<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for the Linux Kernel</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2023:1892-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2023-07-06T01:58:50Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2023-07-06T01:58:50Z</InitialReleaseDate>
    <CurrentReleaseDate>2023-07-06T01:58:50Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for the Linux Kernel</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208787).
- CVE-2023-28772: Fixed buffer overflow in seq_buf_putmem_hex in lib/seq_buf.c (bsc#1209549).
- CVE-2023-1513: Fixed an uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak (bsc#1209532).
- CVE-2023-28464: Fixed use-after-free that could lead to privilege escalation in hci_conn_cleanup in net/bluetooth/hci_conn.c (bsc#1209052).
- CVE-2023-0394: Fixed a null pointer dereference flaw in the network subcomponent in the Linux kernel which could lead to system crash (bsc#1207168).
- CVE-2023-28466: Fixed race condition that could lead to use-after-free or NULL pointer dereference in do_tls_getsockopt in net/tls/tls_main.c (bsc#1209366).
- CVE-2021-3923: Fixed stack information leak vulnerability that could lead to kernel protection bypass in infiniband RDMA (bsc#1209778).
- CVE-2023-1390: Fixed remote DoS vulnerability in tipc_link_xmit() (bsc#1209289).
- CVE-2022-4744: Fixed double-free that could lead to DoS or privilege escalation in TUN/TAP device driver functionality (bsc#1209635).
- CVE-2023-1281: Fixed use after free that could lead to privilege escalation in tcindex (bsc#1209634).
- CVE-2023-1582: Fixed soft lockup in __page_mapcount (bsc#1209636).
- CVE-2023-28327: Fixed DoS in in_skb in unix_diag_get_exact() (bsc#1209290).
- CVE-2017-5753: Fixed spectre vulnerability in prlimit (bsc#1209256).
- CVE-2023-1382: Fixed denial of service in tipc_conn_close (bsc#1209288).
- CVE-2023-28328: Fixed a denial of service issue in az6027 driver in drivers/media/usb/dev-usb/az6027.c (bsc#1209291).
- CVE-2023-1078: Fixed a heap out-of-bounds write in rds_rm_zerocopy_callback (bsc#1208601).
- CVE-2023-1075: Fixed a type confusion in tls_is_tx_ready (bsc#1208598).
- CVE-2017-5753: Fixed spectre V1 vulnerability on netlink (bsc#1209547).

The following non-security bugs were fixed:

- ipv6: raw: Deduct extension header length in rawv6_push_pending_frames (bsc#1207168).
- net: ena: optimize data access in fast-path code (bsc#1208137).
- PCI: hv: Add a per-bus mutex state_lock (bsc#1209785).
- PCI: hv: fix a race condition bug in hv_pci_query_relations() (bsc#1209785).
- PCI: hv: Fix a race condition in hv_irq_unmask() that can cause panic (bsc#1209785).
- PCI: hv: Remove the useless hv_pcichild_state from struct hv_pci_dev (bsc#1209785).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2023-1892,SUSE-SLE-Module-RT-15-SP3-2023-1892,SUSE-SUSE-MicroOS-5.1-2023-1892,SUSE-SUSE-MicroOS-5.2-2023-1892</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      <Description>Link for SUSE-SU-2023:1892-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2023-April/028848.html</URL>
      <Description>E-Mail link for SUSE-SU-2023:1892-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1207168</URL>
      <Description>SUSE Bug 1207168</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1208137</URL>
      <Description>SUSE Bug 1208137</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1208598</URL>
      <Description>SUSE Bug 1208598</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1208601</URL>
      <Description>SUSE Bug 1208601</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1208787</URL>
      <Description>SUSE Bug 1208787</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209052</URL>
      <Description>SUSE Bug 1209052</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209256</URL>
      <Description>SUSE Bug 1209256</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209288</URL>
      <Description>SUSE Bug 1209288</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209289</URL>
      <Description>SUSE Bug 1209289</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209290</URL>
      <Description>SUSE Bug 1209290</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209291</URL>
      <Description>SUSE Bug 1209291</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209366</URL>
      <Description>SUSE Bug 1209366</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209532</URL>
      <Description>SUSE Bug 1209532</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209547</URL>
      <Description>SUSE Bug 1209547</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209549</URL>
      <Description>SUSE Bug 1209549</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209634</URL>
      <Description>SUSE Bug 1209634</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209635</URL>
      <Description>SUSE Bug 1209635</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209636</URL>
      <Description>SUSE Bug 1209636</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209778</URL>
      <Description>SUSE Bug 1209778</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1209785</URL>
      <Description>SUSE Bug 1209785</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2017-5753/</URL>
      <Description>SUSE CVE CVE-2017-5753 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3923/</URL>
      <Description>SUSE CVE CVE-2021-3923 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-4744/</URL>
      <Description>SUSE CVE CVE-2022-4744 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-0394/</URL>
      <Description>SUSE CVE CVE-2023-0394 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-0461/</URL>
      <Description>SUSE CVE CVE-2023-0461 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1075/</URL>
      <Description>SUSE CVE CVE-2023-1075 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1078/</URL>
      <Description>SUSE CVE CVE-2023-1078 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1281/</URL>
      <Description>SUSE CVE CVE-2023-1281 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1382/</URL>
      <Description>SUSE CVE CVE-2023-1382 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1390/</URL>
      <Description>SUSE CVE CVE-2023-1390 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1513/</URL>
      <Description>SUSE CVE CVE-2023-1513 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-1582/</URL>
      <Description>SUSE CVE CVE-2023-1582 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-28327/</URL>
      <Description>SUSE CVE CVE-2023-28327 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-28328/</URL>
      <Description>SUSE CVE CVE-2023-28328 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-28464/</URL>
      <Description>SUSE CVE CVE-2023-28464 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-28466/</URL>
      <Description>SUSE CVE CVE-2023-28466 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2023-28772/</URL>
      <Description>SUSE CVE CVE-2023-28772 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.1">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1" CPE="cpe:/o:suse:suse-microos:5.1">SUSE Linux Enterprise Micro 5.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.2">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.2" CPE="cpe:/o:suse:suse-microos:5.2">SUSE Linux Enterprise Micro 5.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Real Time Module 15 SP3">
      <Branch Type="Product Name" Name="SUSE Real Time Module 15 SP3">
        <FullProductName ProductID="SUSE Real Time Module 15 SP3" CPE="cpe:/o:suse:sle-module-rt:15:sp3">SUSE Real Time Module 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="cluster-md-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="cluster-md-kmp-rt-5.3.18-150300.124.1">cluster-md-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="cluster-md-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="cluster-md-kmp-rt_debug-5.3.18-150300.124.1">cluster-md-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="dlm-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="dlm-kmp-rt-5.3.18-150300.124.1">dlm-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="dlm-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="dlm-kmp-rt_debug-5.3.18-150300.124.1">dlm-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gfs2-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="gfs2-kmp-rt-5.3.18-150300.124.1">gfs2-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gfs2-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="gfs2-kmp-rt_debug-5.3.18-150300.124.1">gfs2-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-devel-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-devel-rt-5.3.18-150300.124.1">kernel-devel-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt-5.3.18-150300.124.1">kernel-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt-devel-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt-devel-5.3.18-150300.124.1">kernel-rt-devel-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt-extra-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt-extra-5.3.18-150300.124.1">kernel-rt-extra-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt-livepatch-devel-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt-livepatch-devel-5.3.18-150300.124.1">kernel-rt-livepatch-devel-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt-optional-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt-optional-5.3.18-150300.124.1">kernel-rt-optional-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt_debug-5.3.18-150300.124.1">kernel-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt_debug-devel-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt_debug-devel-5.3.18-150300.124.1">kernel-rt_debug-devel-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt_debug-extra-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt_debug-extra-5.3.18-150300.124.1">kernel-rt_debug-extra-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt_debug-livepatch-devel-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt_debug-livepatch-devel-5.3.18-150300.124.1">kernel-rt_debug-livepatch-devel-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-rt_debug-optional-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-rt_debug-optional-5.3.18-150300.124.1">kernel-rt_debug-optional-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-source-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-source-rt-5.3.18-150300.124.1">kernel-source-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-syms-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="kernel-syms-rt-5.3.18-150300.124.1">kernel-syms-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kselftests-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="kselftests-kmp-rt-5.3.18-150300.124.1">kselftests-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kselftests-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="kselftests-kmp-rt_debug-5.3.18-150300.124.1">kselftests-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ocfs2-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="ocfs2-kmp-rt-5.3.18-150300.124.1">ocfs2-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ocfs2-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="ocfs2-kmp-rt_debug-5.3.18-150300.124.1">ocfs2-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="reiserfs-kmp-rt-5.3.18-150300.124.1">
      <FullProductName ProductID="reiserfs-kmp-rt-5.3.18-150300.124.1">reiserfs-kmp-rt-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="reiserfs-kmp-rt_debug-5.3.18-150300.124.1">
      <FullProductName ProductID="reiserfs-kmp-rt_debug-5.3.18-150300.124.1">reiserfs-kmp-rt_debug-5.3.18-150300.124.1</FullProductName>
    </Branch>
    <Relationship ProductReference="kernel-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.1">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1">kernel-rt-5.3.18-150300.124.1 as a component of SUSE Linux Enterprise Micro 5.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.2">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1">kernel-rt-5.3.18-150300.124.1 as a component of SUSE Linux Enterprise Micro 5.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="cluster-md-kmp-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1">cluster-md-kmp-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="dlm-kmp-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1">dlm-kmp-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gfs2-kmp-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1">gfs2-kmp-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-devel-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1">kernel-devel-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1">kernel-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-rt-devel-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1">kernel-rt-devel-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-rt_debug-devel-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1">kernel-rt_debug-devel-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-source-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1">kernel-source-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-syms-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1">kernel-syms-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ocfs2-kmp-rt-5.3.18-150300.124.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Real Time Module 15 SP3">
      <FullProductName ProductID="SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1">ocfs2-kmp-rt-5.3.18-150300.124.1 as a component of SUSE Real Time Module 15 SP3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.</Note>
    </Notes>
    <CVE>CVE-2017-5753</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.9</BaseScore>
        <Vector>AV:L/AC:L/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.7</BaseScore>
        <Vector>AV:L/AC:M/Au:N/C:C/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2017-5753.html</URL>
        <Description>CVE-2017-5753</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1068032</URL>
        <Description>SUSE Bug 1068032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074562</URL>
        <Description>SUSE Bug 1074562</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074578</URL>
        <Description>SUSE Bug 1074578</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1074701</URL>
        <Description>SUSE Bug 1074701</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075006</URL>
        <Description>SUSE Bug 1075006</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075419</URL>
        <Description>SUSE Bug 1075419</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1075748</URL>
        <Description>SUSE Bug 1075748</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1080039</URL>
        <Description>SUSE Bug 1080039</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087084</URL>
        <Description>SUSE Bug 1087084</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1087939</URL>
        <Description>SUSE Bug 1087939</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1089055</URL>
        <Description>SUSE Bug 1089055</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1136865</URL>
        <Description>SUSE Bug 1136865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1178658</URL>
        <Description>SUSE Bug 1178658</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201877</URL>
        <Description>SUSE Bug 1201877</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209547</URL>
        <Description>SUSE Bug 1209547</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechanisms.</Note>
    </Notes>
    <CVE>CVE-2021-3923</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3923.html</URL>
        <Description>CVE-2021-3923</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209778</URL>
        <Description>SUSE Bug 1209778</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A double-free flaw was found in the Linux kernel's TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.</Note>
    </Notes>
    <CVE>CVE-2022-4744</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-4744.html</URL>
        <Description>CVE-2022-4744</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209635</URL>
        <Description>SUSE Bug 1209635</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209672</URL>
        <Description>SUSE Bug 1209672</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211833</URL>
        <Description>SUSE Bug 1211833</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A NULL pointer dereference flaw was found in rawv6_push_pending_frames in net/ipv6/raw.c in the network subcomponent in the Linux kernel. This flaw causes the system to crash.</Note>
    </Notes>
    <CVE>CVE-2023-0394</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-0394.html</URL>
        <Description>CVE-2023-0394</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1207168</URL>
        <Description>SUSE Bug 1207168</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">There is a use-after-free vulnerability in the Linux Kernel which can be exploited to achieve local privilege escalation. To reach the vulnerability kernel configuration flag CONFIG_TLS  or CONFIG_XFRM_ESPINTCP  has to be configured, but the operation does not require any privilege.

There is a use-after-free bug of icsk_ulp_data  of a struct inet_connection_sock.

When CONFIG_TLS  is enabled, user can install a tls context (struct tls_context) on a connected tcp socket. The context is not cleared if this socket is disconnected and reused as a listener. If a new socket is created from the listener, the context is inherited and vulnerable.

The setsockopt  TCP_ULP  operation does not require any privilege.

We recommend upgrading past commit  2c02d41d71f90a5168391b6a5f2954112ba2307c</Note>
    </Notes>
    <CVE>CVE-2023-0461</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-0461.html</URL>
        <Description>CVE-2023-0461</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208787</URL>
        <Description>SUSE Bug 1208787</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208911</URL>
        <Description>SUSE Bug 1208911</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211833</URL>
        <Description>SUSE Bug 1211833</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1217079</URL>
        <Description>SUSE Bug 1217079</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1218514</URL>
        <Description>SUSE Bug 1218514</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Linux Kernel. The tls_is_tx_ready() incorrectly checks for list emptiness, potentially accessing a type confused entry to the list_head, leaking the last byte of the confused field that overlaps with rec-&gt;tx_ready.</Note>
    </Notes>
    <CVE>CVE-2023-1075</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1075.html</URL>
        <Description>CVE-2023-1075</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208598</URL>
        <Description>SUSE Bug 1208598</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.</Note>
    </Notes>
    <CVE>CVE-2023-1078</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1078.html</URL>
        <Description>CVE-2023-1078</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208601</URL>
        <Description>SUSE Bug 1208601</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208603</URL>
        <Description>SUSE Bug 1208603</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation.  The imperfect hash area can be updated while packets are traversing, which will cause a use-after-free when 'tcf_exts_exec()' is called with the destroyed tcf_ext.  A local attacker user can use this vulnerability to elevate its privileges to root.
This issue affects Linux Kernel: from 4.14 before git commit ee059170b1f7e94e55fa6cadee544e176a6e59c2.</Note>
    </Notes>
    <CVE>CVE-2023-1281</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1281.html</URL>
        <Description>CVE-2023-1281</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209634</URL>
        <Description>SUSE Bug 1209634</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209683</URL>
        <Description>SUSE Bug 1209683</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1210335</URL>
        <Description>SUSE Bug 1210335</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1210423</URL>
        <Description>SUSE Bug 1210423</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211833</URL>
        <Description>SUSE Bug 1211833</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A data race flaw was found in the Linux kernel, between where con is allocated and con-&gt;sock is set. This issue leads to a NULL pointer dereference when accessing con-&gt;sock-&gt;sk in net/tipc/topsrv.c in the tipc protocol in the Linux kernel.</Note>
    </Notes>
    <CVE>CVE-2023-1382</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1382.html</URL>
        <Description>CVE-2023-1382</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209288</URL>
        <Description>SUSE Bug 1209288</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A remote denial of service vulnerability was found in the Linux kernel's TIPC kernel module. The while loop in tipc_link_xmit() hits an unknown state while attempting to parse SKBs, which are not in the queue. Sending two small UDP packets to a system with a UDP bearer results in the CPU utilization for the system to instantly spike to 100%, causing a denial of service condition.</Note>
    </Notes>
    <CVE>CVE-2023-1390</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1390.html</URL>
        <Description>CVE-2023-1390</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209289</URL>
        <Description>SUSE Bug 1209289</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1210779</URL>
        <Description>SUSE Bug 1210779</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211495</URL>
        <Description>SUSE Bug 1211495</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.</Note>
    </Notes>
    <CVE>CVE-2023-1513</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1513.html</URL>
        <Description>CVE-2023-1513</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209532</URL>
        <Description>SUSE Bug 1209532</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. This issue may allow a local attacker with user privilege to cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2023-1582</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-1582.html</URL>
        <Description>CVE-2023-1582</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209636</URL>
        <Description>SUSE Bug 1209636</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A NULL pointer dereference flaw was found in the UNIX protocol in net/unix/diag.c In unix_diag_get_exact in the Linux Kernel. The newly allocated skb does not have sk, leading to a NULL pointer. This flaw allows a local user to crash or potentially cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2023-28327</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-28327.html</URL>
        <Description>CVE-2023-28327</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209290</URL>
        <Description>SUSE Bug 1209290</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A NULL pointer dereference flaw was found in the az6027 driver in drivers/media/usb/dev-usb/az6027.c in the Linux Kernel. The message from user space is not checked properly before transferring into the device. This flaw allows a local user to crash the system or potentially cause a denial of service.</Note>
    </Notes>
    <CVE>CVE-2023-28328</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-28328.html</URL>
        <Description>CVE-2023-28328</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209291</URL>
        <Description>SUSE Bug 1209291</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1222212</URL>
        <Description>SUSE Bug 1222212</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.</Note>
    </Notes>
    <CVE>CVE-2023-28464</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-28464.html</URL>
        <Description>CVE-2023-28464</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209052</URL>
        <Description>SUSE Bug 1209052</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211111</URL>
        <Description>SUSE Bug 1211111</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1220130</URL>
        <Description>SUSE Bug 1220130</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">do_tls_getsockopt in net/tls/tls_main.c in the Linux kernel through 6.2.6 lacks a lock_sock call, leading to a race condition (with a resultant use-after-free or NULL pointer dereference).</Note>
    </Notes>
    <CVE>CVE-2023-28466</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-28466.html</URL>
        <Description>CVE-2023-28466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209366</URL>
        <Description>SUSE Bug 1209366</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1210452</URL>
        <Description>SUSE Bug 1210452</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211833</URL>
        <Description>SUSE Bug 1211833</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1213841</URL>
        <Description>SUSE Bug 1213841</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.</Note>
    </Notes>
    <CVE>CVE-2023-28772</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Micro 5.1:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.2:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:cluster-md-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:dlm-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:gfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-devel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-rt_debug-devel-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-source-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:kernel-syms-rt-5.3.18-150300.124.1</ProductID>
        <ProductID>SUSE Real Time Module 15 SP3:ocfs2-kmp-rt-5.3.18-150300.124.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2023/suse-su-20231892-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2023-28772.html</URL>
        <Description>CVE-2023-28772</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1209549</URL>
        <Description>SUSE Bug 1209549</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211110</URL>
        <Description>SUSE Bug 1211110</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1214378</URL>
        <Description>SUSE Bug 1214378</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
