An update that solves seven vulnerabilities can now be installed.. # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20252-1 Release Date: 2026-01-19T15:28:20Z Rating: important References: * bsc#1248400 * bsc#1248670 * bsc#1249241 * bsc#1250192 * bsc#1251203 * bsc#1251787 * bsc#1253437 Cross-References: * CVE-2023-53676 * CVE-2025-38476 * CVE-2025-38572 * CVE-2025-38588 * CVE-2025-38608 * CVE-2025-39682 * CVE-2025-40204 CVSS scores: * CVE-2023-53676 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53676 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-53676 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38476 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38476 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38476 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38572 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38572 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38572 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38588 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38588 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38588 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38608 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38608 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-38608 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39682 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2025-39682 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-33.1 fixes various security issues The following security issues were fixed: * CVE-2023-53676: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() (bsc#1251787). * CVE-2025-38476: rpl: Fix use-after-free in rpl_do_srh_inline() (bsc#1251203). * CVE-2025-38572: ipv6: reject malicious packets in ipv6_gso_segment() (bsc#1248400). * CVE-2025-38588: ipv6: prevent infinite loop in rt6_nlmsg_size() (bsc#1249241). * CVE-2025-38608: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (bsc#1248670). * CVE-2025-39682: tls: fix handling of zero-length records on the rx_list (bsc#1250192). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-237=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-9-1.2 * kernel-livepatch-6_4_0-33-rt-debuginfo-9-1.2 * kernel-livepatch-6_4_0-33-rt-9-1.2 ## References: * https://www.suse.com/security/cve/CVE-2023-53676.html * https://www.suse.com/security/cve/CVE-2025-38476.html * https://www.suse.com/security/cve/CVE-2025-38572.html * https://www.suse.com/security/cve/CVE-2025-38588.html * https://www.suse.com/security/cve/CVE-2025-38608.html * https://www.suse.com/security/cve/CVE-2025-39682.html * https://www.suse.com/security/cve/CVE-2025-40204.html *https://bugzilla.suse.com/show_bug.cgi?id=1248400 * https://bugzilla.suse.com/show_bug.cgi?id=1248670 * https://bugzilla.suse.com/show_bug.cgi?id=1249241 * https://bugzilla.suse.com/show_bug.cgi?id=1250192 * https://bugzilla.suse.com/show_bug.cgi?id=1251203 * https://bugzilla.suse.com/show_bug.cgi?id=1251787 * https://bugzilla.suse.com/show_bug.cgi?id=1253437 . This security update for SUSE Linux addresses multiple vulnerabilities in kernel RT, ensuring enhanced system protection.. SUSE Kernel RT Patch, SUSE Linux Security, Kernel Security Update. . Severity: Important. LinuxSecurity.com Team
Update to 4.11 for CVE-2023-30570. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-60faf77aca 2023-05-13 02:27:14.363675 --------------------------------------------------------------------------------Name : libreswan Product : Fedora 37 Version : 4.11 Release : 1.fc37 URL : https://libreswan.org/ Summary : Internet Key Exchange (IKEv1 and IKEv2) implementation for IPsec Description : Libreswan is a free implementation of IPsec & IKE for Linux. IPsec is the Internet Protocol Security and uses strong cryptography to provide both authentication and encryption services. These services allow you to build secure tunnels through untrusted networks. Everything passing through the untrusted net is encrypted by the ipsec gateway machine and decrypted by the gateway at the other end of the tunnel. The resulting tunnel is a virtual private network or VPN. This package contains the daemons and userland tools for setting up Libreswan. Libreswan also supports IKEv2 (RFC7296) and Secure Labeling Libreswan is based on Openswan-2.6.38 which in turn is based on FreeS/WAN-2.04 --------------------------------------------------------------------------------Update Information: Update to 4.11 for CVE-2023-30570 --------------------------------------------------------------------------------ChangeLog: * Thu May 4 2023 Paul Wouters
CVE-2018-14339 CVE-2018-14340 CVE-2018-14341 . Package : wireshark Version : 1.12.1+g01b65bf-4+deb8u15 CVE ID : CVE-2018-14339 CVE-2018-14340 CVE-2018-14341 CVE-2018-14342 CVE-2018-14343 CVE-2018-14368 CVE-2018-14369 CVE-2018-14339 CVE-2018-14340 CVE-2018-14341 CVE-2018-14342 CVE-2018-14343 CVE-2018-14368 CVE-2018-14369 Due to several flaws different dissectors could go in infinite loop or could be crashed by malicious packets. For Debian 8 "Jessie", these problems have been fixed in version 1.12.1+g01b65bf-4+deb8u15. We recommend that you upgrade your wireshark packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS promptly enhances VLC to address various security flaws, ensuring users remain protected from malicious streams.. Debian LTS, Wireshark Update, Security Issues, Packet Analysis. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.