CVE.RADIO
FREN

CVE-2023-20585

noyau Linux de SUSEVulnerabilityCVSS 5.6Patched

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

No public exploitation has been reported so far. A fixed version is available (see the table below).

Recommended action: Update to the fixed version listed for your distribution using the native package manager.

CVE-2023-20585 noyau Linux de SUSE Vulnerability

Severity metrics

CVSS 4.0 : 5.6 MEDIUM

Attack vectorLocal
Attack complexityHigh
Attack requirementsNone
Privileges requiredHigh
User interactionNone
Confidentiality impactNone
Integrity impactHigh
Availability impactNone
Subsequent confidentialityNone
Subsequent integrityNone
Subsequent availabilityNone

Vector: AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Key points

Affected & fixed versions by distribution

Versions are the native distribution strings (backport-aware): RHEL/Debian/SUSE backport fixes, so compare with the distro version comparator (dpkg / rpm / vercmp), not the upstream version.

DistributionPackageAffectedFixed versionStatus
SUSE:Linux Micro 6.2kernel-default-base-6.12.0-160000.34.1.160000.2.15fixed
SUSE:Linux Enterprise Server 16.0kernel-default-base-6.12.0-160000.34.1.160000.2.15fixed
SUSE:Linux Enterprise Server for SAP applications 16.0kernel-default-base-6.12.0-160000.34.1.160000.2.15fixed
SUSE:Linux Enterprise Module for Basesystem 15 SP7kernel-default-base-6.4.0-150700.53.55.1.150700.17.33.1fixed

Sources

Published 2026-07-24 · updated 2026-07-26 · source: CERT-FR Avis