File _patchinfo of Package patchinfo.30480
<patchinfo incident="30480">
<issue id="1208839" tracker="bnc">VUL-0: CVE-2023-1077: kernel live patch: type confusion in pick_next_rt_entity</issue>
<issue id="1212849" tracker="bnc">VUL-0: CVE-2023-3090: kernel live patch: heap out-of-bounds vulnerability in the ipvlan network driver could lead to local privilege escalation</issue>
<issue id="1213063" tracker="bnc">VUL-0: CVE-2023-35001: kernel live patch: nf_tables nft_byteorder_eval OOB read/write</issue>
<issue id="1213244" tracker="bnc">VUL-0: CVE-2023-3567: kernel live patch: use after free in vcs_read() in the vc_screen driver due to race condition</issue>
<issue id="2023-1077" tracker="cve" />
<issue id="2023-3090" tracker="cve" />
<issue id="2023-35001" tracker="cve" />
<issue id="2023-3567" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 5.3.18-150200_24_154 fixes several issues.
The following security issues were fixed:
- CVE-2023-3567: Fixed a use-after-free in vcs_read in drivers/tty/vt/vc_screen.c (bsc#1213244).
- CVE-2023-35001: Fixed an out-of-bounds memory access flaw in nft_byteorder that could allow a local attacker to escalate their privilege (bsc#1213063).
- CVE-2023-1077: Fixed a type confusion in pick_next_rt_entity(), that could cause memory corruption (bsc#1208839).
- CVE-2023-3090: Fixed a heap out-of-bounds write in the ipvlan network driver (bsc#1212849).
</description>
<summary>Security update for the Linux Kernel (Live Patch 37 for SLE 15 SP2)</summary>
</patchinfo>