Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves six vulnerabilities and has one fix can now be installed.. # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22415-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-485=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-32-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 *https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 . Install important security update for SUSE Kernel fixing six vulnerabilities, including heap overflow and netfilter issues.. Kernel Security Update,SUSE Micro 6.0,Security Patch,Heap Overflow Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities and has five fixes can now be installed.. # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:21989-1 Release Date: 2026-06-03T12:28:02Z Rating: important References: * bsc#1210938 * bsc#1239334 * bsc#1239944 * bsc#1243254 * bsc#1243505 * bsc#1245759 * bsc#1253889 * bsc#1257010 * bsc#1260264 * bsc#1262926 * bsc#1265762 Cross-References: * CVE-2025-22868 * CVE-2025-22869 * CVE-2025-58181 * CVE-2026-33186 * CVE-2026-33814 * CVE-2026-34986 CVSS scores: * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-58181 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has five fixes can now be installed. ## Description: This update for google-guest-agent fixes the following issues: Update to version 20260430.00 * Update THIRD_PARTY_LICENSES to be package specific location. (#608) * Update dependencies and go version to 1.26.2 (#607) (bsc#1265762, CVE-2026-33814) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) (bsc#1260264, CVE-2026-33186) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) (bsc#1239334, CVE-2025-22869, bsc#1253889, CVE-2025-58181) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep(#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20260424.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20260423.01 * Update THIRD_PARTY_LICENSES to be package specific location. (#608) * from version 20260423.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routesmonitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20260422.01 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1(#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20260422.00 * Update dependencies and go version to 1.26.2 (#607) * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packaging changes for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Source the contents of /var/google-users.d config files. (#586) * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routesscript from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20260421.00 * Bring topic-stable up to latest point. (#606) * Bring stable branch up to 822ad49fd52b4d29869604af836a33cb22a667ba (#592) * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20260414.00 * Bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#604) * Bump Go API version to 1.26 * Fix crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926, CVE-2026-34986) * Update to version 20260402.00: (bsc#1257010) * Backport oslogin changes for sles16 to legacy agent (#603) * Bump go.opentelemetry.io/otel/sdk from 1.37.0 to 1.40.0 (#596) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) * Actually finally fix the RPM spec (#601) * Correct guest telemetry build target (#600) * Add packaging for new telemetry extension (#599) * Implement new scheduled job for routes monitor (#598) * Add packagingchanges for locally bundled extensions feature support (#593) * Ensure the uninstall script handles GCE metadata endpoint unavailability. (#591) * Disable certificates when security keys are enabled (#588) * Move sourcing of per-user configs to the end of sshd_config, fixing 2FA logins. (#590) * Update to version 20260108.00 * Source the contents of /var/google-users.d config files. (#586) * Update to version 20251223.00 * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251218.01 * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adaptscript in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251218.00 * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251216.00 * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revertcompat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251215.00 * Force remove core plugin configuration for windows (#587) * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251210.00 * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binarydirectly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251209.00 * Force remove core plugin configuration for windows (#587) * Update to version 20251208.00 * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251206.00 * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable originalagent and disable core plugin (#557) * from version 20251205.00 * network: force address manager to always consolidate the OS state (#585) * Bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#583) * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * Update to version 20251120.01 * fix start mode for windows on stable release (#584) * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251120.00 * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251117.00 * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251115.00 * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fixadapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251108.00 * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251107.01 * Don't delete the authorized_keys file when an empty key list is passed to updateAuthorizedKeysFile (#582) * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and installdependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251031.00 * Update agent_uninstall.ps1 (#558) (#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251030.02 * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251030.01 * Update agent_uninstall.ps1 (#558)(#580) * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251030.00 * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251011.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251009.01 * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows packageupdate (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251009.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * Update to version 20251007.00 * Add Tyler, Saswat, Hank to OWNERS (#577) * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts shouldstart after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251006.01 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20251006.00 * Honor core plugin setting on windows package update (#576) * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20251005.00 * Update go version for stable branch to 1.25 (#571) *Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250930.01 * Honor core plugin setting on windows package update (#576) * from version 20250929.01 * Restart agent if core plugin is disabled (#575) * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250929.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250926.00 * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to usemore portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250924.02 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250924.01 * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging(#543) * systemd should manage only the main process (#544) * from version 20250924.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * Update to version 20250923.01 * Add extra debug logging around toggling OS Login (#572) * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250923.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250921.00 * Add extra debug logging around toggling OS Login (#572) * from version 20250920.01 * Update go version to 1.25 (#565) * Add compat adapt script to windows inagent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250920.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250918.01 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemdshould manage only the main process (#544) * from version 20250917.01 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250917.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250916.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250915.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdownboth (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * Disable missing daemon google_guest_agent_manager referenced by google- startup-scripts.service * Update to version 20250908.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250907.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version20250905.01 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250905.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250902.00 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * Build and install new gce_workload_cert_refresh binary * Fix installation source of google_metadata_script_runner_adapt script * Install new systemd service file * gce-workload-cert-refresh.service * Update to version 20250901.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep(#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250831.03 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250831.02 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manageonly the main process (#544) * from version 20250831.01 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250831.00 * Update go version to 1.25 (#565) * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250830.02 * Update go version for stable branch to 1.25 (#571) * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250830.01 * Update go version to 1.25 (#565) * from version 20250830.00 * Add compat adapt script to windows in agent sysprep (#569) * Fix adapt to use more portable shebang line (#567) * Remove routes script from packaging (#566) * Update adapt script to run onstartup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250828.00 * Add adapt script in stable branch as per #569 (#570) * Backport fix from #567 to stable branch (#568) * from version 20250826.00 * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250821.01 * Remove routes script from packaging (#566) * Update Go API version to 1.25 * Update to version 20250718.00 * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * Update to version 20250709.02 * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agentand disable core plugin (#557) * from version 20250709.01 * Update adapt script to run on startup/shutdown both (#561) * Update agent_uninstall.ps1 (#558) * Stop core plugin before removing agent package (#554) * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * from version 20250709.00 * Revert compat behavior and call known binary directly (#560) * Revert compat behavior and call known binary directly (#559) * Build rollforward package to re-enable original agent and disable core plugin (#557) * from version 20250702.00 * Update adapt script to run on startup/shutdown both (#561) * from version 20250701.01 * Update agent_uninstall.ps1 (#558) * from version 20250701.00 * Stop core plugin before removing agent package (#554) * from version 20250628.00 * Startup scripts should start after agent manager instead (#553) * Update presets and install dependencies on systemd units (#552) * Ensure agent service is disabled (#551) * from version 20250626.00 * Disable legacy agent to enable core plugin (#550) * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * startup script: wrap compatibility decision into its own scripts (#538) * Reapply "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) (#540) * from version 20250625.00 * prepare stable release. * Installgoogle_metadata_script_runner_adapt script (bsc#1245759) * Update to version 20250624.00 * Final fix for RHEL packaging for routes setup (#549) * Fix RHEL packaging for routes scripts (#548) * Packaging changes to include routes script installation (#542) * Update CLI name in packaging (#543) * systemd should manage only the main process (#544) * startup script: wrap compatibility decision into its own scripts (#538) * Reapply "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) (#540) * from version 20250611.01 * prepare stable release. * from version 20250611.00 * startup script: wrap compatibility decision into its own scripts (#538) * Reapply "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) (#540) * from version 20250609.00 * prepare stable release. * from version 20250605.00 * startup script: wrap compatibility decision into its own scripts (#538) * Reapply "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) (#540) * Make sure agent added connections are activated by NM (#534) * wrap NSS cache refresh in a goroutine (#533) * Wicked: Only reload interfaces for which configurations are written or changed. (#524) * Add AuthorizedKeysCompat to windows packaging (#530) * Remove error messages from gce_workload_cert_refresh and metadata script runner (#527) * Update guest-logging-go dependency (#526) * Add 'created-by' metadata, and pass it as option to logging library (#508) * Revert "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) * Re-enable disabled services if the core plugin was enabled (#522) * Enable guest services on package upgrade (#519) * oslogin: Correctly handle newlines at the end of modified files (#520) * Fix core plugin path (#518) * Fix package build issues (#517) * Fix dependencies ran go mod tidy -v (#515) * Fix debian build path (#514) * Bundle compat metadata script runner binary inpackage (#513) * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512) * Update startup/shutdown services to launch compat manager (#503) * Bundle new gce metadata script runner binary in agent package (#502) * Revert "Revert bundling new binaries in the package (#509)" (#511) * Update to version 20250604.00 * Preparing stable build. * from version 20250602.00 * Make sure agent added connections are activated by NM (#534) * wrap NSS cache refresh in a goroutine (#533) * Wicked: Only reload interfaces for which configurations are written or changed. (#524) * Add AuthorizedKeysCompat to windows packaging (#530) * Remove error messages from gce_workload_cert_refresh and metadata script runner (#527) * Update guest-logging-go dependency (#526) * Add 'created-by' metadata, and pass it as option to logging library (#508) * Revert "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) * Re-enable disabled services if the core plugin was enabled (#522) * Enable guest services on package upgrade (#519) * oslogin: Correctly handle newlines at the end of modified files (#520) * Fix core plugin path (#518) * Fix package build issues (#517) * Fix dependencies ran go mod tidy -v (#515) * Fix debian build path (#514) * Bundle compat metadata script runner binary in package (#513) * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512) * Update startup/shutdown services to launch compat manager (#503) * Bundle new gce metadata script runner binary in agent package (#502) * Revert "Revert bundling new binaries in the package (#509)" (#511) * from version 20250521.00 * Preparing stable build. * from version 20250515.00 * Make sure agent added connections are activated by NM (#534) * wrap NSS cache refresh in a goroutine (#533) * Wicked: Only reload interfaces for which configurations are written or changed. (#524) * Add AuthorizedKeysCompat to windows packaging (#530) * Remove error messages from gce_workload_cert_refreshand metadata script runner (#527) * Update guest-logging-go dependency (#526) * Add 'created-by' metadata, and pass it as option to logging library (#508) * Revert "oslogin: Correctly handle newlines at the end of modified files (#520)" (#523) * Re-enable disabled services if the core plugin was enabled (#522) * Enable guest services on package upgrade (#519) * oslogin: Correctly handle newlines at the end of modified files (#520) * Fix core plugin path (#518) * Fix package build issues (#517) * Fix dependencies ran go mod tidy -v (#515) * Fix debian build path (#514) * Bundle compat metadata script runner binary in package (#513) * Bump golang.org/x/net from 0.27.0 to 0.36.0 (#512) * Update startup/shutdown services to launch compat manager (#503) * Bundle new gce metadata script runner binary in agent package (#502) * Revert "Revert bundling new binaries in the package (#509)" (#511) * Update to version 20250508.00 * Preparing stable build. * from version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-741=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-guest-agent-20260430.00-1.1 * google-guest-agent-debuginfo-20260430.00-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22868.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-58181.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1239334 * https://bugzilla.suse.com/show_bug.cgi?id=1239944 *https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1245759 * https://bugzilla.suse.com/show_bug.cgi?id=1253889 * https://bugzilla.suse.com/show_bug.cgi?id=1257010 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1262926 * https://bugzilla.suse.com/show_bug.cgi?id=1265762 . Address six security issues in google-guest-agent with this important SUSE update for enhanced system safety.. google-guest-agent update, SUSE security, vulnerabilities patch. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21939-1 Release Date: 2026-06-01T09:26:54Z Rating: important References: * bsc#1259798 * bsc#1260563 * bsc#1260908 * bsc#1264096 * bsc#1265224 * bsc#1265384 Cross-References: * CVE-2025-54518 * CVE-2026-23243 * CVE-2026-23274 * CVE-2026-23317 * CVE-2026-46300 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23243 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 (SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). * CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). * CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-459=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-6-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-23243.html * https://www.suse.com/security/cve/CVE-2026-23274.html * https://www.suse.com/security/cve/CVE-2026-23317.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1259798 * https://bugzilla.suse.com/show_bug.cgi?id=1260563 *https://bugzilla.suse.com/show_bug.cgi?id=1260908 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . Install important security update that resolves six issues for SUSE Linux Enterprise Micro kernel Live Patch 16.. SUSE Linux Micro, kernel security, important patch. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2172-1 Release Date: 2026-05-31T15:06:21Z Rating: important References: * bsc#1259798 * bsc#1260563 * bsc#1260908 * bsc#1264096 * bsc#1265224 * bsc#1265384 Cross-References: * CVE-2025-54518 * CVE-2026-23243 * CVE-2026-23274 * CVE-2026-23317 * CVE-2026-46300 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23243 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23317 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 (SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.92 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798). * CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908). * CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260563). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2172=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2172=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2170=1 SUSE-2026-2171=1SUSE-2026-2165=1 SUSE-2026-2166=1 SUSE-2026-2167=1 SUSE-2026-2173=1 SUSE-2026-2169=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2170=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2171=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2165=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2166=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2167=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2173=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2169=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-8-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-8-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-8-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-8-150500.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_50-default-debuginfo-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-7-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_50-default-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_11-debugsource-18-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-4-150600.2.1 *kernel-livepatch-SLE15-SP6_Update_12-debugsource-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-4-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_50-default-debuginfo-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-7-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_50-default-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_60-default-16-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_11-debugsource-18-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-4-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-18-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-6-150600.2.1 *kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-4-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-23243.html * https://www.suse.com/security/cve/CVE-2026-23274.html * https://www.suse.com/security/cve/CVE-2026-23317.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1259798 * https://bugzilla.suse.com/show_bug.cgi?id=1260563 * https://bugzilla.suse.com/show_bug.cgi?id=1260908 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 . An important update for SUSE Linux Kernel addresses multiple issues and enhances security. Install updates promptly.. Kernel Update, Live Patching, SUSE Security, Linux Kernel, SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:21554-1 Release Date: 2026-05-05T19:49:32Z Rating: important References: * bsc#1258005 * bsc#1258655 * bsc#1259126 * bsc#1261630 * bsc#1261845 * bsc#1263689 Cross-References: * CVE-2025-71066 * CVE-2026-23004 * CVE-2026-23204 * CVE-2026-23437 * CVE-2026-31406 * CVE-2026-31431 CVSS scores: * CVE-2025-71066 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23437 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23437 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23437 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31406 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31406 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: *SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1258005). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). * CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). * CVE-2026-23437: net: shaper: protect late read accesses to the hierarchy (bsc#1261845). * CVE-2026-31406: xfrm: Fix work re-schedule after cancel in xfrm_nat_keepalive_net_fini() (bsc#1261630). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-691=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-691=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71066.html * https://www.suse.com/security/cve/CVE-2026-23004.html *https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-23437.html * https://www.suse.com/security/cve/CVE-2026-31406.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1258005 * https://bugzilla.suse.com/show_bug.cgi?id=1258655 * https://bugzilla.suse.com/show_bug.cgi?id=1259126 * https://bugzilla.suse.com/show_bug.cgi?id=1261630 * https://bugzilla.suse.com/show_bug.cgi?id=1261845 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . Important update for SUSE Linux Enterprise fixes six security issues in kernel live patch affecting systems.. SUSE Linux Enterprise,Kernels,Security Update,Live Patch,SUSE 16. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21501-1 Release Date: 2026-05-05T13:15:07Z Rating: important References: * bsc#1252048 * bsc#1258005 * bsc#1258073 * bsc#1258655 * bsc#1259126 * bsc#1263689 Cross-References: * CVE-2025-38375 * CVE-2025-39977 * CVE-2025-71066 * CVE-2026-23004 * CVE-2026-23204 * CVE-2026-31431 CVSS scores: * CVE-2025-38375 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38375 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39977 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-39977 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71066 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23004 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23004 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-23204 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23204 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE LinuxEnterprise Kernel 6.4.0-29.1 fixes various security issues The following security issues were fixed: * CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1258073). * CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252048). * CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1258005). * CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). * CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). * CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-394=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_7-debugsource-17-1.2 * kernel-livepatch-6_4_0-29-default-17-1.2 * kernel-livepatch-6_4_0-29-default-debuginfo-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-38375.html * https://www.suse.com/security/cve/CVE-2025-39977.html * https://www.suse.com/security/cve/CVE-2025-71066.html * https://www.suse.com/security/cve/CVE-2026-23004.html * https://www.suse.com/security/cve/CVE-2026-23204.html * https://www.suse.com/security/cve/CVE-2026-31431.html * https://bugzilla.suse.com/show_bug.cgi?id=1252048 * https://bugzilla.suse.com/show_bug.cgi?id=1258005 * https://bugzilla.suse.com/show_bug.cgi?id=1258073 * https://bugzilla.suse.com/show_bug.cgi?id=1258655 * https://bugzilla.suse.com/show_bug.cgi?id=1259126 * https://bugzilla.suse.com/show_bug.cgi?id=1263689 . SUSE Linux Micro update addresses important kernel security issues fixing six identified flaws. Install recommendedupdates.. SUSE Linux Micro Kernel Update, Security Flaws, Important Security Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:1136-1 Release Date: 2026-03-27T18:04:05Z Rating: important References: * bsc#1255053 * bsc#1255378 * bsc#1255402 * bsc#1255895 * bsc#1256624 * bsc#1256644 Cross-References: * CVE-2025-40258 * CVE-2025-40297 * CVE-2025-68284 * CVE-2025-68285 * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2025-40258 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40258 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40297 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40297 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68284 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68284 ( SUSE ): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-68285 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68285 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel6.4.0-150700.53.25 fixes various security issues The following security issues were fixed: * CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). * CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255895). * CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). * CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-1136=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_25-default-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_53_25-default-2-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_7-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40258.html * https://www.suse.com/security/cve/CVE-2025-40297.html * https://www.suse.com/security/cve/CVE-2025-68284.html * https://www.suse.com/security/cve/CVE-2025-68285.html * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html * https://bugzilla.suse.com/show_bug.cgi?id=1255053 * https://bugzilla.suse.com/show_bug.cgi?id=1255378 * https://bugzilla.suse.com/show_bug.cgi?id=1255402 * https://bugzilla.suse.com/show_bug.cgi?id=1255895 * https://bugzilla.suse.com/show_bug.cgi?id=1256624 * https://bugzilla.suse.com/show_bug.cgi?id=1256644 . Critical update patching sixissues in SUSE Linux Kernel improves security and stability for enterprises.. SUSE Linux Patch, Kernel Security Update, Linux Enterprise Server. . Severity: Important. LinuxSecurity.com Team
An update that solves six vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:1100-1 Release Date: 2026-03-26T23:08:13Z Rating: important References: * bsc#1255053 * bsc#1255378 * bsc#1255402 * bsc#1255895 * bsc#1256624 * bsc#1256644 Cross-References: * CVE-2025-40258 * CVE-2025-40297 * CVE-2025-68284 * CVE-2025-68285 * CVE-2025-68813 * CVE-2025-71085 CVSS scores: * CVE-2025-40258 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40258 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40297 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40297 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68284 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68284 ( SUSE ): 7.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-68285 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-68285 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68813 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-68813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71085 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE LinuxEnterprise Kernel 6.4.0-150600.23.81 fixes various security issues The following security issues were fixed: * CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). * CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255895). * CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). * CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). * CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). * CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1100=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-1100=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-2-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-2-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-2-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-2-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-2-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-2-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40258.html * https://www.suse.com/security/cve/CVE-2025-40297.html * https://www.suse.com/security/cve/CVE-2025-68284.html * https://www.suse.com/security/cve/CVE-2025-68285.html * https://www.suse.com/security/cve/CVE-2025-68813.html * https://www.suse.com/security/cve/CVE-2025-71085.html *https://bugzilla.suse.com/show_bug.cgi?id=1255053 * https://bugzilla.suse.com/show_bug.cgi?id=1255378 * https://bugzilla.suse.com/show_bug.cgi?id=1255402 * https://bugzilla.suse.com/show_bug.cgi?id=1255895 * https://bugzilla.suse.com/show_bug.cgi?id=1256624 * https://bugzilla.suse.com/show_bug.cgi?id=1256644 . Update addresses six important security issues in SUSE Linux kernel. Immediate patch recommended for users.. SUSE Linux Enterprise Kernel, important security update, live patch installations. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.