The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
bugfixes.
The following security bugs were fixed:
* CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the
allocated buffer (bsc#1238917).
* CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075).
* CVE-2025-71066: net/sched: ets: Always remove class from active list before
deleting in ets_qdisc_change (bsc#1256645).
* CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and
rt_del_uncached_list() (bsc#1257231).
* CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to
match ESP/ESN spec (bsc#1257735).
* CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258395).
* CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful()
(bsc#1258340).
* CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink()
(bsc#1258518).
* CVE-2026-23268: apparmor: fix unprivileged local user can do...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Live Patching 15-SP4
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-984=1
* openSUSE Leap 15.4
zypper in -t patch SUSE-2026-984=1
* SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-984=1
* SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-984=1
* SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-984=1
* SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-984=1
* SUSE Linux Enterprise High Availability Extension 15 SP4
zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-984=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-984=1
* SUSE Linux Enterprise High Performance...
Read the Full Advisory* SUSE Linux Enterprise Live Patching 15-SP4 (nosrc)
* kernel-default-5.14.21-150400.24.197.1
* SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64)
* kernel-default-debugsource-5.14.21-150400.24.197.1
* kernel-default-livepatch-5.14.21-150400.24.197.1
* kernel-default-debuginfo-5.14.21-150400.24.197.1
* kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-1-150400.9.3.1
* kernel-livepatch-5_14_21-150400_24_197-default-1-150400.9.3.1
* kernel-livepatch-SLE15-SP4_Update_49-debugsource-1-150400.9.3.1
* kernel-default-livepatch-devel-5.14.21-150400.24.197.1
* openSUSE Leap 15.4 (noarch nosrc)
* kernel-docs-5.14.21-150400.24.197.1
* openSUSE Leap 15.4 (noarch)
* kernel-devel-5.14.21-150400.24.197.1
* kernel-docs-html-5.14.21-150400.24.197.1
* kernel-macros-5.14.21-150400.24.197.1
* kernel-source-vanilla-5.14.21-150400.24.197.1
* kernel-source-5.14.21-150400.24.197.1
* openSUSE Leap 15.4 (aarch64 ppc64le x86_64)
* kernel-default-base-rebuild-5.14.21-150400.24.197.1.150400.24.100.1
*...
Read the Full Advisory* bsc#1238917
* bsc#1255075
* bsc#1256645
* bsc#1257231
* bsc#1257473
* bsc#1257732
* bsc#1257735
* bsc#1258340
* bsc#1258395
* bsc#1258518
* bsc#1258849
* bsc#1258850
* bsc#1259857
## References:
* https://www.suse.com/security/cve/CVE-2025-21738.html
* https://www.suse.com/security/cve/CVE-2025-40242.html
* https://www.suse.com/security/cve/CVE-2025-71066.html
* https://www.suse.com/security/cve/CVE-2026-23004.html
* https://www.suse.com/security/cve/CVE-2026-23054.html
* https://www.suse.com/security/cve/CVE-2026-23060.html
* https://www.suse.com/security/cve/CVE-2026-23191.html
* https://www.suse.com/security/cve/CVE-2026-23204.html
* https://www.suse.com/security/cve/CVE-2026-23209.html
* https://www.suse.com/security/cve/CVE-2026-23268.html
* https://www.suse.com/security/cve/CVE-2026-23269.html
* https://bugzilla.suse.com/show_bug.cgi?id=1238917
* https://bugzilla.suse.com/show_bug.cgi?id=1255075
* https://bugzilla.suse.com/show_bug.cgi?id=1256645
* https://bugzilla.suse.com/show_bug.cgi?id=1257231
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.