Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for firewalld Announcement ID: SUSE-SU-2026:2302-1 Release Date: 2026-06-08T15:27:07Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue: * CVE-2026-4948: local unprivileged users can modify the runtime firewall state without proper authentication due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2302=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2302=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2302=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2302=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2302=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2302=1 ## Package List: * openSUSE Leap 15.4 (noarch) * firewalld-lang-0.9.3-150400.8.15.1 * firewall-applet-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 *firewall-macros-0.9.3-150400.8.15.1 * python3-firewall-0.9.3-150400.8.15.1 * firewall-config-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-firewall-0.9.3-150400.8.15.1 * firewalld-0.9.3-150400.8.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 . This advisory details a moderate security update for openSUSE firewalld fixing a D-Bus authentication issue for local users.. firewalld security update, openSUSE vulnerability, D-Bus authentication issue. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21399-1 Release Date: 2026-04-24T10:01:55Z Rating: important References: * bsc#1259859 Cross-References: * CVE-2026-23268 CVSS scores: * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes one security issue The following security issue was fixed: * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-638=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-638=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_26-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-3-160000.1.1 ## References: *https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . Install important SUSE kernel patch addressing privileged access issue. Update your systems now for enhanced security.. SUSE kernel security patch privileged access local user important. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21401-1 Release Date: 2026-04-24T10:08:05Z Rating: important References: * bsc#1259859 Cross-References: * CVE-2026-23268 CVSS scores: * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes one security issue The following security issue was fixed: * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-640=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-640=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-4-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-4-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-4-160000.1.1 ## References: *https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . SUSE Linux Enterprise Kernel update fixes unprivileged local user issue with important security patch. Learn more.. SUSE Linux, security advisory, kernel patch, privilege escalation, security update. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21387-1 Release Date: 2026-04-23T08:20:31Z Rating: important References: * bsc#1259859 Cross-References: * CVE-2026-23268 CVSS scores: * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes one security issue The following security issue was fixed: * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-633=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-633=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_8-default-5-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_8-default-5-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-5-160000.1.1 ## References: *https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . SUSE Linux Enterprise 16 Kernel important update resolves a security issue with local user policy management flaws.. SUSE Linux Enterprise Security Kernel Update Local User Policy. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1630-1 Release Date: 2026-04-27T08:04:20Z Rating: important References: * bsc#1258396 * bsc#1259859 Cross-References: * CVE-2026-23191 * CVE-2026-23268 CVSS scores: * CVE-2026-23191 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23191 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23191 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23191 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.103 fixes various security issues The following security issues were fixed: * CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258396). * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1630=1 * SUSE Linux Enterprise Live Patching15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-1630=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_103-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_103-default-debuginfo-17-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_26-debugsource-17-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_103-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_103-default-debuginfo-17-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_26-debugsource-17-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23191.html * https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1258396 * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . Install updates for openSUSE kernel addressing two important issues including ALSA and AppArmor access fixes.. openSUSE kernel security patch, vulnerability management openSUSE, security advisory updates. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21348-1 Release Date: 2026-04-24T10:08:05Z Rating: important References: * bsc#1259859 Cross-References: * CVE-2026-23268 CVSS scores: * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes one security issue The following security issue was fixed: * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-640=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_4-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-4-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . Critical update for SUSE Linux Enterprise Kernel to fix unprivileged user policy management issue.. SUSE Linux Security, Kernel Update, SUSE Patch, Local User Exploit. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:1622-1 Release Date: 2026-04-25T06:33:49Z Rating: important References: * bsc#1258396 * bsc#1259859 Cross-References: * CVE-2026-23191 * CVE-2026-23268 CVSS scores: * CVE-2026-23191 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23191 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23191 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23191 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.110 fixes various security issues The following security issues were fixed: * CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258396). * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-1627=1 SUSE-2026-1628=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-1627=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-1628=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-1622=1 SUSE-2026-1623=1 SUSE-2026-1624=1 SUSE-2026-1625=1 SUSE-2026-1626=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-1622=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-1623=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-1624=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-1625=1 SUSE-SLE-Module-Live-Patching-15-SP4-2026-1626=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_27-debugsource-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_100-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_100-default-debuginfo-17-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_25-debugsource-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-16-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_27-debugsource-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_100-default-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_100-default-debuginfo-17-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_25-debugsource-17-150500.2.1 * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-16-150500.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) *kernel-livepatch-SLE15-SP4_Update_41-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_40-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-16-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-9-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_41-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_40-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-11-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_164-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-12-150400.2.1 *kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-12-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-16-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-9-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23191.html * https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1258396 * https://bugzilla.suse.com/show_bug.cgi?id=1259859 . Two important vulnerabilities fixed in the SUSE Linux Enterprise Kernel, improving overall system security and stability.. SUSE Linux, kernel update, security alert, Linux Enterprise, patch management. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21294-1 Release Date: 2026-04-22T17:09:05Z Rating: important References: * bsc#1255066 * bsc#1259859 Cross-References: * CVE-2025-40309 * CVE-2026-23268 CVSS scores: * CVE-2025-40309 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40309 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23268 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23268 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-28.1 fixes various security issues The following security issues were fixed: * CVE-2025-40309: Bluetooth: SCO: Fix UAF on sco_conn_free (bsc#1255066). * CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-356=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_6-debugsource-17-3.1 * kernel-livepatch-6_4_0-28-default-17-3.1 * kernel-livepatch-6_4_0-28-default-debuginfo-17-3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40309.html * https://www.suse.com/security/cve/CVE-2026-23268.html * https://bugzilla.suse.com/show_bug.cgi?id=1255066 * https://bugzilla.suse.com/show_bug.cgi?id=1259859 .Important update for SUSE Linux Micro 6.1 kernel addressing security flaws to enhance system protection.. SUSE Linux Micro kernel security important update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.