Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 11 |
CVE-ID | CVE-2019-19083 CVE-2022-3105 CVE-2022-3106 CVE-2022-3107 CVE-2022-3108 CVE-2022-3111 CVE-2022-3435 CVE-2022-3643 CVE-2022-42328 CVE-2022-42329 CVE-2022-4662 |
CWE-ID | CWE-401 CWE-476 CWE-252 CWE-125 CWE-20 CWE-399 CWE-284 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
openSUSE Leap Micro Operating systems & Components / Operating system SUSE Linux Enterprise Real Time Operating systems & Components / Operating system SUSE Linux Enterprise Module for Realtime Operating systems & Components / Operating system SUSE Linux Enterprise Micro Operating systems & Components / Operating system ocfs2-kmp-rt-debuginfo Operating systems & Components / Operating system package or component ocfs2-kmp-rt Operating systems & Components / Operating system package or component kernel-syms-rt Operating systems & Components / Operating system package or component kernel-rt_debug-devel-debuginfo Operating systems & Components / Operating system package or component kernel-rt_debug-devel Operating systems & Components / Operating system package or component kernel-rt_debug-debugsource Operating systems & Components / Operating system package or component kernel-rt_debug-debuginfo Operating systems & Components / Operating system package or component kernel-rt-devel-debuginfo Operating systems & Components / Operating system package or component kernel-rt-devel Operating systems & Components / Operating system package or component gfs2-kmp-rt-debuginfo Operating systems & Components / Operating system package or component gfs2-kmp-rt Operating systems & Components / Operating system package or component dlm-kmp-rt-debuginfo Operating systems & Components / Operating system package or component dlm-kmp-rt Operating systems & Components / Operating system package or component cluster-md-kmp-rt-debuginfo Operating systems & Components / Operating system package or component cluster-md-kmp-rt Operating systems & Components / Operating system package or component kernel-source-rt Operating systems & Components / Operating system package or component kernel-devel-rt Operating systems & Components / Operating system package or component kernel-rt-debugsource Operating systems & Components / Operating system package or component kernel-rt-debuginfo Operating systems & Components / Operating system package or component kernel-rt Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 11 vulnerabilities.
EUVDB-ID: #VU24446
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2019-19083
CWE-ID:
CWE-401 - Missing release of memory after effective lifetime
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak within the "clock_source_create()" functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 allow a local user to cause a denial of service (memory consumption).
This vulnerability affects the following functions:
Update the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71536
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3105
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the uapi_finalize() function in drivers/infiniband/core/uverbs_uapi.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71537
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3106
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the ef100_update_stats() function in drivers/net/ethernet/sfc/ef100_nic.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71538
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3107
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the netvsc_get_ethtool_stats() function in drivers/net/hyperv/netvsc_drv.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71539
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3108
CWE-ID:
CWE-252 - Unchecked Return Value
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to unchecked return value within the kfd_parse_subtype_iolink() function in drivers/gpu/drm/amd/amdkfd/kfd_crat.c. A local user can crash the kernel.
Update the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71540
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-3111
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the free_charger_irq() function in drivers/power/supply/wm8350_power.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70499
Risk: Medium
CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-3435
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition within the fib_nh_match() function in net/ipv4/fib_semantics.c IPv4 handler. A remote attacker can send specially crafted data to the system, trigger an out-of-bounds read error and read contents of memory on the system.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70468
Risk: Medium
CVSSv4.0: 5.6 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/U:Green]
CVE-ID: CVE-2022-3643
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of network packets. An attacker with access to the guest OS can trigger the related physical NIC on the host to reset, abort, or crash by sending certain kinds of packets.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70469
Risk: Medium
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/U:Green]
CVE-ID: CVE-2022-42328
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources. An attacker with access to the guest OS can trigger deadlock in Linux netback driver and perform a denial of service (DoS) attack of the host via the paravirtualized network interface.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU70470
Risk: Medium
CVSSv4.0: 5.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/U:Green]
CVE-ID: CVE-2022-42329
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources. An attacker with access to the guest OS can trigger deadlock in Linux netback driver and perform a denial of service (DoS) attack of the host via the paravirtualized network interface.
MitigationUpdate the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU71541
Risk: Low
CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-4662
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper access restrictions in the Linux kernel USB core subsystem in the way user attaches usb device. A local user can perform a denial of service (DoS) attack.
Update the affected package the Linux Kernel to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.2
SUSE Linux Enterprise Real Time: 15-SP3
SUSE Linux Enterprise Module for Realtime: 15-SP3
SUSE Linux Enterprise Micro: 5.1 - 5.2
ocfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
ocfs2-kmp-rt: before 5.3.18-150300.115.1
kernel-syms-rt: before 5.3.18-150300.115.1
kernel-rt_debug-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt_debug-devel: before 5.3.18-150300.115.1
kernel-rt_debug-debugsource: before 5.3.18-150300.115.1
kernel-rt_debug-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel-debuginfo: before 5.3.18-150300.115.1
kernel-rt-devel: before 5.3.18-150300.115.1
gfs2-kmp-rt-debuginfo: before 5.3.18-150300.115.1
gfs2-kmp-rt: before 5.3.18-150300.115.1
dlm-kmp-rt-debuginfo: before 5.3.18-150300.115.1
dlm-kmp-rt: before 5.3.18-150300.115.1
cluster-md-kmp-rt-debuginfo: before 5.3.18-150300.115.1
cluster-md-kmp-rt: before 5.3.18-150300.115.1
kernel-source-rt: before 5.3.18-150300.115.1
kernel-devel-rt: before 5.3.18-150300.115.1
kernel-rt-debugsource: before 5.3.18-150300.115.1
kernel-rt-debuginfo: before 5.3.18-150300.115.1
kernel-rt: before 5.3.18-150300.115.1
CPE2.3http://www.suse.com/support/update/announcement/2023/suse-su-20230134-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.