Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 60 vulnerabilities and has four fixes can now be installed.. # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22099-1 Release Date: 2026-06-15T10:50:32Z Rating: important References: * bsc#1259884 * bsc#1260502 * bsc#1260548 * bsc#1261041 * bsc#1261603 * bsc#1261619 * bsc#1261791 * bsc#1262606 * bsc#1262615 * bsc#1262619 * bsc#1262622 * bsc#1262624 * bsc#1263006 * bsc#1263058 * bsc#1263062 * bsc#1263115 * bsc#1263180 * bsc#1263579 * bsc#1263594 * bsc#1263724 * bsc#1263794 * bsc#1263883 * bsc#1263932 * bsc#1264000 * bsc#1264040 * bsc#1264091 * bsc#1264196 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264415 * bsc#1264484 * bsc#1264609 * bsc#1264622 * bsc#1264672 * bsc#1264723 * bsc#1264765 * bsc#1265081 * bsc#1265114 * bsc#1265170 * bsc#1265186 * bsc#1265579 * bsc#1266394 * bsc#1266400 * bsc#1266696 * bsc#1266711 * bsc#1266720 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266888 * bsc#1266889 * bsc#1266901 * bsc#1266914 * bsc#1266927 * bsc#1266972 * bsc#1267205 * bsc#1267214 * bsc#1267220 * bsc#1267531 * bsc#1267652 * bsc#1267875 * bsc#1268018 Cross-References: * CVE-2026-23254 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23438 * CVE-2026-31396 * CVE-2026-31401 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31556 * CVE-2026-31562 * CVE-2026-31584 * CVE-2026-31645 * CVE-2026-31648 * CVE-2026-31655 * CVE-2026-31671 * CVE-2026-31683 * CVE-2026-31703 * CVE-2026-31774 * CVE-2026-43026 * CVE-2026-43030 * CVE-2026-43040 * CVE-2026-43063 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43109 * CVE-2026-43150 * CVE-2026-43184 * CVE-2026-43197 * CVE-2026-43332 * CVE-2026-43393 * CVE-2026-43394 * CVE-2026-43411 * CVE-2026-43455 * CVE-2026-45842 * CVE-2026-45846 *CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45886 * CVE-2026-45898 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45942 * CVE-2026-45970 * CVE-2026-45984 * CVE-2026-46021 * CVE-2026-46043 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46114 * CVE-2026-46159 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46316 * CVE-2026-46317 CVSS scores: * CVE-2026-23254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31401 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31401 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31556 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31556 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31556 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31562 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31562 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31562 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31584 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31584 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31645 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N *CVE-2026-31645 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31645 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31648 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31648 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31648 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31683 ( SUSE ): 5.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31683 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-31683 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31774 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31774 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43063 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43063 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43150 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43150 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43150 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43184 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43184 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-43184 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43197 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43332 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43332 ( SUSE ): 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43393 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43393 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43393 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43394 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43394 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N *CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45898 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45898 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45942 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45942 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45942 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46021 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46316 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46316 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46317 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server High Availability Extension 16.0 An update that solves 60 vulnerabilities and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-23254: net: gro: fix outer network offset (bsc#1259884). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() (bsc#1260548). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31401: HID: bpf: prevent buffer overflow in hid_hw_request (bsc#1261603). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31556: xfs: scrub: unlock dquot before early return in quota scrub (bsc#1263062). * CVE-2026-31562: drm/mediatek: dsi: Store driver data before invoking mipi_dsi_host_register (bsc#1263058). * CVE-2026-31584: media: mediatek: vcodec: fix use-after-free in encoder release path (bsc#1263180). * CVE-2026-31645: net: lan966x: fix page pool leak in error paths (bsc#1263794). * CVE-2026-31648: mm: filemap: fix nr_pages calculation overflow in filemap_map_pages() (bsc#1263579). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31683: batman-adv: avoid OGM aggregation when skb tailroom is insufficient (bsc#1263594). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31774: io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (bsc#1264040). *CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak (bsc#1264091). * CVE-2026-43063: xfs: don't irele after failing to iget in xfs_attri_recover_work (bsc#1264196). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43150: perf/arm-cmn: Reject unsupported hardware configurations (bsc#1264415). * CVE-2026-43184: rnbd-srv: Zero the rsp buffer before using it (bsc#1264622). * CVE-2026-43197: netconsole: avoid OOB reads, msg is not nul-terminated (bsc#1264609). * CVE-2026-43332: thermal: core: Fix thermal zone device registration error path (bsc#1265114). * CVE-2026-43393: btrfs: fix chunk map leak in btrfs_map_block() after btrfs_chunk_map_num_copies() (bsc#1264723). * CVE-2026-43394: nfsd: Fix cred ref leak in nfsd_nl_listener_set_doit() (bsc#1265081). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). *CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45898: RDMA/iwcm: Fix workqueue list corruption by removing work_list (bsc#1266888). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45942: ext4: fix e4b bitmap inconsistency reports (bsc#1266914). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45984: gfs2: Fix use-after-free in iomap inline data write path (bsc#1267214). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). The following non security issues were fixed: * accel/ivpu: Add bounds checks for firmware log indices (git-fixes). * accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: seq: dummy: fix UMP event stack overread (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes). * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes). * Bluetooth: bnep:reject short frames before parsing (git-fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * config: remove DEBUG_FS_DISALLOW_MOUNT * debugfs: Remove broken no-mount mode (bsc#1265186). * debugfs: Fix default access mode config check (bsc#1265186). * debugfs: Remove broken no-mount mode (bsc#1265186). * debugfs: Remove redundant access mode checks (bsc#1265186). * drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Reject gpio_bitshift > = 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes). * drm/xe: Clear pending_disable before signaling suspend fence (git-fixes). * ima: return error early if file xattr cannot be changed (bsc#1261041). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * KVM: arm64: Reassign nested_mmus array behind mmu_lock (git-fixes). * KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation (git-fixes). * KVM: arm64: vgic-its: Drop the translation cachereference only for the erased entry (git-fixes). * KVM: SEV: Check PSC request indices against the actual size of the buffer (git-fixes). * KVM: SEV: Compute the correct max length of the in-GHCB scratch area (git- fixes). * KVM: SEV: Don't explicitly pass PSC buffer to snp_begin_psc() (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SEV: Reject MMIO requests larger than 8 bytes with GHCB v2+ (git- fixes). * KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (git-fixes). * KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer (git- fixes). * KVM: SEV: Use the size of the PSC header as the minimum size for PSC requests (git-fixes). * KVM: SEV: WARN if KVM attempts to setup scratch area with min_len==0 (git- fixes). * KVM: SVM: Convert plain error code numbers to defines (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Provide helpers to set the error code (git-fixes). * KVM: x86: Consolidate SEV-ES MMIO emulation into a single public API (git- fixes). * KVM: x86: Dedup kvm_sev_es_mmio_{read,write}() (git-fixes). * KVM: x86: Harden SEV-ES MMIO against on-stack use-after-free (git-fixes). * KVM: x86: Move MMIO write tracing into vcpu_mmio_write() (git-fixes). * KVM: x86: Open code handling of completed MMIO reads in emulator_read_write() (git-fixes). * KVM: x86: Open code read vs. write userspace MMIO exits in emulator_read_write() (git-fixes). * KVM: x86: Trace unsatisfied MMIO reads on a per-page basis (git-fixes). * KVM: x86: Use local MMIO fragment variable to clean up emulator_read_write() (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: dw_mmc-rockchip: Add missing private data for very old controllers (git-fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0(git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-929=1 ## Package List: * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * cluster-md-kmp-default-6.12.0-160000.35.1 * gfs2-kmp-default-debuginfo-6.12.0-160000.35.1 * dlm-kmp-default-debuginfo-6.12.0-160000.35.1 * gfs2-kmp-default-6.12.0-160000.35.1 * kernel-default-debuginfo-6.12.0-160000.35.1 * cluster-md-kmp-default-debuginfo-6.12.0-160000.35.1 * kernel-default-debugsource-6.12.0-160000.35.1 * dlm-kmp-default-6.12.0-160000.35.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (nosrc) * kernel-default-6.12.0-160000.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23254.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31401.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html *https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31556.html * https://www.suse.com/security/cve/CVE-2026-31562.html * https://www.suse.com/security/cve/CVE-2026-31584.html * https://www.suse.com/security/cve/CVE-2026-31645.html * https://www.suse.com/security/cve/CVE-2026-31648.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31683.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31774.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43063.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43150.html * https://www.suse.com/security/cve/CVE-2026-43184.html * https://www.suse.com/security/cve/CVE-2026-43197.html * https://www.suse.com/security/cve/CVE-2026-43332.html * https://www.suse.com/security/cve/CVE-2026-43393.html * https://www.suse.com/security/cve/CVE-2026-43394.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45898.html * https://www.suse.com/security/cve/CVE-2026-45910.html *https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45942.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46316.html * https://www.suse.com/security/cve/CVE-2026-46317.html * https://bugzilla.suse.com/show_bug.cgi?id=1259884 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260548 * https://bugzilla.suse.com/show_bug.cgi?id=1261041 * https://bugzilla.suse.com/show_bug.cgi?id=1261603 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263058 * https://bugzilla.suse.com/show_bug.cgi?id=1263062 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263180 * https://bugzilla.suse.com/show_bug.cgi?id=1263579 * https://bugzilla.suse.com/show_bug.cgi?id=1263594 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263794 *https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264040 * https://bugzilla.suse.com/show_bug.cgi?id=1264091 * https://bugzilla.suse.com/show_bug.cgi?id=1264196 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264415 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264609 * https://bugzilla.suse.com/show_bug.cgi?id=1264622 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264723 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1265081 * https://bugzilla.suse.com/show_bug.cgi?id=1265114 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265186 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266888 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266914 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 *https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267875 * https://bugzilla.suse.com/show_bug.cgi?id=1268018 . New SUSE kernel security update addresses critical vulnerabilities. Immediate action recommended to protect systems.. SUSE kernel update, security patches, system vulnerabilities, important updates. . Severity: Important. LinuxSecurity.com Team
An update that solves eight vulnerabilities can now be installed.. # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:21058-1 Release Date: 2026-04-09T13:21:12Z Rating: important References: * bsc#1252036 * bsc#1252689 * bsc#1253404 * bsc#1256780 * bsc#1257238 * bsc#1258051 * bsc#1258183 * bsc#1258784 Cross-References: * CVE-2025-39973 * CVE-2025-40018 * CVE-2025-40159 * CVE-2025-71120 * CVE-2026-22999 * CVE-2026-23074 * CVE-2026-23111 * CVE-2026-23209 CVSS scores: * CVE-2025-39973 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-39973 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40018 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40018 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40159 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40159 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71120 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71120 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71120 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-22999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-22999 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23074 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23111 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23209 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036). * CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252689). * CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation (bsc#1253404). * CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256780). * CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257238). * CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1258051). * CVE-2026-23111: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() (bsc#1258183). * CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258784). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-336=1 ## Package List: * SUSE Linux Micro 6.1(x86_64) * kernel-livepatch-6_4_0-31-rt-14-1.2 * kernel-livepatch-6_4_0-31-rt-debuginfo-14-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-14-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-39973.html * https://www.suse.com/security/cve/CVE-2025-40018.html * https://www.suse.com/security/cve/CVE-2025-40159.html * https://www.suse.com/security/cve/CVE-2025-71120.html * https://www.suse.com/security/cve/CVE-2026-22999.html * https://www.suse.com/security/cve/CVE-2026-23074.html * https://www.suse.com/security/cve/CVE-2026-23111.html * https://www.suse.com/security/cve/CVE-2026-23209.html * https://bugzilla.suse.com/show_bug.cgi?id=1252036 * https://bugzilla.suse.com/show_bug.cgi?id=1252689 * https://bugzilla.suse.com/show_bug.cgi?id=1253404 * https://bugzilla.suse.com/show_bug.cgi?id=1256780 * https://bugzilla.suse.com/show_bug.cgi?id=1257238 * https://bugzilla.suse.com/show_bug.cgi?id=1258051 * https://bugzilla.suse.com/show_bug.cgi?id=1258183 * https://bugzilla.suse.com/show_bug.cgi?id=1258784 . SUSE Linux Enterprise Micro 6.0 update resolves eight important issues, enhancing overall system security.. SUSE Linux Micro 6.0, Kernel RT, Security Update, Important Fixes. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability, contains two features and has 51 security fixes can now be installed.. # Maintenance update for Multi-Linux Manager 4.3: Server, Proxy and Retail Announcement ID: SUSE-SU-2026:1031-1 Release Date: 2026-03-25T10:19:43Z Rating: important References: * bsc#1213308 * bsc#1214568 * bsc#1214569 * bsc#1216711 * bsc#1217755 * bsc#1220899 * bsc#1221950 * bsc#1223368 * bsc#1227577 * bsc#1227579 * bsc#1228577 * bsc#1230876 * bsc#1232125 * bsc#1233496 * bsc#1236066 * bsc#1236799 * bsc#1237536 * bsc#1238481 * bsc#1239636 * bsc#1240565 * bsc#1241013 * bsc#1243241 * bsc#1243679 * bsc#1243768 * bsc#1243808 * bsc#1243876 * bsc#1243881 * bsc#1244177 * bsc#1244542 * bsc#1244648 * bsc#1244724 * bsc#1245241 * bsc#1245307 * bsc#1245405 * bsc#1245766 * bsc#1246421 * bsc#1246981 * bsc#1247038 * bsc#1248741 * bsc#1248804 * bsc#1249502 * bsc#1251864 * bsc#1251995 * bsc#1252937 * bsc#1253024 * bsc#1253068 * bsc#1253158 * bsc#1253322 * bsc#1253501 * bsc#1253773 * bsc#1255298 * bsc#1257538 * jsc#MSQA-1046 * jsc#SUMA-406 Cross-References: * CVE-2024-29371 CVSS scores: * CVE-2024-29371 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-29371 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-29371 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 *SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Client Tools for SLE 15 * SUSE Manager Client Tools for SLE Micro 5 An update that solves one vulnerability, contains two features and has 51 security fixes can now be installed. ## Recommended update 4.3.17 for Multi-Linux Manager Proxy and Retail Branch Server LTS ### Description: This update fixes the following issues: mgr-cfg: * Version 4.3.7-0 * Non-customer-facing optimization and update mgr-custom-info: * Version 4.3.4-0 * Non-customer-facingoptimization and update mgr-daemon: * Version 4.3.13-0 * Update translation strings mgr-osad: * Version 4.3.8-0 * Non-customer-facing optimization and update mgr-push: * Version 4.3.7-0 * Non-customer-facing optimization and update rhnlib: * Version 4.3.8-0 * Use more secure defusedxml parser (bsc#1227577) spacecmd: * Version 4.3.32-0 * Make caching code Py 2.7 compatible * Python 2.7 cannot re-raise exceptions * Make spacecmd to work with Python 3.12 and higher * Call print statements properly in Python 3 * Convert cached IDs to int (bsc#1251995) * Use JSON instead of pickle for spacecmd cache (bsc#1227579) spacewalk-backend: * Version 4.3.35-0 * Prevent authentication issues with traditional stack (bsc#1253068) * Fix parameter error when syncing product repositories in ISS v1 (bsc#1244724) * Fix fetching the mirrorlist with a ca bundle which include only the intermediate CAs. This is the case for RHUI CA bundles (bsc#1243241). * Use more secure defusedxml parser (bsc#1227577) spacewalk-certs-tools: * Version 4.3.27-0 * Non-customer-facing optimization and update spacewalk-client-tools: * Version 4.3.24-0 * Update translation strings spacewalk-proxy: * Version 4.3.21-0 * Non-customer-facing optimization and update spacewalk-proxy-docs: * Version 4.3.2-0 * Non-customer-facing optimization and update spacewalk-proxy-html: * Version 4.3.4-0 * Non-customer-facing optimization and update spacewalk-proxy-installer: * Version 4.3.13-0 * Configure squid replacement policy properly before cache dir (bsc#1253773) spacewalk-setup-jabberd: * Version 4.3.2-0 * Non-customer-facing optimization and update spacewalk-ssl-cert-check: * Version 4.3.4-0 * Non-customer-facing optimization and update spacewalk-web: * Version 4.3.48-0 * Fix broken CVE links in CVE audit page. * Fix bug: confirmation message missing when assigning channel to minion (bsc#1236799) * Fix URL to salt formular documentation(bsc#1248741) supportutils-plugin-susemanager-client: * Version 4.3.6-0 * Non-customer-facing optimization and update suseRegisterInfo: * Version 4.3.4-0 * Non-customer-facing optimization and update uyuni-base: * Version 4.3.3-0 * Non-customer-facing optimization and update uyuni-proxy-systemd-services: * Version 4.3.19-0 * Updated for SUSE Manager 4.3.17 How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy or Retail Branch Server LTS. 2. Stop the proxy service: `spacewalk-proxy stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-proxy start` ## Security update 4.3.17 for Multi-Linux Manager Server LTS ### Description: This update fixes the following issues: cobbler: * Fix "test_grubimage_run" on Uyuni and SUSE Multi-Linux Manager test containers inter-server-sync: * Version 0.3.10-0 * Write log to a rotated file without rsyslog and logrotate * Recreate cobbler entries on the import (bsc#1220899) * remove support for 4.2 file based pillars * use correct hostname detection for 5.x servers (bsc#1253322) * Version 0.3.9-0 * Do not export autogenerated identity column (bsc##1244648) * Version 0.3.8-0 * Rename suseproductsccrepository to susechanneltemplate (bsc#1244648) * Allow skipping changelog export (bsc#1245307) * Add options to specify xmlRpcPassword via file path or stdin jose4j: * CVE-2024-29371: Safeguard against excessive resource utilization by restricting the size of data during JWE payload decompression (bsc#1255298) liberate-formula: * Version 0.1.1 * fix installation for liberty 7 (bsc#1246981) * Change reinstall parameter default value to false mgr-osad: * Version 4.3.8-0 * Non-customer-facing optimization and update mgr-push: * Version 4.3.7-0 * Non-customer-facing optimization and update perl-Satcon: * Version 4.3.3-0 * Non-customer-facing optimization and update prometheus-exporters-formula: *Version 1.4.2 * Allow only node exporter on transactional systems (bsc#1244542) prometheus-formula: * Version 0.9.0 * Check for supported distributions (bsc#1243876) * Fix checking Prometheus package version rhnlib: * Version 4.3.8-0 * Use more secure defusedxml parser (bsc#1227577) spacecmd: * Version 4.3.32-0 * Make caching code Py 2.7 compatible * Python 2.7 cannot re-raise exceptions * Make spacecmd to work with Python 3.12 and higher * Call print statements properly in Python 3 * Convert cached IDs to int (bsc#1251995) * Use JSON instead of pickle for spacecmd cache (bsc#1227579) spacewalk: * Version 4.3.7-0 * Non-customer-facing optimization and update spacewalk-admin: * Version 4.3.15-0 * Correctly handles http proxy empty passwords (bsc#1249502) spacewalk-backend: * Version 4.3.35-0 * Prevent authentication issues with traditional stack (bsc#1253068) * Fix parameter error when syncing product repositories in ISS v1 (bsc#1244724) * Fix fetching the mirrorlist with a ca bundle which include only the intermediate CAs. This is the case for RHUI CA bundles (bsc#1243241). * Use more secure defusedxml parser (bsc#1227577) spacewalk-branding: * Version 4.3.6-0 * Non-customer-facing optimization and update spacewalk-certs-tools: * Version 4.3.27-0 * Non-customer-facing optimization and update spacewalk-client-tools: * Version 4.3.24-0 * Update translation strings spacewalk-config: * Version 4.3.17-0 * Non-customer-facing optimization and update spacewalk-java: * Version 4.3.90-0 * Fix reposync crashing at metadata generation (bsc#1257538) * Version 4.3.89-0 * Delay highstate during bootstrap to run it after the initial minimal state (bsc#1240565) * add proxy option to provisionSystem API (bsc#1232125) * Fix dnf updateinfo showing wrong severity for security updates (bsc#1252937) * Display correct advisory link by using an errata advisory map (bsc#1243808) * Improve hibernate object creation for ServerPath(bsc#1243881) * Prevent printing user input in traceback logs and mails (bsc#1239636) * Send CPU architecture specific data to SCC (jsc#SUMA-406) * Fix broken CVE links in CVE audit page. * Fix http proxy verification (bsc#1253501) * Fix: Broken URL in API docs (bsc#1244177) * Correctly handles http proxy empty passwords (bsc#1249502) * Ensure null safety when converting from proxy paths to host names (bsc#1237536) * Use the correct identifier to map the salt migration result * Succeed liberate product migration also when reinstall packages is disabled (bsc#1248804) * Prioritize beacon data for regular minion reboot status (bsc#1245405) spacewalk-reports: * Version 4.3.6-0 * Non-customer-facing optimization and update spacewalk-search: * Version 4.3.12-0 * Non-customer-facing optimization and update spacewalk-setup: * Version 4.3.20-0 * Non-customer-facing optimization and update spacewalk-setup-jabberd: * Version 4.3.2-0 * Non-customer-facing optimization and update spacewalk-utils: * Version 4.3.25-0 * Non-customer-facing optimization and update spacewalk-web: * Version 4.3.48-0 * Fix broken CVE links in CVE audit page. * Fix bug: confirmation message missing when assigning channel to minion (bsc#1236799) * Fix URL to salt formular documentation (bsc#1248741) supportutils-plugin-susemanager: * Version 4.3.16-0 * Non-customer-facing optimization and update suseRegisterInfo: * Version 4.3.4-0 * Non-customer-facing optimization and update susemanager: * Version 4.3.43-0 * Added missing bootrap repository definition for OES 24.4 (bsc#1241013) susemanager-docs_en: * Removed CIS from list of supported OpenSCAP profiles * Fixed the incorrect path in Administration Guide (bsc#1221950) * Corrected the reactivation key varaible name (bsc#1253158) * Improved CLM procedure in Adminstration Guide (bsc#1230876) * Added commands to server migration procedures in Installation and Upgrade Guide (bsc#1214569) * Clarifiedrequirement for PAYG in Installation and Upgrade Guide (bsc#1236066) * Added information for proxy migration to Installation and Upgrade Guide (bsc#1214568) * Added reference to dry run documentation (bsc#1223368) * Added information about requesting access to PTFs (bsc#1213308) * Added lang support for new shared header to html outputs * Added shared header styles for documentation.suse.com * Removed Ubuntu 20.04 from the list supported clients in Client Configuration Guide (bsc#1238481) * Fixed output box with grep command in LTS section in Installation and Upgrade Guide (bsc#1247038) * Added procedure to reregister client behind a proxy after renaming the server (bsc#1245766) * Fixed the admonition in Client Configuration Guide (bsc#1233496) * Reorganised files for better visibility of differences between AutoYaST and Kickstart profiles (bsc#1217755) * Fixed command for public cloud module in Installation and Upgrade Guide (bsc#1216711) * Removed obsolete command from Administration Guide (bsc#1228577) * Renamed parameter in Specialized Guides (bsc#1245241) susemanager-schema: * Version 4.3.30-0 * Store CPU architecture specific data (jsc#SUMA-406) * Creation of table suseErrataAdvisoryMap and added errata-advisory-map-sync taskomatic job fixing bug (bsc#1243808) susemanager-sls: * Version 4.3.53-0 * Automatically deploy IBM GPG keys to SUSE minions (bsc#1246421) * Succeed liberate product migration also when reinstall packages is disabled (bsc#1248804) * Adjust sls files for python311-kiwi (bsc#1251864)(bsc#1253024) * Collect CPU architecture specific data on hardware profile update (jsc#SUMA-406) susemanager-tftpsync: * Version 4.3.5-0 * Use TLS in sync_post_tftpd_proxies (bsc#1243679) * Refuse files with shell characters (bsc#1243768) uyuni-base: * Version 4.3.3-0 * Non-customer-facing optimization and update How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server LTS. 2. Stop the Spacewalk service: `spacewalk-service stop` 3. Apply the patch using either zypper patch or YaST Online Update. 4. Start the Spacewalk service: `spacewalk-service start` ## Recommended update for uyuni-proxy-systemd-services ### Description: This update fixes the following issues: uyuni-proxy-systemd-services: * Version 4.3.19-0 * Update for SUSE Manager 4.3.17 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE 15 zypper in -t patch SUSE-SLE-Manager-Tools-15-2026-1031=1 * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2026-1031=1 ## Package List: * SUSE Manager Client Tools for SLE 15 (noarch) * uyuni-proxy-systemd-services-4.3.19-150000.1.40.2 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * uyuni-proxy-systemd-services-4.3.19-150000.1.40.2 ## References: * https://www.suse.com/security/cve/CVE-2024-29371.html * https://bugzilla.suse.com/show_bug.cgi?id=1213308 * https://bugzilla.suse.com/show_bug.cgi?id=1214568 * https://bugzilla.suse.com/show_bug.cgi?id=1214569 * https://bugzilla.suse.com/show_bug.cgi?id=1216711 * https://bugzilla.suse.com/show_bug.cgi?id=1217755 * https://bugzilla.suse.com/show_bug.cgi?id=1220899 * https://bugzilla.suse.com/show_bug.cgi?id=1221950 * https://bugzilla.suse.com/show_bug.cgi?id=1223368 * https://bugzilla.suse.com/show_bug.cgi?id=1227577 * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1228577 * https://bugzilla.suse.com/show_bug.cgi?id=1230876 * https://bugzilla.suse.com/show_bug.cgi?id=1232125 * https://bugzilla.suse.com/show_bug.cgi?id=1233496 * https://bugzilla.suse.com/show_bug.cgi?id=1236066 * https://bugzilla.suse.com/show_bug.cgi?id=1236799 *https://bugzilla.suse.com/show_bug.cgi?id=1237536 * https://bugzilla.suse.com/show_bug.cgi?id=1238481 * https://bugzilla.suse.com/show_bug.cgi?id=1239636 * https://bugzilla.suse.com/show_bug.cgi?id=1240565 * https://bugzilla.suse.com/show_bug.cgi?id=1241013 * https://bugzilla.suse.com/show_bug.cgi?id=1243241 * https://bugzilla.suse.com/show_bug.cgi?id=1243679 * https://bugzilla.suse.com/show_bug.cgi?id=1243768 * https://bugzilla.suse.com/show_bug.cgi?id=1243808 * https://bugzilla.suse.com/show_bug.cgi?id=1243876 * https://bugzilla.suse.com/show_bug.cgi?id=1243881 * https://bugzilla.suse.com/show_bug.cgi?id=1244177 * https://bugzilla.suse.com/show_bug.cgi?id=1244542 * https://bugzilla.suse.com/show_bug.cgi?id=1244648 * https://bugzilla.suse.com/show_bug.cgi?id=1244724 * https://bugzilla.suse.com/show_bug.cgi?id=1245241 * https://bugzilla.suse.com/show_bug.cgi?id=1245307 * https://bugzilla.suse.com/show_bug.cgi?id=1245405 * https://bugzilla.suse.com/show_bug.cgi?id=1245766 * https://bugzilla.suse.com/show_bug.cgi?id=1246421 * https://bugzilla.suse.com/show_bug.cgi?id=1246981 * https://bugzilla.suse.com/show_bug.cgi?id=1247038 * https://bugzilla.suse.com/show_bug.cgi?id=1248741 * https://bugzilla.suse.com/show_bug.cgi?id=1248804 * https://bugzilla.suse.com/show_bug.cgi?id=1249502 * https://bugzilla.suse.com/show_bug.cgi?id=1251864 * https://bugzilla.suse.com/show_bug.cgi?id=1251995 * https://bugzilla.suse.com/show_bug.cgi?id=1252937 * https://bugzilla.suse.com/show_bug.cgi?id=1253024 * https://bugzilla.suse.com/show_bug.cgi?id=1253068 * https://bugzilla.suse.com/show_bug.cgi?id=1253158 * https://bugzilla.suse.com/show_bug.cgi?id=1253322 * https://bugzilla.suse.com/show_bug.cgi?id=1253501 * https://bugzilla.suse.com/show_bug.cgi?id=1253773 * https://bugzilla.suse.com/show_bug.cgi?id=1255298 * https://bugzilla.suse.com/show_bug.cgi?id=1257538 * https://jira.suse.com/browse/MSQA-1046 * https://jira.suse.com/browse/SUMA-406 . Important updatefor SUSE Multi-Linux Manager 4.3 with vulnerability fixes and optimizations to enhance security and functionality.. SUSE Multi-Linux Manager security fixes, important update, Linux vulnerability, patch instructions, SUSE security. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7990-4 February 12, 2026 linux-oracle, linux-oracle-5.4 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-oracle: Linux kernel for Oracle Cloud systems - linux-oracle-5.4: Linux kernel for Oracle Cloud systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Cryptographic API; - Padata parallel execution mechanism; - Netfilter; (CVE-2022-49698, CVE-2025-21726, CVE-2025-40019) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.4.0-1152-oracle 5.4.0-1152.162 Available with Ubuntu Pro linux-image-oracle-5.4 5.4.0.1152.146 Available with Ubuntu Pro linux-image-oracle-lts-20.04 5.4.0.1152.146 Available with Ubuntu Pro Ubuntu 18.04 LTS linux-image-5.4.0-1152-oracle 5.4.0-1152.162~18.04.1 Available with Ubuntu Pro linux-image-oracle 5.4.0.1152.162~18.04.1 Available with Ubuntu Pro linux-image-oracle-5.4 5.4.0.1152.162~18.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third partykernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7990-4 https://ubuntu.com/security/notices/USN-7990-3 https://ubuntu.com/security/notices/USN-7990-2 https://ubuntu.com/security/notices/USN-7990-1 CVE-2022-49698, CVE-2025-21726, CVE-2025-40019 . Several security issues fixed in Ubuntu kernel updating the linux-oracle package is essential for system integrity.. Ubuntu Security Notice, Linux Kernel Update, Oracle Cloud Kernel Fixes. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-7682-5 August 12, 2025 linux-gcp-6.8, linux-raspi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-raspi: Linux kernel for Raspberry Pi systems - linux-gcp-6.8: Linux kernel for Google Cloud Platform (GCP) systems Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network traffic control; (CVE-2025-38083, CVE-2025-37797) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS linux-image-6.8.0-1032-raspi 6.8.0-1032.36 linux-image-raspi 6.8.0-1032.36 linux-image-raspi-6.8 6.8.0-1032.36 Ubuntu 22.04 LTS linux-image-6.8.0-1034-gcp 6.8.0-1034.36~22.04.2 linux-image-6.8.0-1034-gcp-64k 6.8.0-1034.36~22.04.2 linux-image-gcp 6.8.0-1034.36~22.04.2 linux-image-gcp-6.8 6.8.0-1034.36~22.04.2 linux-image-gcp-64k 6.8.0-1034.36~22.04.2 linux-image-gcp-64k-6.8 6.8.0-1034.36~22.04.2 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-7682-5 https://ubuntu.com/security/notices/USN-7682-4 https://ubuntu.com/security/notices/USN-7682-3 https://ubuntu.com/security/notices/USN-7682-2 https://ubuntu.com/security/notices/USN-7682-1 CVE-2025-37797, CVE-2025-38083 Package Information: https://launchpad.net/ubuntu/+source/linux-raspi/6.8.0-1032.36 https://launchpad.net/ubuntu/+source/linux-gcp-6.8/6.8.0-1034.36~22.04.2 . Important updates for Ubuntu 24.04 and 22.04 LTS have been released, addressing multiple significant vulnerabilities that impact system security.. Ubuntu Linux Kernel Update, Security Issues, System Compromise, Network Control, Kernel Flaws. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-12746 http://linux.oracle.com/errata/ELSA-2025-12746.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-abi-stablelists-5.14.0-570.32.1.0.1.el9_6.noarch.rpm kernel-core-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-cross-headers-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-core-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-devel-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-devel-matched-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-modules-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-modules-core-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-modules-extra-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-debug-uki-virt-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-devel-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-devel-matched-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-doc-5.14.0-570.32.1.0.1.el9_6.noarch.rpm kernel-headers-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-modules-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-modules-core-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-modules-extra-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-tools-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-tools-libs-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-tools-libs-devel-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-uki-virt-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm kernel-uki-virt-addons-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm libperf-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm perf-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm python3-perf-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm rtla-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm rv-5.14.0-570.32.1.0.1.el9_6.x86_64.rpm aarch64: kernel-cross-headers-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm kernel-headers-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm kernel-tools-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm kernel-tools-libs-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm kernel-tools-libs-devel-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm perf-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm python3-perf-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm rtla-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm rv-5.14.0-570.32.1.0.1.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/kernel-5.14.0-570.32.1.0.1.el9_6.src.rpm Related CVEs: CVE-2022-49788 CVE-2025-21727 CVE-2025-21928 CVE-2025-21929 CVE-2025-21962 CVE-2025-22020 CVE-2025-37890 CVE-2025-38052 CVE-2025-38087 Description of changes: [5.14.0-570.32.1.0.1.el9_6.OL9] - nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
Multiple vulnerabilities have been discovered in Bluez, the worst of which can lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: BlueZ: Privilege Escalation Date: January 05, 2024 Bugs: #919383 ID: 202401-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Bluez, the worst of which can lead to privilege escalation. Background ========== BlueZ is the canonical bluetooth tools and system daemons package for Linux. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------ net-wireless/bluez < 5.70-r1 > = 5.70-r1 Description =========== Multiple vulnerabilities have been discovered in BlueZ. Please review the CVE identifiers referenced below for details. Impact ====== An attacker may inject unauthenticated keystrokes via Bluetooth, leading to privilege escalation or denial of service. Workaround ========== There is no known workaround at this time. Resolution ========== All BlueZ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/bluez-5.70-r1" References ========== [ 1 ] CVE-2023-45866 https://nvd.nist.gov/vuln/detail/CVE-2023-45866 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202401-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns shouldbe addressed to
The package linux before version 4.17.11-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201808-4 ======================================== Severity: High Date : 2018-08-08 CVE-ID : CVE-2018-5390 Package : linux Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-747 Summary ====== The package linux before version 4.17.11-1 is vulnerable to denial of service. Resolution ========= Upgrade to 4.17.11-1. # pacman -Syu "linux> =4.17.11-1" The problem has been fixed upstream in version 4.17.11. Workaround ========= None. Description ========== A flaw named SegmentSmack was found in the way the Linux kernel handled specially crafted TCP packets. A remote attacker could use this flaw to trigger time and calculation expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() functions by sending specially modified packets within ongoing TCP sessions which could lead to a CPU saturation and hence a denial of service on the system. Maintaining the denial of service condition requires continuous two-way TCP sessions to a reachable open port, thus the attacks cannot be performed using spoofed IP addresses. Impact ===== A remote attacker is able to saturate the CPU and hence cause a denial of service on the host system by sending specially modified packets within ongoing TCP sessions. References ========= https://www.kb.cert.org/vuls/id/962459 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/ https://security.archlinux.org/CVE-2018-5390 . Arch Linux Security Advisory ASA-201808-4 ======================================== Severity: High Da. linux, package, version,vulnerable, denial, service, security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.