## The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009).
* bsc#1261700
* bsc#1263790
* bsc#1263995
* bsc#1264093
* bsc#1264551
* bsc#1266001
* bsc#1266009
* bsc#1266238
* bsc#1266711
* bsc#1266901
* bsc#1266969
* bsc#1267205
* bsc#1267220
Cross-
* CVE-2026-31405
* CVE-2026-31629
* CVE-2026-31758
* CVE-2026-43037
* CVE-2026-43206
* CVE-2026-43499
* CVE-2026-43501
* CVE-2026-45852
* CVE-2026-45970
* CVE-2026-46021
* CVE-2026-46043
* CVE-2026-46113
* CVE-2026-46243
CVSS scores:
* CVE-2026-31405 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31405 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31629 ( SUSE ): 8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Get the latest Linux and open source security news straight to your inbox.