Oval Definition:oval:org.opensuse.security:def:202328464
Revision Date:2023-06-22Version:1
Title:CVE-2023-28464
Description:

hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
Family:unixClass:vulnerability
Status:Reference(s):Mitre CVE-2023-28464
SUSE CVE-2023-28464
SUSE-SU-2023:1800-1
SUSE-SU-2023:1801-1
SUSE-SU-2023:1802-1
SUSE-SU-2023:1803-1
SUSE-SU-2023:1811-1
SUSE-SU-2023:1848-1
SUSE-SU-2023:1892-1
SUSE-SU-2023:1894-1
SUSE-SU-2023:1897-1
SUSE-IU-2023:317-1
SUSE-IU-2023:318-1
SUSE-IU-2023:319-1
SUSE-IU-2023:347-1
SUSE-IU-2023:348-1
SUSE-IU-2023:349-1
SUSE-SU-2023:1992-1
SUSE-SU-2023:2232-1
SUSE-SU-2023:2369-1
SUSE-SU-2023:2371-1
SUSE-SU-2023:2376-1
SUSE-SU-2023:2384-1
SUSE-SU-2023:2389-1
SUSE-SU-2023:2399
SUSE-SU-2023:2405
SUSE-SU-2023:2415
SUSE-SU-2023:2416
SUSE-SU-2023:2420
SUSE-SU-2023:2422
SUSE-SU-2023:2423
SUSE-SU-2023:2425
SUSE-SU-2023:2431
SUSE-SU-2023:2442-1
SUSE-SU-2023:2443-1
SUSE-SU-2023:2448-1
SUSE-SU-2023:2453-1
SUSE-SU-2023:2455-1
SUSE-SU-2023:2459-1
SUSE-SU-2023:2468-1
Platform(s):SUSE Linux Enterprise Desktop 15 SP5
SUSE Linux Enterprise High Performance Computing 15 SP5
SUSE Linux Enterprise Micro 5.4
SUSE Linux Enterprise Module for Basesystem 15 SP5
SUSE Linux Enterprise Module for Development Tools 15 SP5
SUSE Linux Enterprise Module for Public Cloud 15 SP5
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Micro 5.4 is installed
  • AND Package Information
  • kernel-default-5.14.21-150400.24.60.1 is installed
  • OR kernel-default-base-5.14.21-150400.24.60.1.150400.24.24.3 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Development Tools 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-default is not affected
  • OR kernel-source is not affected
  • OR Package Information
  • SUSE Linux Enterprise Desktop 15 SP5 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Basesystem 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-default is not affected
  • OR kernel-default-devel is not affected
  • OR kernel-devel is not affected
  • OR kernel-macros is not affected
  • OR Package Information
  • SUSE Linux Enterprise High Performance Computing 15 SP5 is installed
  • OR SUSE Linux Enterprise Module for Public Cloud 15 SP5 is installed
  • OR SUSE Linux Enterprise Server 15 SP5 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP5 is installed
  • AND
  • kernel-devel-azure is not affected
  • OR kernel-source-azure is not affected
  • BACK