The SUSE Linux Enterprise 15 SP6 RT kernel was updated to fix various security
issues
The following security issues were fixed:
* CVE-2025-38008: mm/page_alloc: fix race condition in unaccepted memory
handling (bsc#1244939).
* CVE-2025-38539: trace/fgraph: Fix the warning caused by missing unregister
notifier (bsc#1248211).
* CVE-2025-38552: mptcp: plug races between subflow fail and subflow creation
(bsc#1248230).
* CVE-2025-38653: proc: use the same treatment to check proc_lseek as ones for
proc_read_iter et.al (bsc#1248630).
* CVE-2025-38699: scsi: bfa: Double-free fix (bsc#1249224).
* CVE-2025-38700: scsi: libiscsi: Initialize iscsi_conn->dd_data only if
memory is allocated (bsc#1249182).
* CVE-2025-38718: sctp: linearize cloned gso packets in sctp_rcv
(bsc#1249161).
* CVE-2025-39673: ppp: fix race conditions in ppp_fill_forward_path
(bsc#1249320).
* CVE-2025-39676: scsi: qla4xxx: Prevent a potential error pointer dereference
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Real Time Module 15-SP6
zypper in -t patch SUSE-SLE-Module-RT-15-SP6-2025-4301=1
* openSUSE Leap 15.6
zypper in -t patch openSUSE-SLE-15.6-2025-4301=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-4301=1
* SUSE Real Time Module 15-SP6 (x86_64)
* dlm-kmp-rt-6.4.0-150600.10.58.1
* gfs2-kmp-rt-debuginfo-6.4.0-150600.10.58.1
* kernel-rt-debuginfo-6.4.0-150600.10.58.1
* kernel-rt-debugsource-6.4.0-150600.10.58.1
* kernel-rt_debug-devel-debuginfo-6.4.0-150600.10.58.1
* dlm-kmp-rt-debuginfo-6.4.0-150600.10.58.1
* kernel-syms-rt-6.4.0-150600.10.58.1
* cluster-md-kmp-rt-debuginfo-6.4.0-150600.10.58.1
* kernel-rt-devel-debuginfo-6.4.0-150600.10.58.1
* ocfs2-kmp-rt-6.4.0-150600.10.58.1
* kernel-rt-devel-6.4.0-150600.10.58.1
* gfs2-kmp-rt-6.4.0-150600.10.58.1
* kernel-rt_debug-debuginfo-6.4.0-150600.10.58.1
* cluster-md-kmp-rt-6.4.0-150600.10.58.1
* kernel-rt_debug-debugsource-6.4.0-150600.10.58.1
* kernel-rt_debug-devel-6.4.0-150600.10.58.1
* ocfs2-kmp-rt-debuginfo-6.4.0-150600.10.58.1
* SUSE Real Time Module 15-SP6 (noarch)
* kernel-devel-rt-6.4.0-150600.10.58.1
* kernel-source-rt-6.4.0-150600.10.58.1
* SUSE Real Time Module 15-SP6 (nosrc x86_64)
* kernel-rt_debug-6.4.0-150600.10.58.1
* kernel-rt-6.4.0-150600.10.58.1
*...
Read the Full Advisory* bsc#1012628
* bsc#1214954
* bsc#1215143
* bsc#1215199
* bsc#1216396
* bsc#1220419
* bsc#1236743
* bsc#1239206
* bsc#1244939
* bsc#1246244
* bsc#1248211
* bsc#1248230
* bsc#1248517
* bsc#1248630
* bsc#1248754
* bsc#1248886
* bsc#1249161
* bsc#1249182
* bsc#1249224
* bsc#1249286
* bsc#1249302
* bsc#1249317
* bsc#1249319
* bsc#1249320
* bsc#1249512
* bsc#1249595
* bsc#1249608
* bsc#1250032
* bsc#1250119
* bsc#1250202
* bsc#1250205
* bsc#1250237
* bsc#1250274
* bsc#1250296
* bsc#1250379
* bsc#1250400
* bsc#1250455
* bsc#1250491
* bsc#1250519
* bsc#1250650
* bsc#1250702
* bsc#1250704
* bsc#1250721
* bsc#1250742
* bsc#1250946
* bsc#1251024
* bsc#1251027
* bsc#1251028
* bsc#1251031
* bsc#1251035
* bsc#1251038
* bsc#1251043
* bsc#1251045
* bsc#1251052
* bsc#1251053
* bsc#1251054
* bsc#1251056
* bsc#1251057
* bsc#1251059
* bsc#1251060
* bsc#1251065
* bsc#1251066
* bsc#1251067
* bsc#1251068
* bsc#1251071
* bsc#1251076
* bsc#1251079
* bsc#1251081
* bsc#1251083
* bsc#1251084
* bsc#1251100
* bsc#1251105
* bsc#1251106
* bsc#1251108
* bsc#1251113
* bsc#1251114
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.