The SUSE Linux Enterprise 15 SP6 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2025-21682: eth: bnxt: always recalculate features after XDP clearing,
fix null-deref (bsc#1236703).
* CVE-2025-21678: gtp: Destroy device along with udp socket's netns dismantle
(bsc#1236698).
* CVE-2025-21676: net: fec: handle page_pool_dev_alloc_pages error
(bsc#1236696).
* CVE-2025-21675: net/mlx5: Clear port select structure when fail to create
(bsc#1236694).
* CVE-2025-21674: net/mlx5e: Fix inversion dependency warning while enabling
IPsec tunnel (bsc#1236688).
* CVE-2025-21670: vsock/bpf: return early if transport is not assigned
(bsc#1236685).
* CVE-2025-21669: vsock/virtio: discard packets if the transport changes
(bsc#1236683).
* CVE-2025-21666: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]
(bsc#1236680).
* CVE-2025-21664: dm thin: make get_first_thin use rcu-safe list first
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-499=1 SUSE-2025-499=1
* Basesystem Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-499=1
* Development Tools Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-499=1
* Legacy Module 15-SP6
zypper in -t patch SUSE-SLE-Module-Legacy-15-SP6-2025-499=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-499=1
Please note that this is the initial kernel livepatch without fixes itself, this
package is later updated by separate standalone kernel livepatch updates.
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2025-499=1
* SUSE Linux Enterprise Workstation Extension 15 SP6
zypper in -t...
Read the Full Advisory* openSUSE Leap 15.6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.38.1
* openSUSE Leap 15.6 (noarch)
* kernel-devel-6.4.0-150600.23.38.1
* kernel-source-vanilla-6.4.0-150600.23.38.1
* kernel-macros-6.4.0-150600.23.38.1
* kernel-source-6.4.0-150600.23.38.1
* kernel-docs-html-6.4.0-150600.23.38.1
* openSUSE Leap 15.6 (nosrc ppc64le x86_64)
* kernel-debug-6.4.0-150600.23.38.1
* openSUSE Leap 15.6 (ppc64le x86_64)
* kernel-debug-devel-debuginfo-6.4.0-150600.23.38.1
* kernel-debug-debuginfo-6.4.0-150600.23.38.1
* kernel-debug-debugsource-6.4.0-150600.23.38.1
* kernel-debug-devel-6.4.0-150600.23.38.1
* openSUSE Leap 15.6 (x86_64)
* kernel-default-vdso-6.4.0-150600.23.38.1
* kernel-kvmsmall-vdso-6.4.0-150600.23.38.1
* kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.38.1
* kernel-default-vdso-debuginfo-6.4.0-150600.23.38.1
* kernel-debug-vdso-6.4.0-150600.23.38.1
* kernel-debug-vdso-debuginfo-6.4.0-150600.23.38.1
* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-debuginfo-6.4.0-150600.23.38.1
*...
Read the Full Advisory* bsc#1012628
* bsc#1194869
* bsc#1215199
* bsc#1216813
* bsc#1218470
* bsc#1220711
* bsc#1221326
* bsc#1222803
* bsc#1224049
* bsc#1225897
* bsc#1226980
* bsc#1228592
* bsc#1229833
* bsc#1231016
* bsc#1231088
* bsc#1232087
* bsc#1232101
* bsc#1232158
* bsc#1232161
* bsc#1232421
* bsc#1232882
* bsc#1233055
* bsc#1233112
* bsc#1233221
* bsc#1233248
* bsc#1233259
* bsc#1233260
* bsc#1233488
* bsc#1233522
* bsc#1233638
* bsc#1233642
* bsc#1233778
* bsc#1234195
* bsc#1234619
* bsc#1234635
* bsc#1234683
* bsc#1234693
* bsc#1234726
* bsc#1234825
* bsc#1234863
* bsc#1234887
* bsc#1234888
* bsc#1234893
* bsc#1234898
* bsc#1234901
* bsc#1234906
* bsc#1234923
* bsc#1234931
* bsc#1234934
* bsc#1234947
* bsc#1234957
* bsc#1235000
* bsc#1235001
* bsc#1235011
* bsc#1235031
* bsc#1235032
* bsc#1235035
* bsc#1235037
* bsc#1235038
* bsc#1235039
* bsc#1235040
* bsc#1235042
* bsc#1235043
* bsc#1235046
* bsc#1235050
* bsc#1235051
* bsc#1235053
* bsc#1235054
* bsc#1235057
* bsc#1235059
* bsc#1235065
* bsc#1235070
* bsc#1235073
* bsc#1235100
* bsc#1235112
* bsc#1235115
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.