Oval Definition:oval:org.opensuse.security:def:20230461
Revision Date:2023-06-22Version:1
Title:CVE-2023-0461
Description:

There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS?or CONFIG_XFRM_ESPINTCP?has to be configured, but the operation does not require any privilege.

There is a use-after-free bug of icsk_ulp_data?of a struct inet_connection_sock.

When CONFIG_TLS?is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable.

The setsockopt?TCP_ULP?operation does not require any privilege.

We recommend upgrading past commit?2c02d41d71f90a5168391b6a5f2954112ba2307c
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2023-0461
SUSE CVE-2023-0461
SUSE-IU-2023:219-1
SUSE-IU-2023:220-1
SUSE-IU-2023:221-1
SUSE-SU-2023:0749-1
SUSE-SU-2023:0796-1
SUSE-SU-2023:1608-1
SUSE-SU-2023:1609-1
SUSE-SU-2023:1710-1
SUSE-SU-2023:1800-1
SUSE-SU-2023:1811-1
SUSE-SU-2023:1892-1
SUSE-IU-2023:347-1
SUSE-IU-2023:348-1
SUSE-IU-2023:349-1
SUSE-SU-2023:2371-1
SUSE-SU-2023:2384-1
SUSE-SU-2023:2405
SUSE-SU-2023:2416
SUSE-SU-2023:2423
SUSE-SU-2023:2425
SUSE-SU-2023:2431
SUSE-SU-2023:2443-1
SUSE-SU-2023:2448-1
SUSE-SU-2023:2455-1
SUSE-SU-2023:2468-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Availability Extension 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Live Patching 15 SP5
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Module for Legacy 15 SP5
SUSE Linux Enterprise Module for Public Cloud 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
SUSE Linux Enterprise Workstation Extension 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.4 is installed
  • AND Package Information
  • kernel-default-5.14.21-150400.24.55.3 is installed
  • OR kernel-default-base-5.14.21-150400.24.55.3.150400.24.22.7 is installed
  • OR kernel-rt-5.14.21-150400.15.18.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Legacy 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND reiserfs-kmp-default is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • OR SUSE Linux Enterprise Workstation Extension 15 SP5 is installed
  • AND kernel-default-extra is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-default is affected
  • OR kernel-docs is affected
  • OR kernel-obs-build is affected
  • OR kernel-source is affected
  • OR kernel-syms is affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-64kb is affected
  • OR kernel-64kb-devel is affected
  • OR kernel-default is affected
  • OR kernel-default-devel is affected
  • OR kernel-devel is affected
  • OR kernel-macros is affected
  • OR kernel-zfcpdump is affected
  • OR Package Information
  • SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Public Cloud 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-azure is affected
  • OR kernel-azure-devel is affected
  • OR kernel-devel-azure is affected
  • OR kernel-source-azure is affected
  • OR kernel-syms-azure is affected
  • OR Package Information
  • SUSE Linux Enterprise Live Patching 15 SP5 is installed
  • AND
  • kernel-default-livepatch is affected
  • OR kernel-default-livepatch-devel is affected
  • OR Package Information
  • SUSE Linux Enterprise High Availability Extension 15 SP5 is installed
  • AND
  • cluster-md-kmp-default is affected
  • OR dlm-kmp-default is affected
  • OR gfs2-kmp-default is affected
  • OR ocfs2-kmp-default is affected
  • BACK