Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-31315 |
CWE-ID | CWE-264 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
openSUSE Leap Micro Operating systems & Components / Operating system SUSE Linux Enterprise Micro Operating systems & Components / Operating system Basesystem Module Operating systems & Components / Operating system SUSE Linux Enterprise Server for SAP Applications 15 Operating systems & Components / Operating system SUSE Linux Enterprise Server 15 Operating systems & Components / Operating system SUSE Linux Enterprise Real Time 15 Operating systems & Components / Operating system SUSE Linux Enterprise High Performance Computing 15 Operating systems & Components / Operating system SUSE Linux Enterprise Desktop 15 Operating systems & Components / Operating system openSUSE Leap Operating systems & Components / Operating system kernel-firmware-amdgpu Operating systems & Components / Operating system package or component kernel-firmware-nvidia Operating systems & Components / Operating system package or component kernel-firmware-serial Operating systems & Components / Operating system package or component kernel-firmware-radeon Operating systems & Components / Operating system package or component ucode-amd Operating systems & Components / Operating system package or component kernel-firmware-all Operating systems & Components / Operating system package or component kernel-firmware-usb-network Operating systems & Components / Operating system package or component kernel-firmware-realtek Operating systems & Components / Operating system package or component kernel-firmware-dpaa2 Operating systems & Components / Operating system package or component kernel-firmware-prestera Operating systems & Components / Operating system package or component kernel-firmware-platform Operating systems & Components / Operating system package or component kernel-firmware-qlogic Operating systems & Components / Operating system package or component kernel-firmware-marvell Operating systems & Components / Operating system package or component kernel-firmware-qcom Operating systems & Components / Operating system package or component kernel-firmware-ath10k Operating systems & Components / Operating system package or component kernel-firmware-media Operating systems & Components / Operating system package or component kernel-firmware-i915 Operating systems & Components / Operating system package or component kernel-firmware-ti Operating systems & Components / Operating system package or component kernel-firmware Operating systems & Components / Operating system package or component kernel-firmware-mediatek Operating systems & Components / Operating system package or component kernel-firmware-atheros Operating systems & Components / Operating system package or component kernel-firmware-iwlwifi Operating systems & Components / Operating system package or component kernel-firmware-network Operating systems & Components / Operating system package or component kernel-firmware-mellanox Operating systems & Components / Operating system package or component kernel-firmware-ath11k Operating systems & Components / Operating system package or component kernel-firmware-sound Operating systems & Components / Operating system package or component kernel-firmware-bnx2 Operating systems & Components / Operating system package or component kernel-firmware-bluetooth Operating systems & Components / Operating system package or component kernel-firmware-ueagle Operating systems & Components / Operating system package or component kernel-firmware-intel Operating systems & Components / Operating system package or component kernel-firmware-chelsio Operating systems & Components / Operating system package or component kernel-firmware-mwifiex Operating systems & Components / Operating system package or component kernel-firmware-brcm Operating systems & Components / Operating system package or component kernel-firmware-nfp Operating systems & Components / Operating system package or component kernel-firmware-liquidio Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU96619
Risk: Low
CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-31315
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper validation in a model specific register (MSR). A malicious application with ring0 access can modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
MitigationUpdate the affected package kernel-firmware to the latest version.
Vulnerable software versionsopenSUSE Leap Micro: 5.5
SUSE Linux Enterprise Micro: 5.5
Basesystem Module: 15-SP5
SUSE Linux Enterprise Server for SAP Applications 15: SP5
SUSE Linux Enterprise Server 15: SP5
SUSE Linux Enterprise Real Time 15: SP5
SUSE Linux Enterprise High Performance Computing 15: SP5
SUSE Linux Enterprise Desktop 15: SP5
openSUSE Leap: 15.5
kernel-firmware-amdgpu: before 20230724-150500.3.12.1
kernel-firmware-nvidia: before 20230724-150500.3.12.1
kernel-firmware-serial: before 20230724-150500.3.12.1
kernel-firmware-radeon: before 20230724-150500.3.12.1
ucode-amd: before 20230724-150500.3.12.1
kernel-firmware-all: before 20230724-150500.3.12.1
kernel-firmware-usb-network: before 20230724-150500.3.12.1
kernel-firmware-realtek: before 20230724-150500.3.12.1
kernel-firmware-dpaa2: before 20230724-150500.3.12.1
kernel-firmware-prestera: before 20230724-150500.3.12.1
kernel-firmware-platform: before 20230724-150500.3.12.1
kernel-firmware-qlogic: before 20230724-150500.3.12.1
kernel-firmware-marvell: before 20230724-150500.3.12.1
kernel-firmware-qcom: before 20230724-150500.3.12.1
kernel-firmware-ath10k: before 20230724-150500.3.12.1
kernel-firmware-media: before 20230724-150500.3.12.1
kernel-firmware-i915: before 20230724-150500.3.12.1
kernel-firmware-ti: before 20230724-150500.3.12.1
kernel-firmware: before 20230724-150500.3.12.1
kernel-firmware-mediatek: before 20230724-150500.3.12.1
kernel-firmware-atheros: before 20230724-150500.3.12.1
kernel-firmware-iwlwifi: before 20230724-150500.3.12.1
kernel-firmware-network: before 20230724-150500.3.12.1
kernel-firmware-mellanox: before 20230724-150500.3.12.1
kernel-firmware-ath11k: before 20230724-150500.3.12.1
kernel-firmware-sound: before 20230724-150500.3.12.1
kernel-firmware-bnx2: before 20230724-150500.3.12.1
kernel-firmware-bluetooth: before 20230724-150500.3.12.1
kernel-firmware-ueagle: before 20230724-150500.3.12.1
kernel-firmware-intel: before 20230724-150500.3.12.1
kernel-firmware-chelsio: before 20230724-150500.3.12.1
kernel-firmware-mwifiex: before 20230724-150500.3.12.1
kernel-firmware-brcm: before 20230724-150500.3.12.1
kernel-firmware-nfp: before 20230724-150500.3.12.1
kernel-firmware-liquidio: before 20230724-150500.3.12.1
CPE2.3https://www.suse.com/support/update/announcement/2024/suse-su-20243081-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.