An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20643-1 Release Date: 2026-03-04T09:20:32Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.7.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-349=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 . A critical update has been released for SUSE Linux kernel addressing an important vulnerability related to CPU latency.. SUSE Linux, kernel update, security advisory, important patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20646-1 Release Date: 2026-03-04T10:43:15Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.6.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-352=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_6-default-5-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 . SUSE's important kernel update addresses a data race issue in CPU latency PM QoS request handling.. SUSE Linux Kernel Update, Security Fix for Kernel, Important SUSE Update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20648-1 Release Date: 2026-03-04T13:12:39Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.8.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-355=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_8-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 . Important update available for SUSE Linux Enterprise kernel addressing a data race issue, enhancing system security and performance.. SUSE Linux kernel update, kernel security patch, important Linux advisory. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20634-1 Release Date: 2026-03-04T09:20:32Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.7.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-349=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-349=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_2-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-3-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_2-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 .Update addresses important kernel security issue for SUSE Linux Enterprise, enhancing stability and performance.. SUSE Linux, Kernel Update, Important Security Patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20636-1 Release Date: 2026-03-04T10:43:15Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.6.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-352=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-352=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_1-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-5-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_1-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 .Critical update for SUSE Linux Enterprise kernel addressing data race vulnerability in CPU latency handling.. SUSE Linux Enterprise kernel important patch data race security. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20637-1 Release Date: 2026-03-04T13:12:39Z Rating: important References: * bsc#1253415 Cross-References: * CVE-2025-40130 CVSS scores: * CVE-2025-40130 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40130 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP Applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.12.0-160000.8.1 fixes one security issue The following security issue was fixed: * CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling (bsc#1253415). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-355=1 * SUSE Linux Enterprise Server for SAP Applications 16.0 zypper in -t patch SUSE-SLES-16.0-355=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_3-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-2-160000.1.1 * SUSE Linux Enterprise Server for SAP Applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_3-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-2-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40130.html * https://bugzilla.suse.com/show_bug.cgi?id=1253415 . SUSELinux Enterprise 16 gets important kernel security update for CVE-2025-40130. Install the patch to mitigate risks.. SUSE Linux Enterprise, Kernel Security Update, CVE-2025-40130, Data Race Fix, CPU Latency Management. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-12571 http://linux.oracle.com/errata/ELSA-2024-12571.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: kernel-uek-doc-4.1.12-124.88.3.el7uek.noarch.rpm kernel-uek-firmware-4.1.12-124.88.3.el7uek.noarch.rpm kernel-uek-4.1.12-124.88.3.el7uek.x86_64.rpm kernel-uek-devel-4.1.12-124.88.3.el7uek.x86_64.rpm kernel-uek-debug-4.1.12-124.88.3.el7uek.x86_64.rpm kernel-uek-debug-devel-4.1.12-124.88.3.el7uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates//kernel-uek-4.1.12-124.88.3.el7uek.src.rpm Related CVEs: CVE-2023-52813 CVE-2021-47495 CVE-2024-36946 CVE-2024-36941 CVE-2024-36934 CVE-2024-27020 CVE-2024-41090 CVE-2024-41091 CVE-2023-52528 CVE-2023-52880 CVE-2024-26642 CVE-2024-25739 CVE-2022-24448 Description of changes: [4.1.12-124.88.3.el7uek] - crypto: pcrypt - Fix hungtask for PADATA_RESET (Lu Jialin) [Orabug: 36806710] {CVE-2023-52813} - usbnet: sanity check for maxpacket (Oliver Neukum) [Orabug: 36806658] {CVE-2021-47495} - phonet: fix rtm_phonet_notify() skb allocation (Eric Dumazet) [Orabug: 36683487] {CVE-2024-36946} - wifi: nl80211: don't free NULL coalescing rule (Johannes Berg) [Orabug: 36683466] {CVE-2024-36941} - bna: ensure the copied buf is NUL terminated (Bui Quang Minh) [Orabug: 36683433] {CVE-2024-36934} - bna: use memdup_user to copy userspace buffers (Ivan Vecera) [Orabug: 36683433] {CVE-2024-36934} - new helper: memdup_user_nul() (Al Viro) [Orabug: 36683433] {CVE-2024-36934} - netfilter: nf_tables: Fix potential data-race in __nft_expr_type_get() (Ziyang Xuan) [Orabug: 36598047] {CVE-2024-27020} - netfilter: nf_tables: __nft_expr_type_get() selects specific family type (Pablo Neira Ayuso) [Orabug: 36598047] {CVE-2024-27020} - net/mlx5e: drop shorter ethernet frames (Manjunath Patil) [Orabug: 36879159] {CVE-2024-41090}{CVE-2024-41091} [4.1.12-124.88.2.el7uek] - net: usb: smsc75xx: Fix uninit-value access in __smsc75xx_read_reg (Shigeru Yoshida) [Orabug: 36802310] {CVE-2023-52528} - usbnet/smsc75xx: silence uninitialized variable warning (Dan Carpenter) {CVE-2023-52528} - tty: n_gsm: require CAP_NET_ADMIN to attach N_GSM0710 ldisc (Thadeu Lima de Souza Cascardo) [Orabug: 36685663] {CVE-2023-52880} - netfilter: nf_tables: disallow anonymous set with timeout flag (Pablo Neira Ayuso) [Orabug: 36530112] {CVE-2024-26642} - ubi: Check for too small LEB size in VTBL code (Richard Weinberger) [Orabug: 36356637] {CVE-2024-25739} [4.1.12-124.88.1.el7uek] - NFS: LOOKUP_DIRECTORY is also ok with symlinks (Trond Myklebust) [Orabug: 33958156] {CVE-2022-24448} - NFSv4: Handle case where the lookup of a directory fails (Trond Myklebust) [Orabug: 33958156] {CVE-2022-24448} _______________________________________________ El-errata mailing list
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libqt5-qtnetworkauth ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0143-1 Rating: moderate References: #1224782 Cross-References: CVE-2024-36048 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libqt5-qtnetworkauth fixes the following issues: - CVE-2024-36048: Fixed data race and poor seeding in generateRandomString() (boo#1224782). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-143=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libQt5NetworkAuth5-5.15.2+kde2-bp155.3.3.1 libqt5-qtnetworkauth-devel-5.15.2+kde2-bp155.3.3.1 libqt5-qtnetworkauth-examples-5.15.2+kde2-bp155.3.3.1 - openSUSE Backports SLE-15-SP5 (aarch64_ilp32): libQt5NetworkAuth5-64bit-5.15.2+kde2-bp155.3.3.1 libqt5-qtnetworkauth-devel-64bit-5.15.2+kde2-bp155.3.3.1 - openSUSE Backports SLE-15-SP5 (noarch): libqt5-qtnetworkauth-private-headers-devel-5.15.2+kde2-bp155.3.3.1 - openSUSE Backports SLE-15-SP5 (x86_64): libQt5NetworkAuth5-32bit-5.15.2+kde2-bp155.3.3.1 libqt5-qtnetworkauth-devel-32bit-5.15.2+kde2-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2024-36048.html https://bugzilla.suse.com/1224782 . This release tackles a significant vulnerability within libqt5-qtnetworkauth, accompanied by a setup instruction for the impacted platforms.. Libqt5, OpenSUSE, SoftwareFix, Security Patch, Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.