Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update addresses two security issues regarding incorrect handling of malformed IPv6 addresses: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) Reject invalid uncompressed IPv6 (CVE-2026-40198). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-0a7ed21996 2026-04-22 07:48:13.354956+00:00 -------------------------------------------------------------------------------- Name : perl-Net-CIDR-Lite Product : Fedora 43 Version : 0.23 Release : 1.fc43 URL : https://metacpan.org/release/Net-CIDR-Lite Summary : Perl extension for merging IPv4 or IPv6 CIDR addresses Description : Faster alternative to Net::CIDR when merging a large number of CIDR address ranges. Works for IPv4 and IPv6 addresses. -------------------------------------------------------------------------------- Update Information: This update addresses two security issues regarding incorrect handling of malformed IPv6 addresses: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) Reject invalid uncompressed IPv6 (CVE-2026-40198) -------------------------------------------------------------------------------- ChangeLog: * Sat Apr 11 2026 Paul Howarth - 0.23-1 - Update to 0.23 - Security: Fix IPv4 mapped IPv6 packed length (CVE-2026-40199) - Security: Reject invalid uncompressed IPv6 (CVE-2026-40198) * Sat Jan 17 2026 Fedora Release Engineering - 0.22-14 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0a7ed21996' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Important: go-rpm-macros security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:8840", "synopsis": "Important: go-rpm-macros security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for go-rpm-macros.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "This package provides build-stage rpm automation to simplify the creation of Go language (golang) packages. It does not need to be included in the default build root: go-srpm-macros will pull it in for Go packages only.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-04-21T12:07:14.176910Z", "rpms": {"Rocky Linux 10": {"nvras": ["go-filesystem-0:3.6.0-8.el10_1.x86_64.rpm", "go-rpm-macros-debuginfo-0:3.6.0-8.el10_1.x86_64.rpm", "go-srpm-macros-0:3.6.0-8.el10_1.noarch.rpm", "go-rpm-templates-0:3.6.0-8.el10_1.s390x.rpm", "go-rpm-macros-0:3.6.0-8.el10_1.src.rpm", "go-rpm-macros-0:3.6.0-8.el10_1.ppc64le.rpm", "go-filesystem-0:3.6.0-8.el10_1.ppc64le.rpm", "go-rpm-macros-debugsource-0:3.6.0-8.el10_1.s390x.rpm", "go-rpm-macros-0:3.6.0-8.el10_1.x86_64.rpm", "go-rpm-macros-debugsource-0:3.6.0-8.el10_1.ppc64le.rpm","go-rpm-macros-0:3.6.0-8.el10_1.s390x.rpm", "go-rpm-macros-debugsource-0:3.6.0-8.el10_1.x86_64.rpm", "go-rpm-macros-0:3.6.0-8.el10_1.aarch64.rpm", "go-filesystem-0:3.6.0-8.el10_1.s390x.rpm", "go-rpm-templates-0:3.6.0-8.el10_1.aarch64.rpm", "go-filesystem-0:3.6.0-8.el10_1.aarch64.rpm", "go-rpm-templates-0:3.6.0-8.el10_1.ppc64le.rpm", "go-rpm-macros-debuginfo-0:3.6.0-8.el10_1.ppc64le.rpm", "go-rpm-templates-0:3.6.0-8.el10_1.x86_64.rpm", "go-rpm-macros-debuginfo-0:3.6.0-8.el10_1.s390x.rpm", "go-rpm-macros-debugsource-0:3.6.0-8.el10_1.aarch64.rpm", "go-rpm-macros-debuginfo-0:3.6.0-8.el10_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important update for go-rpm-macros on Rocky Linux 10 addresses IPV6 handling issues with a CVSS score of 7.5.. go-rpm-macros security, Rocky Linux update, IPV6 flaw, important security patch. . Severity: Important. LinuxSecurity.com Team
Important: grafana-pcp security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:6388", "synopsis": "Important: grafana-pcp security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for grafana-pcp.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-04-09T12:07:05.484110Z", "rpms": {"Rocky Linux 10": {"nvras": ["grafana-pcp-debugsource-0:5.3.0-3.el10_1.ppc64le.rpm", "grafana-pcp-0:5.3.0-3.el10_1.x86_64.rpm", "grafana-pcp-0:5.3.0-3.el10_1.s390x.rpm", "grafana-pcp-0:5.3.0-3.el10_1.aarch64.rpm", "grafana-pcp-debugsource-0:5.3.0-3.el10_1.x86_64.rpm", "grafana-pcp-debuginfo-0:5.3.0-3.el10_1.ppc64le.rpm", "grafana-pcp-0:5.3.0-3.el10_1.ppc64le.rpm", "grafana-pcp-debugsource-0:5.3.0-3.el10_1.s390x.rpm", "grafana-pcp-debugsource-0:5.3.0-3.el10_1.aarch64.rpm", "grafana-pcp-0:5.3.0-3.el10_1.src.rpm", "grafana-pcp-debuginfo-0:5.3.0-3.el10_1.s390x.rpm","grafana-pcp-debuginfo-0:5.3.0-3.el10_1.aarch64.rpm", "grafana-pcp-debuginfo-0:5.3.0-3.el10_1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Rocky Linux 10's grafana-pcp receives an important security update addressing CVE-2026-25679 related to incorrect IPv6 parsing.. Rocky Linux grafana-pcp security update CVE-2026-25679. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:20830-1 Release Date: 2026-03-24T05:43:06Z Rating: important References: * bsc#1256624 * bsc#1256644 Cross-References: * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-429=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_9-rt-2-160000.1.1 * kernel-livepatch-SLE16-RT_Update_4-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_9-rt-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html * https://bugzilla.suse.com/show_bug.cgi?id=1256624 *https://bugzilla.suse.com/show_bug.cgi?id=1256644 . Update addresses important vulnerabilities in SUSE Linux Kernel RT for Enterprise 16. Critical patches available now.. SUSE Linux RT Patch, Kernel Update, Security Fixes. . Severity: Important. LinuxSecurity.com Team
Moderate: kernel-rt security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3964", "synopsis": "Moderate: kernel-rt security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for kernel-rt.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.\n\nSecurity Fix(es):\n\n* kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)\n\n* kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2429026", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2429026", "description": ""}, {"ticket": "2432664", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2432664", "description": ""}], "cves": [{"name": "CVE-2025-71085", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-71085", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}, {"name": "CVE-2026-23001", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-23001", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2026-03-26T12:01:40.953151Z", "rpms": {"Rocky Linux 8": {"nvras": ["kernel-rt-0:4.18.0-553.111.1.rt7.452.el8_10.src.rpm", "kernel-rt-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm","kernel-rt-core-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-core-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-debuginfo-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-devel-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debuginfo-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debuginfo-common-x86_64-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-kvm-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-modules-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-debug-modules-extra-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-devel-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-kvm-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-modules-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm", "kernel-rt-modules-extra-0:4.18.0-553.111.1.rt7.452.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Moderate kernel-rt security update available for Rocky Linux 8 addressing critical networking issues.. kernel-rt security, rocky linux update, ipv6 bug fixes, security advisories. . LinuxSecurity.com Team
Moderate: kernel security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:3963", "synopsis": "Moderate: kernel security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for kernel.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The kernel packages contain the Linux kernel, the core of any Linux operating system.\n\nSecurity Fix(es):\n\n* kernel: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (CVE-2025-71085)\n\n* kernel: macvlan: fix possible UAF in macvlan_forward_source() (CVE-2026-23001)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2429026", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2429026", "description": ""}, {"ticket": "2432664", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2432664", "description": ""}], "cves": [{"name": "CVE-2025-71085", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-71085", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-190"}, {"name": "CVE-2026-23001", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-23001", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2026-03-26T12:00:47.711472Z", "rpms": {"Rocky Linux 8": {"nvras": ["bpftool-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "bpftool-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "bpftool-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "bpftool-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm","kernel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-0:4.18.0-553.111.1.el8_10.src.rpm", "kernel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-abi-stablelists-0:4.18.0-553.111.1.el8_10.noarch.rpm", "kernel-core-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-core-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-core-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-core-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debuginfo-common-aarch64-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debuginfo-common-x86_64-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-modules-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-modules-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-debug-modules-extra-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-doc-0:4.18.0-553.111.1.el8_10.noarch.rpm", "kernel-modules-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-modules-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-modules-extra-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-modules-extra-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "kernel-tools-libs-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-libs-0:4.18.0-553.111.1.el8_10.x86_64.rpm","kernel-tools-libs-devel-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "kernel-tools-libs-devel-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "perf-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "perf-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "perf-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "perf-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "python3-perf-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "python3-perf-0:4.18.0-553.111.1.el8_10.x86_64.rpm", "python3-perf-debuginfo-0:4.18.0-553.111.1.el8_10.aarch64.rpm", "python3-perf-debuginfo-0:4.18.0-553.111.1.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Kernel security update available for Rocky Linux 8, addressing multiple issues impacting the system functionality.. Rocky Linux Kernel Security Update, CVSS Scores, System Functionality Issues. . LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20386-1 Release Date: 2026-01-29T10:35:41Z Rating: important References: * bsc#1249241 * bsc#1256928 Cross-References: * CVE-2025-38588 CVSS scores: * CVE-2025-38588 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38588 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38588 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-28.1 fixes one security issue The following security issue was fixed: * CVE-2025-38588: ipv6: prevent infinite loop in rt6_nlmsg_size() (bsc#1249241). The following non security issue was fixed: * fix addr_bit_set() issue on big-endian machines (bsc#1256928). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-253=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-28-default-debuginfo-12-3.1 * kernel-livepatch-MICRO-6-0_Update_6-debugsource-12-3.1 * kernel-livepatch-6_4_0-28-default-12-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38588.html * https://bugzilla.suse.com/show_bug.cgi?id=1249241 * https://bugzilla.suse.com/show_bug.cgi?id=1256928 . An important update for SUSE Linux Enterprise Micro 6.0 kernel resolves a security issue to enhance system stability.. SUSE Linux Micro, kernel update, security patch, ipv6 issue, system fix. . Severity: Important.LinuxSecurity.com Team
An update that solves one vulnerability and has one fix can now be installed.. # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20388-1 Release Date: 2026-01-29T10:37:57Z Rating: important References: * bsc#1249241 * bsc#1256928 Cross-References: * CVE-2025-38588 CVSS scores: * CVE-2025-38588 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38588 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38588 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-30.1 fixes one security issue The following security issue was fixed: * CVE-2025-38588: ipv6: prevent infinite loop in rt6_nlmsg_size() (bsc#1249241). The following non security issue was fixed: * fix addr_bit_set() issue on big-endian machines (bsc#1256928). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-257=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-11-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-11-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-11-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38588.html * https://bugzilla.suse.com/show_bug.cgi?id=1249241 * https://bugzilla.suse.com/show_bug.cgi?id=1256928 . Critical security update fixes ipv6 loop issue in SUSE Linux Micro 6.0 kernel with higher importance rating.. SUSE Linux Micro, kernel update, ipv6 security, security patch, DoS prevention. . Severity: Important. LinuxSecurity.comTeam
Get the latest Linux and open source security news straight to your inbox.