Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
172

Ubuntu 20.04 Low Latency Kernel Low Security Issues USN-8291-2

Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8291-2 May 22, 2026 linux-lowlatency-hwe-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-lowlatency-hwe-5.15: Linux low latency kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SMB network file system; - Netfilter; - io_uring subsystem; (CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-178-lowlatency 5.15.0-178.188~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-178-lowlatency-64k 5.15.0-178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-5.15 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-5.15 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-hwe-20.04 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-20.04 5.15.0.178.188~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless youmanually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8291-2 https://ubuntu.com/security/notices/USN-8291-1 CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351 . Security update for Ubuntu 20.04 LTS addressing multiple Linux kernel flaws, requiring system reboot and module recompilation.. Linux Kernel Update, Ubuntu 20.04, Low Latency Kernel, Security Issues. . Severity: Low. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Low Ubuntu
100

SUSE StrongSwan Important Security Issues Resolved 2026-1637-1

An update that solves seven vulnerabilities can now be installed.. # Security update for strongswan Announcement ID: SUSE-SU-2026:1637-1 Release Date: 2026-04-27T16:59:38Z Rating: important References: * bsc#1261705 * bsc#1261706 * bsc#1261708 * bsc#1261712 * bsc#1261717 * bsc#1261718 * bsc#1261720 Cross-References: * CVE-2026-35328 * CVE-2026-35329 * CVE-2026-35330 * CVE-2026-35331 * CVE-2026-35332 * CVE-2026-35333 * CVE-2026-35334 CVSS scores: * CVE-2026-35328 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35328 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35329 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35329 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35330 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-35330 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35331 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35331 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-35332 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35332 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35333 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35333 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35334 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35334 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise WorkstationExtension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-35328: infinite loop when handling supported versions TLS extension (bsc#1261712). * CVE-2026-35329: null pointer dereference when processing padding in PKCS#7 (bsc#1261717). * CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes (bsc#1261705). * CVE-2026-35331: accepting certificates violating name constraints (bsc#1261718). * CVE-2026-35332: null pointer dereference when handling ECDH public value in TLS (bsc#1261708). * CVE-2026-35333: integer underflow when handling RADIUS attributes (bsc#1261706). * CVE-2026-35334: possible null pointer dereference in RSA decryption (bsc#1261720). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1637=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1637=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1637=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-libs0-5.9.14-150700.3.14.1 * strongswan-ipsec-debuginfo-5.9.14-150700.3.14.1 * strongswan-libs0-debuginfo-5.9.14-150700.3.14.1 * strongswan-hmac-5.9.14-150700.3.14.1 * strongswan-ipsec-5.9.14-150700.3.14.1 * strongswan-5.9.14-150700.3.14.1 * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * Basesystem Module 15-SP7 (noarch) * strongswan-doc-5.9.14-150700.3.14.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-nm-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * strongswan-nm-debuginfo-5.9.14-150700.3.14.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-nm-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * strongswan-nm-debuginfo-5.9.14-150700.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35328.html * https://www.suse.com/security/cve/CVE-2026-35329.html * https://www.suse.com/security/cve/CVE-2026-35330.html * https://www.suse.com/security/cve/CVE-2026-35331.html * https://www.suse.com/security/cve/CVE-2026-35332.html * https://www.suse.com/security/cve/CVE-2026-35333.html * https://www.suse.com/security/cve/CVE-2026-35334.html * https://bugzilla.suse.com/show_bug.cgi?id=1261705 * https://bugzilla.suse.com/show_bug.cgi?id=1261706 * https://bugzilla.suse.com/show_bug.cgi?id=1261708 * https://bugzilla.suse.com/show_bug.cgi?id=1261712 * https://bugzilla.suse.com/show_bug.cgi?id=1261717 * https://bugzilla.suse.com/show_bug.cgi?id=1261718 * https://bugzilla.suse.com/show_bug.cgi?id=1261720 . SUSE updates strongswan resolving multiple important security issues related to TLS handling and certificate validation.. strongswan security patch, SUSE update vulnerabilities, Linux strongswan fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 28, 2026 Important SuSE
100

SUSE glibc Important Security Update 21019-1 Addresses DNS Issues

An update that solves two vulnerabilities and has one fix can now be installed.. # Security update for glibc Announcement ID: SUSE-SU-2026:21019-1 Release Date: 2026-04-10T06:18:59Z Rating: important References: * bsc#1258319 * bsc#1260078 * bsc#1260082 Cross-References: * CVE-2026-4437 * CVE-2026-4438 CVSS scores: * CVE-2026-4437 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4437 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-4437 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4438 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4438 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-4438 ( NVD ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for glibc fixes the following issues: Security fixes: * CVE-2026-4437: incorrect DNS response parsing via crafted DNS server response (bsc#1260078). * CVE-2026-4438: invalid DNS hostname returned via gethostbyaddr functions (bsc#1260082). Other fixes: * nss: Missing checks in __nss_configure_lookup, __nss_database_get (bsc#1258319). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-516=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * glibc-locale-base-2.40-160000.4.1 * glibc-devel-debuginfo-2.40-160000.4.1 * glibc-devel-2.40-160000.4.1 * glibc-locale-2.40-160000.4.1 * glibc-debuginfo-2.40-160000.4.1 * glibc-2.40-160000.4.1 * glibc-debugsource-2.40-160000.4.1 * SUSE Linux Micro 6.2 (aarch64 x86_64) *glibc-gconv-modules-extra-2.40-160000.4.1 * glibc-gconv-modules-extra-debuginfo-2.40-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4437.html * https://www.suse.com/security/cve/CVE-2026-4438.html * https://bugzilla.suse.com/show_bug.cgi?id=1258319 * https://bugzilla.suse.com/show_bug.cgi?id=1260078 * https://bugzilla.suse.com/show_bug.cgi?id=1260082 . Critical update for SUSE glibc fixes DNS response parsing issues addressed with important ratings.. SUSE Linux, glibc update, system vulnerabilities, software patching, security flaws. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Important SuSE
202

openSUSE Tumbleweed Security Advisory openSUSE-CT-2026-30467-5 Quantum

An update that solves one vulnerability can now be installed.. # himmelblau-2.3.8+git0.dec3693-1.1 on GA media Announcement ID: openSUSE-SU-2026:10328-1 Rating: moderate Cross-References: * CVE-2026-31979 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the himmelblau-2.3.8+git0.dec3693-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * himmelblau 2.3.8+git0.dec3693-1.1 * himmelblau-qr-greeter 2.3.8+git0.dec3693-1.1 * himmelblau-sshd-config 2.3.8+git0.dec3693-1.1 * himmelblau-sso 2.3.8+git0.dec3693-1.1 * libnss_himmelblau2 2.3.8+git0.dec3693-1.1 * pam-himmelblau 2.3.8+git0.dec3693-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31979.html . Upgrade himmelblau on openSUSE Tumbleweed to fix moderate security issues and enhance system safety.. openSUSE Tumbleweed, himmelblau update, security fix, moderate risks, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2026 Important OpenSUSE
100

SUSE Linux Micro 6.0 Kernel Important Security Patch 20506-1

An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20506-1 Release Date: 2026-02-19T09:17:44Z Rating: important References: * bsc#1253439 * bsc#1253473 Cross-References: * CVE-2025-40129 * CVE-2025-40186 CVSS scores: * CVE-2025-40129 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40129 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40186 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40186 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-40129: sunrpc: fix null pointer dereference on zero-length checksum (bsc#1253473). * CVE-2025-40186: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request() (bsc#1253439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-277=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-5-1.1 * kernel-livepatch-6_4_0-34-default-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40129.html * https://www.suse.com/security/cve/CVE-2025-40186.html * https://bugzilla.suse.com/show_bug.cgi?id=1253439 * https://bugzilla.suse.com/show_bug.cgi?id=1253473 . A critical SUSE update addresses important security issues in the kernelfor SUSE Linux Enterprise Micro 6.0.. SUSE Linux, Kernel Security, Live Patch, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 27, 2026 Important SuSE
100

SUSE: Kernel-Livepatch-MICRO Important Issues Advisory 2025:21093-1

* bsc#1242882 * bsc#1245778 * bsc#1248672 * bsc#1249537 . # Security update for kernel-livepatch-MICRO-6-0_Update_4 Announcement ID: SUSE-SU-2025:21093-1 Release Date: 2025-11-28T08:19:30Z Rating: important References: * bsc#1242882 * bsc#1245778 * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2024-53141 * CVE-2025-23145 * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2024-53141 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53141 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53141 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-23145 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_4 fixes the following issues: * CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882) * CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1245778) * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommendedinstallation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-219=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-24-default-14-1.2 * kernel-livepatch-6_4_0-24-default-debuginfo-14-1.2 * kernel-livepatch-MICRO-6-0_Update_4-debugsource-14-1.2 ## References: * https://www.suse.com/security/cve/CVE-2024-53141.html * https://www.suse.com/security/cve/CVE-2025-23145.html * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1242882 * https://bugzilla.suse.com/show_bug.cgi?id=1245778 * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . This advisory outlines important updates for SUSE Linux Micro addressing critical issues such as remote access vulnerabilities.. SUSE Linux Micro, kernel livepatch, security update, important vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 09, 2025 Important SuSE
100

SUSE: Kernel Important VMADDR_PORT Binding Fix Advisory 2025:3932-1

* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References: . # Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:3932-1 Release Date: 2025-11-04T09:04:27Z Rating: important References: * bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References: * CVE-2025-38617 * CVE-2025-38618 * CVE-2025-38664 CVSS scores: * CVE-2025-38617 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38617 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38618 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38618 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_53 fixes several issues. The following security issues were fixed: * CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631). * CVE-2025-38617: net/packet: fix a race in packet_set_ring() and packet_notifier() (bsc#1249208). * CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-3928=1SUSE-SLE- Module-Live-Patching-15-SP6-2025-3932=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3932=1 SUSE-2025-3928=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_10-debugsource-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-9-150600.4.1 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-debuginfo-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-8-150600.4.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_10-debugsource-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-9-150600.4.1 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-debuginfo-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-8-150600.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38617.html * https://www.suse.com/security/cve/CVE-2025-38618.html * https://www.suse.com/security/cve/CVE-2025-38664.html * https://bugzilla.suse.com/show_bug.cgi?id=1248631 * https://bugzilla.suse.com/show_bug.cgi?id=1249207 * https://bugzilla.suse.com/show_bug.cgi?id=1249208 . Critical security patch for SUSE's Linux Kernel addresses important vulnerabilities and updates for key systems.. Linux Kernel,Patching,SUSE Security,Importance of Updates,Vulnerability Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 04, 2025 Important SuSE
100

SUSE: kernel-livepatch-MICRO Security Fixes CVE-2025-21756 DoS Threat

* bsc#1245685 * bsc#1245795 * bsc#1246001 * bsc#1246356 * bsc#1247499 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_3 Announcement ID: SUSE-SU-2025:20737-1 Release Date: 2025-09-23T07:56:26Z Rating: important References: * bsc#1245685 * bsc#1245795 * bsc#1246001 * bsc#1246356 * bsc#1247499 * bsc#1248298 Cross-References: * CVE-2025-21756 * CVE-2025-38109 * CVE-2025-38177 * CVE-2025-38181 * CVE-2025-38498 * CVE-2025-38555 CVSS scores: * CVE-2025-21756 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21756 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38109 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38109 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38177 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38177 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38181 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38181 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38498 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38498 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38555 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38555 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_3 fixes the following issues: * CVE-2025-38177: kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1246356) * CVE-2025-38109: net/mlx5: fix ECVF vports unload on shutdown flow (bsc#1245685) * CVE-2025-38181: calipso: fix null-ptr-deref in calipso_req_{set,del}attr() (bsc#1246001) * CVE-2025-21756: vsock: Keep the binding until socket destruction (bsc#1245795) * CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours mounts (bsc#1247499) * CVE-2025-38555: usb: gadget : fix use-after-free in composite_dev_cleanup() (bsc#1248298) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-122=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-11-rt-12-1.2 * kernel-livepatch-6_4_0-11-rt-debuginfo-12-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_3-debugsource-12-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-21756.html * https://www.suse.com/security/cve/CVE-2025-38109.html * https://www.suse.com/security/cve/CVE-2025-38177.html * https://www.suse.com/security/cve/CVE-2025-38181.html * https://www.suse.com/security/cve/CVE-2025-38498.html * https://www.suse.com/security/cve/CVE-2025-38555.html * https://bugzilla.suse.com/show_bug.cgi?id=1245685 * https://bugzilla.suse.com/show_bug.cgi?id=1245795 * https://bugzilla.suse.com/show_bug.cgi?id=1246001 * https://bugzilla.suse.com/show_bug.cgi?id=1246356 * https://bugzilla.suse.com/show_bug.cgi?id=1247499 * https://bugzilla.suse.com/show_bug.cgi?id=1248298 . Kernel-livepatch-MICRO update resolves important issues in SUSE Linux Micro 6.0, enhancing system security.. SUSE Linux Micro 6.0, kernel livepatch, important security fixes, Linux updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 26, 2025 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200