Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21934-1 Release Date: 2026-06-01T09:26:53Z Rating: important References: * bsc#1259798 * bsc#1260563 * bsc#1260908 * bsc#1264096 * bsc#1265224 * bsc#1265384 Cross-References: * CVE-2025-54518 * CVE-2026-23243 * CVE-2026-23274 * CVE-2026-23317 * CVE-2026-46300 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23243 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 (SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). * CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). * CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-456=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-18-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-18-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-18-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-23243.html * https://www.suse.com/security/cve/CVE-2026-23274.html * https://www.suse.com/security/cve/CVE-2026-23317.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1259798 * https://bugzilla.suse.com/show_bug.cgi?id=1260563 *https://bugzilla.suse.com/show_bug.cgi?id=1260908 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . Install a crucial security update for SUSE Linux Micro with fixes for six important issues.. kernel update, SUSE security, Linux vulnerabilities, security patches, local root exploits. . Severity: Important. LinuxSecurity.com Team
The 6.19.14-104 kernel update contains a fix for the keysign-pwn vulnerability CVE-2026-46333 as well as a mitigation for one more code path of fragnesia. The 6.19.14-103 build contains an additional fix for the GRO path with fragnesia.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-8b4a8d18d2 2026-05-15 22:44:59.632858+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 42 Version : 6.19.14 Release : 104.fc42 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.19.14-104 kernel update contains a fix for the keysign-pwn vulnerability CVE-2026-46333 as well as a mitigation for one more code path of fragnesia. The 6.19.14-103 build contains an additional fix for the GRO path with fragnesia. -------------------------------------------------------------------------------- ChangeLog: * Fri May 15 2026 Justin M. Forbes [6.19.14-104] - Revert "redhat/kernel.spec.template: Fix indentation of uki-virt generation code" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Simplify uki-virt signing" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Add kernel-uki-dtbloader sub-package" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Make -uki-dtbloader provide kernel-core-uname-r" (Justin M. Forbes) * Fri May 15 2026 Justin M. Forbes [6.19.14-0] - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) - Revert v3 of the fragnesia fix. V4 covers an additional path (Justin M. Forbes) - ptrace: slightly saner 'get_dumpable()' logic (Linus Torvalds) - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) - Revert old fragnesia fixes in favor of more complete solution (Justin M.Forbes) - Revert old fragnesia fixes in favor of more complete solution (Justin M. Forbes) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-8b4a8d18d2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 7.0.7 stable kernel update contains a number of important fixes across the tree. It also patches up a vulnerable codepath for fragnesia that was not in the original patches for 7.0.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-5e5a0f9621 2026-05-15 03:06:23.642331+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 43 Version : 7.0.7 Release : 100.fc43 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 7.0.7 stable kernel update contains a number of important fixes across the tree. It also patches up a vulnerable codepath for fragnesia that was not in the original patches for 7.0.6 -------------------------------------------------------------------------------- ChangeLog: * Thu May 14 2026 Justin M. Forbes [7.0.7-0] - net: skbuff: propagate shared-frag marker through frag-transfer helpers (Hyunwoo Kim) - Revert old fragnesia fixes in favor of more complete solution (Justin M. Forbes) - Revert old fragnesia fixes in favor of more complete solution (Justin M. Forbes) - Change version in Bugsfixed due to build (Justin M. Forbes) - Linux v7.0.7 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5e5a0f9621' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 6.19.14-102 stable kernel update contains a fix for the Fragnesia CVE-2026-46300.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-ec1c523fdb 2026-05-14 04:02:29.141275+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 42 Version : 6.19.14 Release : 102.fc42 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 6.19.14-102 stable kernel update contains a fix for the Fragnesia CVE-2026-46300. -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2026 Justin M. Forbes [6.19.14-102] - Revert "redhat/kernel.spec.template: Fix indentation of uki-virt generation code" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Simplify uki-virt signing" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Add kernel-uki-dtbloader sub-package" (Justin M. Forbes) - Revert "redhat/kernel.spec.template: Make -uki-dtbloader provide kernel-core-uname-r" (Justin M. Forbes) * Wed May 13 2026 Justin M. Forbes [6.19.14-0] - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) - net: skbuff: propagate shared-frag marker through pskb_copy() (Hyunwoo Kim) - Turn off F43 and F44 release targets (Justin M. Forbes) - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Hyunwoo Kim) - rxrpc: Fix rxrpc_input_call_event() to only unshare DATA packets (David Howells) - rxrpc: Fix re-decryption of RESPONSE packets (David Howells) - rxrpc: Fix error handling in rxgk_extract_token() (David Howells) - rxrpc: Fix rxkad crypto unalignment handling (David Howells) - rxrpc: Fix conn-level packet handling to unshare RESPONSE packets (David Howells) - rxrpc: Fix memory leaks inrxkad_verify_response() (David Howells) - rxrpc: Fix potential UAF after skb_unshare() failure (David Howells) - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-ec1c523fdb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 7.0.6 stable kernel update contains a number of important fixes across the tree. It also contains a fix for the Fragnesia CVE-2026-46300. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-cccb681166 2026-05-14 00:41:12.640505+00:00 -------------------------------------------------------------------------------- Name : kernel-headers Product : Fedora 43 Version : 7.0.6 Release : 100.fc43 URL : http://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. -------------------------------------------------------------------------------- Update Information: The 7.0.6 stable kernel update contains a number of important fixes across the tree. It also contains a fix for the Fragnesia CVE-2026-46300 -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2026 Justin M. Forbes - 7.0.6-1 - Linux v7.0.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2468594 - overlayfs+fsverity-require (composefs) broken in 7.x - just needs cherry pick https://bugzilla.redhat.com/show_bug.cgi?id=2468594 [ 2 ] Bug #2468995 - Regression: Intel MEI modules missing in kernel 7.0.4-200.fc44 causing i915 / Meteor Lake system freezes https://bugzilla.redhat.com/show_bug.cgi?id=2468995 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-cccb681166' at the command line. For more information, refer to the dnf documentationavailable at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The 7.0.6 stable kernel update contains a number of important fixes across the tree. It also contains a fix for the Fragnesia CVE-2026-46300. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4462efc052 2026-05-14 00:25:16.447806+00:00 -------------------------------------------------------------------------------- Name : kernel Product : Fedora 44 Version : 7.0.6 Release : 200.fc44 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package -------------------------------------------------------------------------------- Update Information: The 7.0.6 stable kernel update contains a number of important fixes across the tree. It also contains a fix for the Fragnesia CVE-2026-46300 -------------------------------------------------------------------------------- ChangeLog: * Wed May 13 2026 Justin M. Forbes [7.0.6-0] - net: skbuff: propagate shared-frag marker through pskb_copy() (Hyunwoo Kim) - net: skbuff: preserve shared-frag marker during coalescing (William Bowling) - Add BugsFixed for 7.0.7 (Justin M. Forbes) - ovl: fix verity lazy-load guard broken by fsverity_active() semantic change (Colin Walters) - Revert rxrpc dirtyfrag fix in favor of version which landed upstream (Justin M. Forbes) - Re-enable Intel MEI for Fedora x86 (Justin M. Forbes) - xfrm: esp: avoid in-place decrypt on shared skb frags (Kuan-Ting Chen) - rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present (Hyunwoo Kim) - Linux v7.0.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2468594 - overlayfs+fsverity-require (composefs) broken in 7.x - just needs cherry pick https://bugzilla.redhat.com/show_bug.cgi?id=2468594 [ 2 ] Bug #2468995 - Regression: Intel MEI modules missing in kernel 7.0.4-200.fc44 causing i915 / Meteor Lake system freezes https://bugzilla.redhat.com/show_bug.cgi?id=2468995 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4462efc052' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.