Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security
issues
The following security issues were fixed:
* CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock
(bsc#1264484).
* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
(bsc#1267494).
* CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).
* CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted
by L1 (bsc#1267365).
* CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete (bsc#1267369).
* CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task
(bsc#1267722).
* CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data
exposure (bsc#1267567).
* CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc()
(bsc#1267618).
* CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old()
...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3156=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1
* openSUSE Leap 15.6 (aarch64)
* dtb-apm-6.4.0-150600.23.125.1
* dtb-lg-6.4.0-150600.23.125.1
* kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1
* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-64kb-6.4.0-150600.23.125.1
* dtb-amazon-6.4.0-150600.23.125.1
* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-amlogic-6.4.0-150600.23.125.1
* dtb-amd-6.4.0-150600.23.125.1
* kernel-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-sprd-6.4.0-150600.23.125.1
* kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1
* dtb-nvidia-6.4.0-150600.23.125.1
* dtb-xilinx-6.4.0-150600.23.125.1
* dtb-mediatek-6.4.0-150600.23.125.1
* kernel-64kb-extra-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-6.4.0-150600.23.125.1
* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* kernel-64kb-debugsource-6.4.0-150600.23.125.1
* dtb-renesas-6.4.0-150600.23.125.1
* dtb-arm-6.4.0-150600.23.125.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1
* dtb-broadcom-6.4.0-150600.23.125.1
*...
Read the Full Advisory* bsc#1264484
* bsc#1265421
* bsc#1267365
* bsc#1267369
* bsc#1267494
* bsc#1267567
* bsc#1267591
* bsc#1267618
* bsc#1267635
* bsc#1267684
* bsc#1267722
* bsc#1267918
* bsc#1267966
* bsc#1267993
* bsc#1268022
* bsc#1268049
* bsc#1268237
* bsc#1268335
* bsc#1268660
* bsc#1268989
* bsc#1269022
* bsc#1269033
* bsc#1269036
* bsc#1269090
* bsc#1269100
* bsc#1269159
* bsc#1269172
* bsc#1269174
* bsc#1269184
* bsc#1269193
* bsc#1269195
* bsc#1269310
* bsc#1269314
* bsc#1269398
* bsc#1269493
* bsc#1269574
* bsc#1269678
* bsc#1269681
* bsc#1269795
* bsc#1269798
* bsc#1269821
* bsc#1269884
* bsc#1269986
* bsc#1269993
* bsc#1270022
* bsc#1270059
* bsc#1270257
* bsc#1271050
* bsc#1271366
* jsc#PED-16303
* jsc#PED-16305
## References:
* https://www.suse.com/security/cve/CVE-2026-43109.html
* https://www.suse.com/security/cve/CVE-2026-46052.html
* https://www.suse.com/security/cve/CVE-2026-46071.html
* https://www.suse.com/security/cve/CVE-2026-46076.html
* https://www.suse.com/security/cve/CVE-2026-46116.html
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.