Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 449
Alerts This Week
Warning Icon 1 449

openSUSE Kernel Important Security Fix Multiple Issues 2026-3254-1

opensuse
Calendar Grey July 27, 2026
Scroller Opensuse
Update resolves six important vulnerabilities in openSUSE's kernel, ensuring system security and stability. Recommended installation available.
A security update for SUSE Linux Enterprise 15 SP6 addresses six vulnerabilities, improving kernel stability and security through patches related to TLS, IPv4, and KVM issues.

Description

This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.109 fixes

various security issues:

The following security issues were fixed:

* CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx()

(bsc#1262404).

* CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create

(bsc#1264060).

* CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()

(bsc#1271648).

* CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected

GFN (bsc#1266970).

* CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected

role (bsc#1270060).

* CVE-2026-53366: ipv4: account for fraggap on the paged allocation path

(bsc#1271370).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Live Patching 15-SP6

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3254=1

* openSUSE Leap 15.6

zypper in -t patch SUSE-2026-3254=1

Package List

* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)

* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1

* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1

* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1

* openSUSE Leap 15.6 (ppc64le s390x x86_64)

* kernel-livepatch-6_4_0-150600_23_109-default-4-150600.2.1

* kernel-livepatch-SLE15-SP6_Update_25-debugsource-4-150600.2.1

* kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-4-150600.2.1

References

* bsc#1262404

* bsc#1264060

* bsc#1266970

* bsc#1270060

* bsc#1271370

* bsc#1271648

## References:

* https://www.suse.com/security/cve/CVE-2026-23240.html

* https://www.suse.com/security/cve/CVE-2026-31738.html

* https://www.suse.com/security/cve/CVE-2026-43038.html

* https://www.suse.com/security/cve/CVE-2026-46113.html

* https://www.suse.com/security/cve/CVE-2026-53359.html

* https://www.suse.com/security/cve/CVE-2026-53366.html

* https://bugzilla.suse.com/show_bug.cgi?id=1262404

* https://bugzilla.suse.com/show_bug.cgi?id=1264060

* https://bugzilla.suse.com/show_bug.cgi?id=1266970

* https://bugzilla.suse.com/show_bug.cgi?id=1270060

* https://bugzilla.suse.com/show_bug.cgi?id=1271370

* https://bugzilla.suse.com/show_bug.cgi?id=1271648

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3254-1
Release Date: 2026-07-26T18:33:35Z

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.