## The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-39998: scsi: target: target_core_configfs: Add length check to avoid buffer overflow (bsc#1252073). * CVE-2026-23103: ipvlan: Make the addrs_lock be per port (bsc#1257773). * CVE-2026-23231: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() (bsc#1259188). * CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259797). * CVE-2026-23272: netfilter: nf_tables: unconditionally bump set->nelems before insertion (bsc#1260009). * CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260005). * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall
* bsc#1252073
* bsc#1253122
* bsc#1257506
* bsc#1257773
* bsc#1259188
* bsc#1259461
* bsc#1259580
* bsc#1259707
* bsc#1259797
* bsc#1259998
* bsc#1260005
* bsc#1260009
* bsc#1260347
* bsc#1260471
* bsc#1260486
* bsc#1260562
* bsc#1260730
* bsc#1261412
* bsc#1261498
Cross-
* CVE-2025-39998
* CVE-2026-23103
* CVE-2026-23231
* CVE-2026-23243
* CVE-2026-23272
* CVE-2026-23274
* CVE-2026-23278
* CVE-2026-23293
* CVE-2026-23317
* CVE-2026-23381
* CVE-2026-23398
* CVE-2026-23412
* CVE-2026-23413
* CVE-2026-31788
CVSS scores:
* CVE-2025-39998 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2025-39998 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2026-23103 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Get the latest Linux and open source security news straight to your inbox.