{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Module for Live Patching 15-SP3","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP2","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP Applications 15-SP3","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"openSUSE Leap 15.3","product":{"name":"openSUSE Leap","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE CaaS Platform 4.0","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Live Patching 12-SP5","product":{"name":"SUSE Linux Enterprise Live Patching","vendor":{"name":"SUSE","scada":false}}},{"description":"openSUSE Leap 15.4","product":{"name":"openSUSE Leap","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15-SP2","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP Applications 15-SP1","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Real Time Extension 12-SP5","product":{"name":"SUSE Linux Enterprise Real Time","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Storage 6","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Micro 5.1","product":{"name":"SUSE Linux Enterprise Micro","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15-SP3","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP 15-SP1","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Manager Server 4.0","product":{"name":"SUSE Manager Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Module for Live Patching 15-SP1","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Module for Live Patching 15-SP4","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP Applications 15-SP4","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Manager Proxy 4.0","product":{"name":"SUSE Manager Proxy","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP1-BCL","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Module for Live Patching 15","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15-SP4","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15-SP1","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP1-LTSS","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Enterprise Storage 6","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Availability 15-SP1","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise High Performance Computing 15","product":{"name":"SUSE Linux Enterprise High Performance Computing","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP4","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP Applications 15-SP2","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Module for Live Patching 15-SP2","product":{"name":"N/A","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server for SAP Applications 15","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP3","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15-SP1","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Linux Enterprise Server 15","product":{"name":"SUSE Linux Enterprise Server","vendor":{"name":"SUSE","scada":false}}},{"description":"SUSE Manager Retail Branch Server 4.0","product":{"name":"SUSE Manager Retail Branch Server","vendor":{"name":"SUSE","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2022-29581","url":"https://www.cve.org/CVERecord?id=CVE-2022-29581"},{"name":"CVE-2022-2977","url":"https://www.cve.org/CVERecord?id=CVE-2022-2977"},{"name":"CVE-2021-4203","url":"https://www.cve.org/CVERecord?id=CVE-2021-4203"},{"name":"CVE-2022-1652","url":"https://www.cve.org/CVERecord?id=CVE-2022-1652"},{"name":"CVE-2022-2639","url":"https://www.cve.org/CVERecord?id=CVE-2022-2639"},{"name":"CVE-2020-36516","url":"https://www.cve.org/CVERecord?id=CVE-2020-36516"},{"name":"CVE-2022-2663","url":"https://www.cve.org/CVERecord?id=CVE-2022-2663"},{"name":"CVE-2022-39188","url":"https://www.cve.org/CVERecord?id=CVE-2022-39188"},{"name":"CVE-2022-1012","url":"https://www.cve.org/CVERecord?id=CVE-2022-1012"},{"name":"CVE-2022-20368","url":"https://www.cve.org/CVERecord?id=CVE-2022-20368"},{"name":"CVE-2022-26373","url":"https://www.cve.org/CVERecord?id=CVE-2022-26373"},{"name":"CVE-2022-36879","url":"https://www.cve.org/CVERecord?id=CVE-2022-36879"},{"name":"CVE-2022-2588","url":"https://www.cve.org/CVERecord?id=CVE-2022-2588"},{"name":"CVE-2021-39698","url":"https://www.cve.org/CVERecord?id=CVE-2021-39698"},{"name":"CVE-2022-20369","url":"https://www.cve.org/CVERecord?id=CVE-2022-20369"},{"name":"CVE-2022-21385","url":"https://www.cve.org/CVERecord?id=CVE-2022-21385"},{"name":"CVE-2022-3028","url":"https://www.cve.org/CVERecord?id=CVE-2022-3028"}],"links":[{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223412-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 27 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223432-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 27 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223433-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223411-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 27\u00a0septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223424-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26\u00a0septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223409-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 27 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223422-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223406-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223415-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223407-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 27 septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223445-1/"},{"title":"Bulletin de s\u00e9curit\u00e9 SUSE du 26\u00a0septembre 2022","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223408-1/"}],"reference":"CERTFR-2022-AVI-857","revisions":[{"description":"Version initiale","revision_date":"2022-09-28T00:00:00.000000"}],"risks":[{"description":"D\u00e9ni de service"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"},{"description":"\u00c9l\u00e9vation de privil\u00e8ges"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 corrig\u00e9es dans <span\nclass=\"textit\">le noyau Linux de SUSE</span>. Elles permettent \u00e0 un\nattaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, un contournement de\nla politique de s\u00e9curit\u00e9, un d\u00e9ni de service et une atteinte \u00e0 la\nconfidentialit\u00e9 des donn\u00e9es.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans le noyau Linux de SUSE","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3445-1 du 27 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3411-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3406-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3433-1 du 27 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3408-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3407-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3432-1 du 27 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3415-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3422-1 du 27 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3412-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3409-1 du 26 septembre 2022","url":null},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 SUSE SUSE-SU-2022:3424-1 du 27 septembre 2022","url":null}]}
