Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

openSUSE Leap 15.5: Kernel Important Multiple Fixes for CVE-2025-21756

opensuse
Calendar Grey September 29, 2025
Scroller Opensuse
A vital kernel update for openSUSE addresses critical vulnerabilities with serious potential consequences.
An update that solves six vulnerabilities can now be installed.

Description

This update for the Linux Kernel 5.14.21-150500_55_97 fixes several issues.

The following security issues were fixed:

* CVE-2025-38177: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1246356).

* CVE-2025-38181: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr()

(bsc#1246001).

* CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours

mounts (bsc#1247499).

* CVE-2025-38555: usb: gadget : fix use-after-free in composite_dev_cleanup()

(bsc#1248298).

* CVE-2025-21756: vsock: Keep the binding until socket destruction

(bsc#1245795).

* CVE-2025-21755: vsock: Orphan socket after transport release (bsc#1245795).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch SUSE-2025-3394=1 SUSE-2025-3395=1

* SUSE Linux Enterprise Live Patching 15-SP5

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2025-3394=1 SUSE-SLE-

Module-Live-Patching-15-SP5-2025-3395=1

Package List

* openSUSE Leap 15.5 (ppc64le s390x x86_64)

* kernel-livepatch-SLE15-SP5_Update_21-debugsource-11-150500.2.1

* kernel-livepatch-SLE15-SP5_Update_24-debugsource-7-150500.2.1

* kernel-livepatch-5_14_21-150500_55_97-default-debuginfo-7-150500.2.1

* kernel-livepatch-5_14_21-150500_55_88-default-debuginfo-11-150500.2.1

* kernel-livepatch-5_14_21-150500_55_88-default-11-150500.2.1

* kernel-livepatch-5_14_21-150500_55_97-default-7-150500.2.1

* SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64)

* kernel-livepatch-SLE15-SP5_Update_21-debugsource-11-150500.2.1

* kernel-livepatch-SLE15-SP5_Update_24-debugsource-7-150500.2.1

* kernel-livepatch-5_14_21-150500_55_97-default-debuginfo-7-150500.2.1

* kernel-livepatch-5_14_21-150500_55_88-default-debuginfo-11-150500.2.1

* kernel-livepatch-5_14_21-150500_55_88-default-11-150500.2.1

* kernel-livepatch-5_14_21-150500_55_97-default-7-150500.2.1

References

* bsc#1245795

* bsc#1246001

* bsc#1246356

* bsc#1247499

* bsc#1248298

## References:

* https://www.suse.com/security/cve/CVE-2025-21755.html

* https://www.suse.com/security/cve/CVE-2025-21756.html

* https://www.suse.com/security/cve/CVE-2025-38177.html

* https://www.suse.com/security/cve/CVE-2025-38181.html

* https://www.suse.com/security/cve/CVE-2025-38498.html

* https://www.suse.com/security/cve/CVE-2025-38555.html

* https://bugzilla.suse.com/show_bug.cgi?id=1245795

* https://bugzilla.suse.com/show_bug.cgi?id=1246001

* https://bugzilla.suse.com/show_bug.cgi?id=1246356

* https://bugzilla.suse.com/show_bug.cgi?id=1247499

* https://bugzilla.suse.com/show_bug.cgi?id=1248298

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2025:03395-1
Release Date: 2025-09-27T14:03:45Z
Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.