{"id":"SUSE-SU-2023:3324-1","summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2018-20784: Fixed a denial of service (infinite loop in update_blocked_averages) by mishandled leaf cfs_rq in kernel/sched/fair.c (bsc#1126703).\n- CVE-2018-3639: Fixed Speculative Store Bypass aka 'Memory Disambiguation' (bsc#1087082).\n- CVE-2022-40982: Fixed transient execution attack called 'Gather Data Sampling' (bsc#1206418).\n- CVE-2023-0459: Fixed information leak in __uaccess_begin_nospec (bsc#1211738).\n- CVE-2023-1637: Fixed vulnerability that could lead to unauthorized access to CPU memory after resuming CPU from suspend-to-RAM (bsc#1209779).\n- CVE-2023-20569: Fixed side channel attack ‘Inception’ or ‘RAS Poisoning’ (bsc#1213287).\n- CVE-2023-20593: Fixed a ZenBleed issue in 'Zen 2' CPUs that could allow an attacker to potentially access sensitive information (bsc#1213286).\n- CVE-2023-2985: Fixed an use-after-free vulnerability in hfsplus_put_super in fs/hfsplus/super.c that could allow a local user to cause a denial of service (bsc#1211867).\n- CVE-2023-3106: Fixed crash in XFRM_MSG_GETSA netlink handler (bsc#1213251).\n- CVE-2023-3268: Fixed an out of bounds memory access flaw in relay_file_read_start_pos in the relayfs (bsc#1212502).\n- CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213059).\n- CVE-2023-3567: Fixed a use-after-free in vcs_read in drivers/tty/vt/vc_screen.c (bsc#1213167).\n- CVE-2023-3611: Fixed an out-of-bounds write in net/sched sch_qfq(bsc#1213585).\n- CVE-2023-3776: Fixed improper refcount update in  cls_fw leads to use-after-free (bsc#1213588).\n\nThe following non-security bugs were fixed:\n\n- net/sched: sch_qfq: refactor parsing of netlink parameters (bsc#1213585).\n- ubi: Fix failure attaching when vid_hdr offset equals to (sub)page size (bsc#1210584).\n- ubi: ensure that VID header offset + VID header size &lt;= alloc, size (bsc#1210584).\n- x86: Treat R_X86_64_PLT32 as R_X86_64_PC32 (git-fixes) No it's not git-fixes it's used to make sle12-sp2 compile with newer toolchain to make the life of all the poor souls maintaining this ancient kernel on their modern machines, a little bit easier....\n","modified":"2026-02-04T02:31:16.170809Z","published":"2023-08-16T06:13:06Z","related":["CVE-2018-20784","CVE-2018-3639","CVE-2022-40982","CVE-2023-0459","CVE-2023-1637","CVE-2023-20569","CVE-2023-20593","CVE-2023-2985","CVE-2023-3106","CVE-2023-3268","CVE-2023-35001","CVE-2023-3567","CVE-2023-3611","CVE-2023-3776"],"upstream":["CVE-2018-20784","CVE-2018-3639","CVE-2022-40982","CVE-2023-0459","CVE-2023-1637","CVE-2023-20569","CVE-2023-20593","CVE-2023-2985","CVE-2023-3106","CVE-2023-3268","CVE-2023-35001","CVE-2023-3567","CVE-2023-3611","CVE-2023-3776"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20233324-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1087082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1126703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1206418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1207561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1209779"},{"type":"REPORT","url":"https://bugzilla.suse.com/1210584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211738"},{"type":"REPORT","url":"https://bugzilla.suse.com/1211867"},{"type":"REPORT","url":"https://bugzilla.suse.com/1212502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213167"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213251"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213585"},{"type":"REPORT","url":"https://bugzilla.suse.com/1213588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-3639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-40982"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-0459"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-1637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20569"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20593"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-35001"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3567"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-3776"}],"affected":[{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.121-92.208.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-devel":"4.4.121-92.208.1","kernel-syms":"4.4.121-92.208.1","kernel-default-base":"4.4.121-92.208.1","kernel-default":"4.4.121-92.208.1","kernel-source":"4.4.121-92.208.1","kernel-devel":"4.4.121-92.208.1","kernel-macros":"4.4.121-92.208.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3324-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.121-92.208.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-devel":"4.4.121-92.208.1","kernel-syms":"4.4.121-92.208.1","kernel-default-base":"4.4.121-92.208.1","kernel-default":"4.4.121-92.208.1","kernel-source":"4.4.121-92.208.1","kernel-devel":"4.4.121-92.208.1","kernel-macros":"4.4.121-92.208.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3324-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Enterprise Server 12 SP2-BCL","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.121-92.208.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-devel":"4.4.121-92.208.1","kernel-syms":"4.4.121-92.208.1","kernel-default-base":"4.4.121-92.208.1","kernel-default":"4.4.121-92.208.1","kernel-source":"4.4.121-92.208.1","kernel-devel":"4.4.121-92.208.1","kernel-macros":"4.4.121-92.208.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:3324-1.json"}}],"schema_version":"1.7.3"}