Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

openSUSE Kernel Important Security Update Vulnerability Fix 2026-3156-1

opensuse
Calendar Grey July 21, 2026
Scroller Opensuse
The latest openSUSE kernel update addresses 44 issues, enhancing system security and stability significantly.
An update that solves 44 vulnerabilities, contains two features and has five security fixes can now be installed.

Description

The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security

issues

The following security issues were fixed:

* CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock

(bsc#1264484).

* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed

(bsc#1267494).

* CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).

* CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted

by L1 (bsc#1267365).

* CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in

__xfrm_state_delete (bsc#1267369).

* CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task

(bsc#1267722).

* CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data

exposure (bsc#1267567).

* CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc()

(bsc#1267618).

* CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old()

...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP6

zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1

* SUSE Linux Enterprise Live Patching 15-SP6

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3156=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1

Package List

* openSUSE Leap 15.6 (aarch64)

* dtb-apm-6.4.0-150600.23.125.1

* dtb-lg-6.4.0-150600.23.125.1

* kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1

* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* dlm-kmp-64kb-6.4.0-150600.23.125.1

* dtb-amazon-6.4.0-150600.23.125.1

* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* dtb-amlogic-6.4.0-150600.23.125.1

* dtb-amd-6.4.0-150600.23.125.1

* kernel-64kb-debuginfo-6.4.0-150600.23.125.1

* dtb-sprd-6.4.0-150600.23.125.1

* kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1

* dtb-nvidia-6.4.0-150600.23.125.1

* dtb-xilinx-6.4.0-150600.23.125.1

* dtb-mediatek-6.4.0-150600.23.125.1

* kernel-64kb-extra-6.4.0-150600.23.125.1

* ocfs2-kmp-64kb-6.4.0-150600.23.125.1

* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* kernel-64kb-debugsource-6.4.0-150600.23.125.1

* dtb-renesas-6.4.0-150600.23.125.1

* dtb-arm-6.4.0-150600.23.125.1

* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1

* dtb-broadcom-6.4.0-150600.23.125.1

*...

Read the Full Advisory

References

* bsc#1264484

* bsc#1265421

* bsc#1267365

* bsc#1267369

* bsc#1267494

* bsc#1267567

* bsc#1267591

* bsc#1267618

* bsc#1267635

* bsc#1267684

* bsc#1267722

* bsc#1267918

* bsc#1267966

* bsc#1267993

* bsc#1268022

* bsc#1268049

* bsc#1268237

* bsc#1268335

* bsc#1268660

* bsc#1268989

* bsc#1269022

* bsc#1269033

* bsc#1269036

* bsc#1269090

* bsc#1269100

* bsc#1269159

* bsc#1269172

* bsc#1269174

* bsc#1269184

* bsc#1269193

* bsc#1269195

* bsc#1269310

* bsc#1269314

* bsc#1269398

* bsc#1269493

* bsc#1269574

* bsc#1269678

* bsc#1269681

* bsc#1269795

* bsc#1269798

* bsc#1269821

* bsc#1269884

* bsc#1269986

* bsc#1269993

* bsc#1270022

* bsc#1270059

* bsc#1270257

* bsc#1271050

* bsc#1271366

* jsc#PED-16303

* jsc#PED-16305

## References:

* https://www.suse.com/security/cve/CVE-2026-43109.html

* https://www.suse.com/security/cve/CVE-2026-46052.html

* https://www.suse.com/security/cve/CVE-2026-46071.html

* https://www.suse.com/security/cve/CVE-2026-46076.html

* https://www.suse.com/security/cve/CVE-2026-46116.html

*...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3156-1
Release Date: 2026-07-21T13:34:56Z
Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.