Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in the Linux kernel.. ========================================================================== Ubuntu Security Notice USN-8291-2 May 22, 2026 linux-lowlatency-hwe-5.15 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux-lowlatency-hwe-5.15: Linux low latency kernel Details: Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SMB network file system; - Netfilter; - io_uring subsystem; (CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS linux-image-5.15.0-178-lowlatency 5.15.0-178.188~20.04.1 Available with Ubuntu Pro linux-image-5.15.0-178-lowlatency-64k 5.15.0-178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-5.15 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-5.15 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-64k-hwe-20.04 5.15.0.178.188~20.04.1 Available with Ubuntu Pro linux-image-lowlatency-hwe-20.04 5.15.0.178.188~20.04.1 Available with Ubuntu Pro After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless youmanually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-8291-2 https://ubuntu.com/security/notices/USN-8291-1 CVE-2024-35862, CVE-2024-50060, CVE-2026-23274, CVE-2026-23351 . Security update for Ubuntu 20.04 LTS addressing multiple Linux kernel flaws, requiring system reboot and module recompilation.. Linux Kernel Update, Ubuntu 20.04, Low Latency Kernel, Security Issues. . Severity: Low. LinuxSecurity.com Team
An update that solves seven vulnerabilities can now be installed.. # Security update for strongswan Announcement ID: SUSE-SU-2026:1637-1 Release Date: 2026-04-27T16:59:38Z Rating: important References: * bsc#1261705 * bsc#1261706 * bsc#1261708 * bsc#1261712 * bsc#1261717 * bsc#1261718 * bsc#1261720 Cross-References: * CVE-2026-35328 * CVE-2026-35329 * CVE-2026-35330 * CVE-2026-35331 * CVE-2026-35332 * CVE-2026-35333 * CVE-2026-35334 CVSS scores: * CVE-2026-35328 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35328 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35329 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35329 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35330 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-35330 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-35331 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35331 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-35332 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35332 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35333 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35333 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35334 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35334 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise WorkstationExtension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-35328: infinite loop when handling supported versions TLS extension (bsc#1261712). * CVE-2026-35329: null pointer dereference when processing padding in PKCS#7 (bsc#1261717). * CVE-2026-35330: integer underflow when handling EAP-SIM/AKA attributes (bsc#1261705). * CVE-2026-35331: accepting certificates violating name constraints (bsc#1261718). * CVE-2026-35332: null pointer dereference when handling ECDH public value in TLS (bsc#1261708). * CVE-2026-35333: integer underflow when handling RADIUS attributes (bsc#1261706). * CVE-2026-35334: possible null pointer dereference in RSA decryption (bsc#1261720). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1637=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1637=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-1637=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-libs0-5.9.14-150700.3.14.1 * strongswan-ipsec-debuginfo-5.9.14-150700.3.14.1 * strongswan-libs0-debuginfo-5.9.14-150700.3.14.1 * strongswan-hmac-5.9.14-150700.3.14.1 * strongswan-ipsec-5.9.14-150700.3.14.1 * strongswan-5.9.14-150700.3.14.1 * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * Basesystem Module 15-SP7 (noarch) * strongswan-doc-5.9.14-150700.3.14.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-nm-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * strongswan-nm-debuginfo-5.9.14-150700.3.14.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * strongswan-debuginfo-5.9.14-150700.3.14.1 * strongswan-nm-5.9.14-150700.3.14.1 * strongswan-debugsource-5.9.14-150700.3.14.1 * strongswan-nm-debuginfo-5.9.14-150700.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35328.html * https://www.suse.com/security/cve/CVE-2026-35329.html * https://www.suse.com/security/cve/CVE-2026-35330.html * https://www.suse.com/security/cve/CVE-2026-35331.html * https://www.suse.com/security/cve/CVE-2026-35332.html * https://www.suse.com/security/cve/CVE-2026-35333.html * https://www.suse.com/security/cve/CVE-2026-35334.html * https://bugzilla.suse.com/show_bug.cgi?id=1261705 * https://bugzilla.suse.com/show_bug.cgi?id=1261706 * https://bugzilla.suse.com/show_bug.cgi?id=1261708 * https://bugzilla.suse.com/show_bug.cgi?id=1261712 * https://bugzilla.suse.com/show_bug.cgi?id=1261717 * https://bugzilla.suse.com/show_bug.cgi?id=1261718 * https://bugzilla.suse.com/show_bug.cgi?id=1261720 . SUSE updates strongswan resolving multiple important security issues related to TLS handling and certificate validation.. strongswan security patch, SUSE update vulnerabilities, Linux strongswan fix. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities and has one fix can now be installed.. # Security update for glibc Announcement ID: SUSE-SU-2026:21019-1 Release Date: 2026-04-10T06:18:59Z Rating: important References: * bsc#1258319 * bsc#1260078 * bsc#1260082 Cross-References: * CVE-2026-4437 * CVE-2026-4438 CVSS scores: * CVE-2026-4437 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4437 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-4437 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4438 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4438 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-4438 ( NVD ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for glibc fixes the following issues: Security fixes: * CVE-2026-4437: incorrect DNS response parsing via crafted DNS server response (bsc#1260078). * CVE-2026-4438: invalid DNS hostname returned via gethostbyaddr functions (bsc#1260082). Other fixes: * nss: Missing checks in __nss_configure_lookup, __nss_database_get (bsc#1258319). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-516=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * glibc-locale-base-2.40-160000.4.1 * glibc-devel-debuginfo-2.40-160000.4.1 * glibc-devel-2.40-160000.4.1 * glibc-locale-2.40-160000.4.1 * glibc-debuginfo-2.40-160000.4.1 * glibc-2.40-160000.4.1 * glibc-debugsource-2.40-160000.4.1 * SUSE Linux Micro 6.2 (aarch64 x86_64) *glibc-gconv-modules-extra-2.40-160000.4.1 * glibc-gconv-modules-extra-debuginfo-2.40-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4437.html * https://www.suse.com/security/cve/CVE-2026-4438.html * https://bugzilla.suse.com/show_bug.cgi?id=1258319 * https://bugzilla.suse.com/show_bug.cgi?id=1260078 * https://bugzilla.suse.com/show_bug.cgi?id=1260082 . Critical update for SUSE glibc fixes DNS response parsing issues addressed with important ratings.. SUSE Linux, glibc update, system vulnerabilities, software patching, security flaws. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # himmelblau-2.3.8+git0.dec3693-1.1 on GA media Announcement ID: openSUSE-SU-2026:10328-1 Rating: moderate Cross-References: * CVE-2026-31979 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the himmelblau-2.3.8+git0.dec3693-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * himmelblau 2.3.8+git0.dec3693-1.1 * himmelblau-qr-greeter 2.3.8+git0.dec3693-1.1 * himmelblau-sshd-config 2.3.8+git0.dec3693-1.1 * himmelblau-sso 2.3.8+git0.dec3693-1.1 * libnss_himmelblau2 2.3.8+git0.dec3693-1.1 * pam-himmelblau 2.3.8+git0.dec3693-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31979.html . Upgrade himmelblau on openSUSE Tumbleweed to fix moderate security issues and enhance system safety.. openSUSE Tumbleweed, himmelblau update, security fix, moderate risks, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:20506-1 Release Date: 2026-02-19T09:17:44Z Rating: important References: * bsc#1253439 * bsc#1253473 Cross-References: * CVE-2025-40129 * CVE-2025-40186 CVSS scores: * CVE-2025-40129 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40129 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40186 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-40186 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2025-40129: sunrpc: fix null pointer dereference on zero-length checksum (bsc#1253473). * CVE-2025-40186: tcp: Don't call reqsk_fastopen_remove() in tcp_conn_request() (bsc#1253439). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-277=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-5-1.1 * kernel-livepatch-6_4_0-34-default-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40129.html * https://www.suse.com/security/cve/CVE-2025-40186.html * https://bugzilla.suse.com/show_bug.cgi?id=1253439 * https://bugzilla.suse.com/show_bug.cgi?id=1253473 . A critical SUSE update addresses important security issues in the kernelfor SUSE Linux Enterprise Micro 6.0.. SUSE Linux, Kernel Security, Live Patch, Security Update. . Severity: Important. LinuxSecurity.com Team
* bsc#1242882 * bsc#1245778 * bsc#1248672 * bsc#1249537 . # Security update for kernel-livepatch-MICRO-6-0_Update_4 Announcement ID: SUSE-SU-2025:21093-1 Release Date: 2025-11-28T08:19:30Z Rating: important References: * bsc#1242882 * bsc#1245778 * bsc#1248672 * bsc#1249537 Cross-References: * CVE-2024-53141 * CVE-2025-23145 * CVE-2025-38500 * CVE-2025-38616 CVSS scores: * CVE-2024-53141 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-53141 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-53141 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-23145 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23145 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38616 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2025-38616 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_4 fixes the following issues: * CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882) * CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1245778) * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672) * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537) ## Patch Instructions: To install this SUSE update use the SUSE recommendedinstallation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-219=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-24-default-14-1.2 * kernel-livepatch-6_4_0-24-default-debuginfo-14-1.2 * kernel-livepatch-MICRO-6-0_Update_4-debugsource-14-1.2 ## References: * https://www.suse.com/security/cve/CVE-2024-53141.html * https://www.suse.com/security/cve/CVE-2025-23145.html * https://www.suse.com/security/cve/CVE-2025-38500.html * https://www.suse.com/security/cve/CVE-2025-38616.html * https://bugzilla.suse.com/show_bug.cgi?id=1242882 * https://bugzilla.suse.com/show_bug.cgi?id=1245778 * https://bugzilla.suse.com/show_bug.cgi?id=1248672 * https://bugzilla.suse.com/show_bug.cgi?id=1249537 . This advisory outlines important updates for SUSE Linux Micro addressing critical issues such as remote access vulnerabilities.. SUSE Linux Micro, kernel livepatch, security update, important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
* bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References: . # Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP6) Announcement ID: SUSE-SU-2025:3932-1 Release Date: 2025-11-04T09:04:27Z Rating: important References: * bsc#1248631 * bsc#1249207 * bsc#1249208 Cross-References: * CVE-2025-38617 * CVE-2025-38618 * CVE-2025-38664 CVSS scores: * CVE-2025-38617 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38617 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38618 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38618 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38664 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38664 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_53 fixes several issues. The following security issues were fixed: * CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631). * CVE-2025-38617: net/packet: fix a race in packet_set_ring() and packet_notifier() (bsc#1249208). * CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-3928=1SUSE-SLE- Module-Live-Patching-15-SP6-2025-3932=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3932=1 SUSE-2025-3928=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_10-debugsource-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-9-150600.4.1 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-debuginfo-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-8-150600.4.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_10-debugsource-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-9-150600.4.1 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_47-default-debuginfo-9-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-8-150600.4.1 * kernel-livepatch-6_4_0-150600_23_53-default-8-150600.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-38617.html * https://www.suse.com/security/cve/CVE-2025-38618.html * https://www.suse.com/security/cve/CVE-2025-38664.html * https://bugzilla.suse.com/show_bug.cgi?id=1248631 * https://bugzilla.suse.com/show_bug.cgi?id=1249207 * https://bugzilla.suse.com/show_bug.cgi?id=1249208 . Critical security patch for SUSE's Linux Kernel addresses important vulnerabilities and updates for key systems.. Linux Kernel,Patching,SUSE Security,Importance of Updates,Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
* bsc#1245685 * bsc#1245795 * bsc#1246001 * bsc#1246356 * bsc#1247499 . # Security update for kernel-livepatch-MICRO-6-0-RT_Update_3 Announcement ID: SUSE-SU-2025:20737-1 Release Date: 2025-09-23T07:56:26Z Rating: important References: * bsc#1245685 * bsc#1245795 * bsc#1246001 * bsc#1246356 * bsc#1247499 * bsc#1248298 Cross-References: * CVE-2025-21756 * CVE-2025-38109 * CVE-2025-38177 * CVE-2025-38181 * CVE-2025-38498 * CVE-2025-38555 CVSS scores: * CVE-2025-21756 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-21756 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38109 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38109 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38177 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38177 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38181 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38181 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38498 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38498 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-38555 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-38555 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_3 fixes the following issues: * CVE-2025-38177: kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1246356) * CVE-2025-38109: net/mlx5: fix ECVF vports unload on shutdown flow (bsc#1245685) * CVE-2025-38181: calipso: fix null-ptr-deref in calipso_req_{set,del}attr() (bsc#1246001) * CVE-2025-21756: vsock: Keep the binding until socket destruction (bsc#1245795) * CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours mounts (bsc#1247499) * CVE-2025-38555: usb: gadget : fix use-after-free in composite_dev_cleanup() (bsc#1248298) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-122=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-11-rt-12-1.2 * kernel-livepatch-6_4_0-11-rt-debuginfo-12-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_3-debugsource-12-1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-21756.html * https://www.suse.com/security/cve/CVE-2025-38109.html * https://www.suse.com/security/cve/CVE-2025-38177.html * https://www.suse.com/security/cve/CVE-2025-38181.html * https://www.suse.com/security/cve/CVE-2025-38498.html * https://www.suse.com/security/cve/CVE-2025-38555.html * https://bugzilla.suse.com/show_bug.cgi?id=1245685 * https://bugzilla.suse.com/show_bug.cgi?id=1245795 * https://bugzilla.suse.com/show_bug.cgi?id=1246001 * https://bugzilla.suse.com/show_bug.cgi?id=1246356 * https://bugzilla.suse.com/show_bug.cgi?id=1247499 * https://bugzilla.suse.com/show_bug.cgi?id=1248298 . Kernel-livepatch-MICRO update resolves important issues in SUSE Linux Micro 6.0, enhancing system security.. SUSE Linux Micro 6.0, kernel livepatch, important security fixes, Linux updates. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.