rpm package
suse/kernel-source&distro=SUSE Linux Enterprise Server 15 SP3-LTSS
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSS
Vulnerabilities (1,483)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-20588 | Med | 5.5 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Aug 8, 2023 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | |
| CVE-2023-20569 | Med | 4.7 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Aug 8, 2023 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | |
| CVE-2023-4194 | Med | 5.5 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Aug 7, 2023 | A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following ups | |
| CVE-2023-4147 | Hig | 7.8 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Aug 7, 2023 | A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system. | |
| CVE-2023-4133 | Med | 5.5 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Aug 3, 2023 | A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of ser | |
| CVE-2023-4132 | Med | 5.5 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Aug 3, 2023 | A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition. | |
| CVE-2023-4004 | Hig | 7.8 | < 5.3.18-150300.59.138.1 | 5.3.18-150300.59.138.1 | Jul 31, 2023 | A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the syste | |
| CVE-2023-3772 | Med | 5.5 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Jul 25, 2023 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of s | |
| CVE-2023-20593 | Med | 5.5 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 24, 2023 | An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | |
| CVE-2023-3812 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 24, 2023 | An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on t | |
| CVE-2023-3567 | Hig | 7.1 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 24, 2023 | A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | |
| CVE-2023-2860 | Med | 4.4 | < 5.3.18-150300.59.161.1 | 5.3.18-150300.59.161.1 | Jul 24, 2023 | An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated | |
| CVE-2023-3863 | Med | 6.4 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Jul 24, 2023 | A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue. | |
| CVE-2023-3776 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_b | |
| CVE-2023-3611 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 21, 2023 | An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes wi | |
| CVE-2023-3609 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 21, 2023 | A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in t | |
| CVE-2023-0160 | Med | 4.7 | < 5.3.18-150300.59.158.1 | 5.3.18-150300.59.158.1 | Jul 18, 2023 | A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system. | |
| CVE-2023-21400 | Med | 6.7 | < 5.3.18-150300.59.133.1 | 5.3.18-150300.59.133.1 | Jul 13, 2023 | In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation. | |
| CVE-2023-35001 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 5, 2023 | Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace | |
| CVE-2023-31248 | Hig | 7.8 | < 5.3.18-150300.59.130.1 | 5.3.18-150300.59.130.1 | Jul 5, 2023 | Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace |
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filters and gain unauthorized access to some resources. The original patches fixing CVE-2023-1076 are incorrect or incomplete. The problem is that the following ups
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device is detaching due to a possible rearming of the flower_stats_timer from the work queue. This flaw allows a local user to crash the system, causing a denial of ser
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device initialization when the siano device is plugged in. This flaw allows a local user to crash the system, causing a denial of service condition.
- affected < 5.3.18-150300.59.138.1fixed 5.3.18-150300.59.138.1
A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the system or potentially escalate their privileges on the syste
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of s
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on t
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
- affected < 5.3.18-150300.59.161.1fixed 5.3.18-150300.59.161.1
An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within the processing of seg6 attributes. The issue results from the improper validation of user-supplied data, which can result in a read past the end of an allocated
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_b
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve local privilege escalation. The qfq_change_agg() function in net/sched/sch_qfq.c allows an out-of-bounds write because lmax is updated according to packet sizes wi
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in t
- affected < 5.3.18-150300.59.158.1fixed 5.3.18-150300.59.158.1
A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.
- affected < 5.3.18-150300.59.133.1fixed 5.3.18-150300.59.133.1
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
- affected < 5.3.18-150300.59.130.1fixed 5.3.18-150300.59.130.1
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
Page 66 of 75