU-2023:0762-1
CVE-2022-38096
CVE-2022-4129
CVE-2023-0597
CVE-2023-1118
CVE-2023-23559
CVE-2023-26545
CVE    6
CVE-2023-23559
CVE-2022-4129
CVE-2023-1118
CVE-2023-26545
...
CPE    2
cpe:/o:linux:linux_kernel
cpe:/o:suse:suse_linux_enterprise_server:12:sp5

© SecPod Technologies