The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2022-48933: netfilter: nf_tables: fix memory leak during stateful obj
update (bsc#1229621).
* CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981).
* CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt
(bsc#1238032).
* CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493).
* CVE-2024-46763: fou: Fix null-ptr-deref in GRO (bsc#1230764).
* CVE-2024-50038: netfilter: xtables: avoid NFPROTO_UNSPEC where needed
(bsc#1231910).
* CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865).
* CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo
array (bsc#1238747).
* CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512).
* CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471).
* CVE-2025-21839: KVM:...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP5
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2025-1620=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1620=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1620=1
* SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1620=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1620=1
* openSUSE Leap 15.5
zypper in -t patch SUSE-2025-1620=1
* SUSE Linux Enterprise Micro 5.5
zypper in -t patch SUSE-SLE-Micro-5.5-2025-1620=1
* SUSE Linux Enterprise Live Patching 15-SP5 (nosrc)
* kernel-default-5.14.21-150500.55.103.1
* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)
* kernel-livepatch-5_14_21-150500_55_103-default-1-150500.11.3.1
* kernel-livepatch-5_14_21-150500_55_103-default-debuginfo-1-150500.11.3.1
* kernel-default-debuginfo-5.14.21-150500.55.103.1
* kernel-default-debugsource-5.14.21-150500.55.103.1
* kernel-livepatch-SLE15-SP5_Update_26-debugsource-1-150500.11.3.1
* kernel-default-livepatch-devel-5.14.21-150500.55.103.1
* kernel-default-livepatch-5.14.21-150500.55.103.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* kernel-default-devel-5.14.21-150500.55.103.1
* cluster-md-kmp-default-debuginfo-5.14.21-150500.55.103.1
* kernel-obs-build-5.14.21-150500.55.103.1
* ocfs2-kmp-default-5.14.21-150500.55.103.1
* cluster-md-kmp-default-5.14.21-150500.55.103.1
* gfs2-kmp-default-debuginfo-5.14.21-150500.55.103.1
* kernel-default-devel-debuginfo-5.14.21-150500.55.103.1
*...
Read the Full Advisory* bsc#1054914
* bsc#1206843
* bsc#1210409
* bsc#1225903
* bsc#1229361
* bsc#1229621
* bsc#1230764
* bsc#1231103
* bsc#1231910
* bsc#1236777
* bsc#1237981
* bsc#1238032
* bsc#1238471
* bsc#1238512
* bsc#1238747
* bsc#1238865
* bsc#1239061
* bsc#1239684
* bsc#1239968
* bsc#1240209
* bsc#1240211
* bsc#1240214
* bsc#1240228
* bsc#1240230
* bsc#1240246
* bsc#1240248
* bsc#1240269
* bsc#1240271
* bsc#1240274
* bsc#1240285
* bsc#1240295
* bsc#1240306
* bsc#1240314
* bsc#1240315
* bsc#1240321
* bsc#1240747
* bsc#1240835
* bsc#1241280
* bsc#1241371
* bsc#1241421
* bsc#1241433
* bsc#1241541
* bsc#1241625
* bsc#1241648
* bsc#1242284
* bsc#1242493
* bsc#1242778
## References:
* https://www.suse.com/security/cve/CVE-2021-47671.html
* https://www.suse.com/security/cve/CVE-2022-48933.html
* https://www.suse.com/security/cve/CVE-2022-49110.html
* https://www.suse.com/security/cve/CVE-2022-49139.html
* https://www.suse.com/security/cve/CVE-2022-49741.html
* https://www.suse.com/security/cve/CVE-2022-49745.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.