Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2023:2892-1 — kernel-azure (CVE-2023-1249 +14 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP5 Azure kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2023-1249: Fixed a use-after-free flaw in the core dump subsystem that allowed a local user to crash the system (bsc#1209039).
  • CVE-2023-1829: Fixed a use-after-free vulnerability in the control index filter (tcindex) (bsc#1210335).
  • CVE-2023-2430: Fixed a possible denial of service via a missing lock in the io_uring subsystem (bsc#1211014).
  • CVE-2023-28866: Fixed an out-of-bounds access in net/bluetooth/hci_sync.c because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but did not (bsc#1209780).
  • CVE-2023-3090: Fixed a heap out-of-bounds write in the ipvlan network driver (bsc#1212842).
  • CVE-2023-3111: Fixed a use-after-free vulnerability in prepare_to_relocate in fs/btrfs/relocation.c (bsc#1212051).
  • CVE-2023-3212: Fixed a NULL pointer dereference flaw in the gfs2 file system (bsc#1212265).
  • CVE-2023-3220: Fixed a NULL pointer dereference flaw in dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() (bsc#1212556).
  • CVE-2023-3357: Fixed a NULL pointer dereference flaw in the AMD Sensor Fusion Hub driver (bsc#1212605).
  • CVE-2023-3358: Fixed a NULL pointer dereference flaw in the Integrated Sensor Hub (ISH) driver (bsc#1212606).
  • CVE-2023-3389: Fixed a use-after-free vulnerability in the io_uring subsystem (bsc#1212838).
  • CVE-2023-35788: Fixed an out-of-bounds write in the flower classifier code via TCA_FLOWER_KEY_ENC_OPTS_GENEVE packets in fl_set_geneve_opt in net/sched/cls_flower.c (bsc#1212504).
  • CVE-2023-35823: Fixed a use-after-free flaw in saa7134_finidev in drivers/media/pci/saa7134/saa7134-core.c (bsc#1212494).
  • CVE-2023-35828: Fixed a use-after-free flaw in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c (bsc#1212513).
  • CVE-2023-35829: Fixed a use-after-free flaw in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c (bsc#1212495).

The following non-security bugs were fixed:

  • ACPI: CPPC: Add AMD pstate energy performance preference cppc control (bsc#1212445).
  • ACPI: CPPC: Add auto select register read/write support (bsc#1212445).
  • ACPI: sleep: Avoid breaking S3 wakeup due to might_sleep() (git-fixes).
  • ALSA: ac97: Fix possible NULL dereference in snd_ac97_mixer (git-fixes).
  • ALSA: fireface: make read-only const array for model names static (git-fixes).
  • ALSA: hda/realtek: Add 'Intel Reference board' and 'NUC 13' SSID in the ALC256 (git-fixes).
  • ALSA: hda/realtek: Add a quirk for Compaq N14JP6 (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG G614Jx (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG G634Z (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG GA402X (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG GV601V (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG GX650P (git-fixes).
  • ALSA: hda/realtek: Add quirk for ASUS ROG GZ301V (git-fixes).
  • ALSA: hda/realtek: Add quirk for Clevo NPx0SNx (git-fixes).
  • ALSA: hda/realtek: Add quirks for ASUS GU604V and GU603V (git-fixes).
  • ALSA: hda/realtek: Add quirks for ROG ALLY CS35l41 audio (git-fixes).
  • ALSA: hda/realtek: Add quirks for Unis H3C Desktop B760 & Q760 (git-fixes).
  • ALSA: hda/realtek: Amend G634 quirk to enable rear speakers (git-fixes).
  • ALSA: hda/realtek: Enable mute/micmute LEDs and limit mic boost on EliteBook (git-fixes).
  • ALSA: hda/realtek: Whitespace fix (git-fixes).
  • ALSA: hda: LNL: add HD Audio PCI ID (git-fixes).
  • ALSA: hda: fix a possible null-pointer dereference due to data race in snd_hdac_regmap_sync() (git-fixes).
  • ALSA: jack: Fix mutex call in snd_jack_report() (git-fixes).
  • ALSA: oxfw: make read-only const array models static (git-fixes).
  • ALSA: pcm: Fix potential data race at PCM memory allocation helpers (git-fixes).
  • ALSA: usb-audio: Add quirk flag for HEM devices to enable native DSD playback (git-fixes).
  • ALSA: usb-audio: Fix broken resume due to UAC3 power state (git-fixes).
  • ARM: 9295/1: unwind:fix unwind abort for uleb128 case (git-fixes)
  • ARM: cpu: Switch to arch_cpu_finalize_init() (bsc#1212448).
  • ARM: dts: Fix erroneous ADS touchscreen polarities (git-fixes).
  • ARM: dts: vexpress: add missing cache properties (git-fixes).
  • ASoC: dwc: move DMA init to snd_soc_dai_driver probe() (git-fixes).
  • ASoC: es8316: Do not set rate constraints for unsupported MCLKs (git-fixes).
  • ASoC: es8316: Increment max value for ALC Capture Target Volume control (git-fixes).
  • ASoC: imx-audmix: check return value of devm_kasprintf() (git-fixes).
  • ASoC: mediatek: mt8173: Fix irq error path (git-fixes).
  • ASoC: nau8824: Add quirk to active-high jack-detect (git-fixes).
  • ASoC: simple-card: Add missing of_node_put() in case of error (git-fixes).
  • ASoC: soc-pcm: test if a BE can be prepared (git-fixes).
  • Add MODULE_FIRMWARE() for FIRMWARE_TG357766 (git-fixes).
  • Bluetooth: Fix

Affected software

SUSE-SU-2023:2892-1 is recorded against 3 packages.

  • kernel-azure (fixed in 5.14.21-150500.33.6.1)
  • kernel-source-azure (fixed in 5.14.21-150500.33.6.1)
  • kernel-syms-azure (fixed in 5.14.21-150500.33.6.1)

Timeline and source

Published on 19 July 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-07-19
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-azure 5.14.21-150500.33.6.1
kernel-source-azure 5.14.21-150500.33.6.1
kernel-syms-azure 5.14.21-150500.33.6.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2023:2892-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2023:2892-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.