The SUSE Linux Enterprise 15 SP6 RT kernel was updated to receive various
security bugfixes.
The following security bugs were fixed:
* CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing
speculative execution may (bsc#1139073)
* CVE-2024-36028: mm/hugetlb: fix DEBUG_LOCKS_WARN_ON(1) when
dissolve_free_hugetlb_folio() (bsc#1225707).
* CVE-2024-36348, CVE-2024-36349, CVE-2024-36350, CVE-2024-36357: x86/process:
Move the buffer clearing before MONITOR (bsc#1238896).
* CVE-2024-44963: btrfs: do not BUG_ON() when freeing tree block after error
(bsc#1230216).
* CVE-2024-56742: vfio/mlx5: Fix an unwind issue in
mlx5vf_add_migration_pages() (bsc#1235613).
* CVE-2025-21839: KVM: x86: Load DR6 with guest value only before entering
.vcpu_run() loop (bsc#1239061).
* CVE-2025-21872: efi/mokvar-table: Avoid repeated map/unmap of the same page
(bsc#1240323).
* CVE-2025-23163: net: vlan: do not propagate flags on open (bsc#1242837).
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-3023=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-3023=1
* SUSE Real Time Module 15-SP6
zypper in -t patch SUSE-SLE-Module-RT-15-SP6-2025-3023=1
* openSUSE Leap 15.6 (x86_64)
* kernel-rt-vdso-6.4.0-150600.10.49.1
* kernel-syms-rt-6.4.0-150600.10.49.1
* reiserfs-kmp-rt-debuginfo-6.4.0-150600.10.49.1
* kernel-rt-optional-6.4.0-150600.10.49.1
* dlm-kmp-rt-6.4.0-150600.10.49.1
* kernel-rt-debugsource-6.4.0-150600.10.49.1
* gfs2-kmp-rt-debuginfo-6.4.0-150600.10.49.1
* gfs2-kmp-rt-6.4.0-150600.10.49.1
* kernel-rt-vdso-debuginfo-6.4.0-150600.10.49.1
* kernel-rt-livepatch-devel-6.4.0-150600.10.49.1
* kernel-rt_debug-debugsource-6.4.0-150600.10.49.1
* kernel-rt-devel-debuginfo-6.4.0-150600.10.49.1
* kernel-rt_debug-vdso-6.4.0-150600.10.49.1
* ocfs2-kmp-rt-6.4.0-150600.10.49.1
* kernel-rt-debuginfo-6.4.0-150600.10.49.1
* kernel-rt-devel-6.4.0-150600.10.49.1
* kselftests-kmp-rt-debuginfo-6.4.0-150600.10.49.1
* kernel-rt-extra-debuginfo-6.4.0-150600.10.49.1
* cluster-md-kmp-rt-debuginfo-6.4.0-150600.10.49.1
* kernel-rt-extra-6.4.0-150600.10.49.1
* kernel-rt_debug-devel-6.4.0-150600.10.49.1
* ocfs2-kmp-rt-debuginfo-6.4.0-150600.10.49.1
*...
Read the Full Advisory* bsc#1139073
* bsc#1204142
* bsc#1219338
* bsc#1225707
* bsc#1230216
* bsc#1233300
* bsc#1235613
* bsc#1235837
* bsc#1236333
* bsc#1236897
* bsc#1238896
* bsc#1239061
* bsc#1240323
* bsc#1240885
* bsc#1240966
* bsc#1241166
* bsc#1241345
* bsc#1242086
* bsc#1242414
* bsc#1242837
* bsc#1242960
* bsc#1242965
* bsc#1242993
* bsc#1243068
* bsc#1243100
* bsc#1243479
* bsc#1243669
* bsc#1243806
* bsc#1244309
* bsc#1244457
* bsc#1244735
* bsc#1244749
* bsc#1244750
* bsc#1244792
* bsc#1244801
* bsc#1245151
* bsc#1245201
* bsc#1245202
* bsc#1245216
* bsc#1245260
* bsc#1245431
* bsc#1245440
* bsc#1245457
* bsc#1245498
* bsc#1245499
* bsc#1245504
* bsc#1245506
* bsc#1245508
* bsc#1245510
* bsc#1245540
* bsc#1245598
* bsc#1245599
* bsc#1245646
* bsc#1245647
* bsc#1245649
* bsc#1245650
* bsc#1245654
* bsc#1245658
* bsc#1245660
* bsc#1245665
* bsc#1245666
* bsc#1245668
* bsc#1245669
* bsc#1245670
* bsc#1245671
* bsc#1245675
* bsc#1245676
* bsc#1245677
* bsc#1245679
* bsc#1245682
* bsc#1245683
* bsc#1245684
* bsc#1245688
* bsc#1245689
* bsc#1245690
* bsc#1245691
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.