Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

openSUSE 15.6 Kernel Important Security Update SUSE-SU-2026-1236-1

opensuse
Calendar Grey April 9, 2026
Scroller Opensuse
An update resolves eight critical issues in the SUSE Kernel, marked important; install to maintain security.
An update that solves eight vulnerabilities can now be installed.

Description

This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.53 fixes

various security issues

The following security issues were fixed:

* CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036).

* CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup

(bsc#1252689).

* CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation

(bsc#1253404).

* CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length

gss_token in gss_read_proxy_verf (bsc#1256780).

* CVE-2026-22999: net/sched: sch_qfq: do not free existing class in

qfq_change_class() (bsc#1257238).

* CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc

(bsc#1258051).

* CVE-2026-23111: netfilter: nf_tables: fix inverted genmask check in

nft_map_catchall_activate() (bsc#1258183).

* CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink()

(bsc#1258784).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-1236=1

* SUSE Linux Enterprise Live Patching 15-SP6

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-1236=1

Package List

* openSUSE Leap 15.6 (ppc64le s390x x86_64)

* kernel-livepatch-6_4_0-150600_23_53-default-14-150600.2.1

* kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-14-150600.2.1

* kernel-livepatch-SLE15-SP6_Update_12-debugsource-14-150600.2.1

* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)

* kernel-livepatch-6_4_0-150600_23_53-default-14-150600.2.1

* kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-14-150600.2.1

* kernel-livepatch-SLE15-SP6_Update_12-debugsource-14-150600.2.1

References

* bsc#1252036

* bsc#1252689

* bsc#1253404

* bsc#1256780

* bsc#1257238

* bsc#1258051

* bsc#1258183

* bsc#1258784

## References:

* https://www.suse.com/security/cve/CVE-2025-39973.html

* https://www.suse.com/security/cve/CVE-2025-40018.html

* https://www.suse.com/security/cve/CVE-2025-40159.html

* https://www.suse.com/security/cve/CVE-2025-71120.html

* https://www.suse.com/security/cve/CVE-2026-22999.html

* https://www.suse.com/security/cve/CVE-2026-23074.html

* https://www.suse.com/security/cve/CVE-2026-23111.html

* https://www.suse.com/security/cve/CVE-2026-23209.html

* https://bugzilla.suse.com/show_bug.cgi?id=1252036

* https://bugzilla.suse.com/show_bug.cgi?id=1252689

* https://bugzilla.suse.com/show_bug.cgi?id=1253404

* https://bugzilla.suse.com/show_bug.cgi?id=1256780

* https://bugzilla.suse.com/show_bug.cgi?id=1257238

* https://bugzilla.suse.com/show_bug.cgi?id=1258051

* https://bugzilla.suse.com/show_bug.cgi?id=1258183

* https://bugzilla.suse.com/show_bug.cgi?id=1258784

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1236-1
Release Date: 2026-04-09T14:22:37Z
Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.