Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-31315 |
CWE-ID | CWE-264 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
SUSE Linux Enterprise Server 15 SP4 LTSS Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing LTSS 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing ESPOS 15 Operating systems & Components / Operating system SUSE Linux Enterprise Desktop 15 SP4 LTSS Operating systems & Components / Operating system SUSE Linux Enterprise Micro for Rancher Operating systems & Components / Operating system SUSE Linux Enterprise Micro Operating systems & Components / Operating system SUSE Linux Enterprise Server for SAP Applications 15 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing 15 Operating systems & Components / Operating system SUSE Manager Retail Branch Server Operating systems & Components / Operating system SUSE Manager Server Operating systems & Components / Operating system SUSE Manager Proxy Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system kernel-firmware-qcom Operating systems & Components / Operating system package or component kernel-firmware-realtek Operating systems & Components / Operating system package or component kernel-firmware-serial Operating systems & Components / Operating system package or component kernel-firmware-mediatek Operating systems & Components / Operating system package or component kernel-firmware-ueagle Operating systems & Components / Operating system package or component ucode-amd Operating systems & Components / Operating system package or component kernel-firmware-dpaa2 Operating systems & Components / Operating system package or component kernel-firmware-network Operating systems & Components / Operating system package or component kernel-firmware-mwifiex Operating systems & Components / Operating system package or component kernel-firmware-ath11k Operating systems & Components / Operating system package or component kernel-firmware-qlogic Operating systems & Components / Operating system package or component kernel-firmware-media Operating systems & Components / Operating system package or component kernel-firmware-atheros Operating systems & Components / Operating system package or component kernel-firmware-radeon Operating systems & Components / Operating system package or component kernel-firmware-prestera Operating systems & Components / Operating system package or component kernel-firmware-nvidia Operating systems & Components / Operating system package or component kernel-firmware-marvell Operating systems & Components / Operating system package or component kernel-firmware-iwlwifi Operating systems & Components / Operating system package or component kernel-firmware-bluetooth Operating systems & Components / Operating system package or component kernel-firmware-nfp Operating systems & Components / Operating system package or component kernel-firmware-ti Operating systems & Components / Operating system package or component kernel-firmware-usb-network Operating systems & Components / Operating system package or component kernel-firmware-intel Operating systems & Components / Operating system package or component kernel-firmware-amdgpu Operating systems & Components / Operating system package or component kernel-firmware-all Operating systems & Components / Operating system package or component kernel-firmware-liquidio Operating systems & Components / Operating system package or component kernel-firmware-i915 Operating systems & Components / Operating system package or component kernel-firmware-platform Operating systems & Components / Operating system package or component kernel-firmware-mellanox Operating systems & Components / Operating system package or component kernel-firmware Operating systems & Components / Operating system package or component kernel-firmware-chelsio Operating systems & Components / Operating system package or component kernel-firmware-sound Operating systems & Components / Operating system package or component kernel-firmware-brcm Operating systems & Components / Operating system package or component kernel-firmware-bnx2 Operating systems & Components / Operating system package or component kernel-firmware-ath10k Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU96619
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-31315
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper validation in a model specific register (MSR). A malicious application with ring0 access can modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
MitigationUpdate the affected package kernel-firmware to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Server 15 SP4 LTSS: 15-SP4
SUSE Linux Enterprise High Performance Computing LTSS 15: SP4
SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4
SUSE Linux Enterprise Desktop 15 SP4 LTSS: 15-SP4
SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4
SUSE Linux Enterprise Micro: 5.3 - 5.4
SUSE Linux Enterprise Server for SAP Applications 15: SP4
SUSE Linux Enterprise Server 15: SP4
SUSE Linux Enterprise High Performance Computing 15: SP4
SUSE Manager Retail Branch Server: 4.3
SUSE Manager Server: 4.3
SUSE Manager Proxy: 4.3
openSUSE Leap: 15.4
kernel-firmware-qcom: before 20220509-150400.4.28.1
kernel-firmware-realtek: before 20220509-150400.4.28.1
kernel-firmware-serial: before 20220509-150400.4.28.1
kernel-firmware-mediatek: before 20220509-150400.4.28.1
kernel-firmware-ueagle: before 20220509-150400.4.28.1
ucode-amd: before 20220509-150400.4.28.1
kernel-firmware-dpaa2: before 20220509-150400.4.28.1
kernel-firmware-network: before 20220509-150400.4.28.1
kernel-firmware-mwifiex: before 20220509-150400.4.28.1
kernel-firmware-ath11k: before 20220509-150400.4.28.1
kernel-firmware-qlogic: before 20220509-150400.4.28.1
kernel-firmware-media: before 20220509-150400.4.28.1
kernel-firmware-atheros: before 20220509-150400.4.28.1
kernel-firmware-radeon: before 20220509-150400.4.28.1
kernel-firmware-prestera: before 20220509-150400.4.28.1
kernel-firmware-nvidia: before 20220509-150400.4.28.1
kernel-firmware-marvell: before 20220509-150400.4.28.1
kernel-firmware-iwlwifi: before 20220509-150400.4.28.1
kernel-firmware-bluetooth: before 20220509-150400.4.28.1
kernel-firmware-nfp: before 20220509-150400.4.28.1
kernel-firmware-ti: before 20220509-150400.4.28.1
kernel-firmware-usb-network: before 20220509-150400.4.28.1
kernel-firmware-intel: before 20220509-150400.4.28.1
kernel-firmware-amdgpu: before 20220509-150400.4.28.1
kernel-firmware-all: before 20220509-150400.4.28.1
kernel-firmware-liquidio: before 20220509-150400.4.28.1
kernel-firmware-i915: before 20220509-150400.4.28.1
kernel-firmware-platform: before 20220509-150400.4.28.1
kernel-firmware-mellanox: before 20220509-150400.4.28.1
kernel-firmware: before 20220509-150400.4.28.1
kernel-firmware-chelsio: before 20220509-150400.4.28.1
kernel-firmware-sound: before 20220509-150400.4.28.1
kernel-firmware-brcm: before 20220509-150400.4.28.1
kernel-firmware-bnx2: before 20220509-150400.4.28.1
kernel-firmware-ath10k: before 20220509-150400.4.28.1
CPE2.3https://www.suse.com/support/update/announcement/2024/suse-su-20242980-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.