File _patchinfo of Package patchinfo.32742
<patchinfo incident="32742">
<issue id="1215300" tracker="bnc">VUL-0: CVE-2023-4921: kernel live patch: use-after-free in net/sched: sch_qfq component</issue>
<issue id="1217116" tracker="bnc">VUL-0: CVE-2023-39198: kernel live patch: QXL: race condition leading to use-after-free in qxl_mode_dumb_create()</issue>
<issue id="1218733" tracker="bnc">VUL-0: CVE-2023-51780: kernel live patch: use-after-free in net/atm/ioctl.c</issue>
<issue id="2023-39198" tracker="cve" />
<issue id="2023-4921" tracker="cve" />
<issue id="2023-51780" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 5.14.21-150400_24_55 fixes several issues.
The following security issues were fixed:
- CVE-2023-4921: Fixed a use-after-free vulnerability in the QFQ network scheduler which could be exploited to achieve local privilege escalation (bsc#1215300).
- CVE-2023-39198: Fixed a race condition leading to a use-after-free in qxl_mode_dumb_create() (bsc#1217116).
- CVE-2023-51780: Fixed a use-after-free in do_vcc_ioctl in net/atm/ioctl.c, because of a vcc_recvmsg race condition (bsc#1218733).
</description>
<summary>Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP4)</summary>
</patchinfo>