MGASA-2024-0033 - Updated kernel packages fix security vulnerabilities and other bugs

Publication date: 09 Feb 2024
URL: https://advisories.mageia.org/MGASA-2024-0033.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-6610,
     CVE-2023-46838

Upstream version 6.6.14 with many bugfixes and at least the following
security fixes:
An out-of-bounds read vulnerability was found in smb2_dump_detail in
fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a
local attacker to crash the system or leak internal kernel information.
(CVE-2023-6610)
An unprivileged guest can cause Denial of Service (DoS) of the host by
sending network packets to the backend, causing the backend to crash.
Data corruption or privilege escalation have not been ruled out.
https://xenbits.xen.org/xsa/advisory-448.html (CVE-2023-46838)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32786
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.1
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.2
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.4
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.5
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.6
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.7
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.8
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.9
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.10
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.11
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.12
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.13
- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.14
- https://xenbits.xen.org/xsa/advisory-448.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6610
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46838

SRPMS:
- 9/core/kernel-6.6.14-2.mga9
- 9/core/kmod-xtables-addons-3.24-54.mga9
- 9/core/kmod-virtualbox-7.0.14-42.mga9
- 9/core/gnome-applets-3.46.0-3.1.mga9
- 9/core/mate-applets-1.26.1-1.1.mga9

Mageia 2024-0033: kernel security update

Upstream version 6.6.14 with many bugfixes and at least the following security fixes: An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c i...

Summary

Upstream version 6.6.14 with many bugfixes and at least the following security fixes: An out-of-bounds read vulnerability was found in smb2_dump_detail in fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a local attacker to crash the system or leak internal kernel information. (CVE-2023-6610) An unprivileged guest can cause Denial of Service (DoS) of the host by sending network packets to the backend, causing the backend to crash. Data corruption or privilege escalation have not been ruled out. https://xenbits.xen.org/xsa/advisory-448.html (CVE-2023-46838)

References

- https://bugs.mageia.org/show_bug.cgi?id=32786

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.1

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.2

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.3

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.4

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.5

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.6

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.7

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.8

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.9

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.10

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.11

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.12

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.13

- https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.14

- https://xenbits.xen.org/xsa/advisory-448.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6610

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46838

Resolution

MGASA-2024-0033 - Updated kernel packages fix security vulnerabilities and other bugs

SRPMS

- 9/core/kernel-6.6.14-2.mga9

- 9/core/kmod-xtables-addons-3.24-54.mga9

- 9/core/kmod-virtualbox-7.0.14-42.mga9

- 9/core/gnome-applets-3.46.0-3.1.mga9

- 9/core/mate-applets-1.26.1-1.1.mga9

Severity
Publication date: 09 Feb 2024
URL: https://advisories.mageia.org/MGASA-2024-0033.html
Type: security
CVE: CVE-2023-6610, CVE-2023-46838

Related News