Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves 24 vulnerabilities can now be installed.. # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2957-1 Release Date: 2026-07-14T10:19:59Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 (SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.87 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2-> cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t-> net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallbackdevice (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2959=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2958=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2957=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2959=1 SUSE-2026-2958=1 SUSE-2026-2957=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 *https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 . An update for openSUSE addresses 24 significant issues in the Kernel. Immediate installation recommended for stability.. openSUSE Kernel update important issues patch. . Severity: Important. LinuxSecurity.com Team
# Security update for kernel-livepatch-MICRO-6-0_Update_20 Announcement ID: SUSE-SU-2026:21638-1 Release Date: 2026-05-12T09:28:42Z Rating: moderate References:. # Security update for kernel-livepatch-MICRO-6-0_Update_20 Announcement ID: SUSE-SU-2026:21638-1 Release Date: 2026-05-12T09:28:42Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: New Livepatch SLE Micro 6.0/6.1 kernel update 20 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-399=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-1-1.1 * kernel-livepatch-6_4_0-43-default-1-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-1-1.1 . Moderate security update for SUSE kernel-livepatch-MICRO-6-0_Update_20 to enhance system stability.. SUSE Linux Micro security update, kernel livepatch issues, system patch management. . LinuxSecurity.com Team
An update that solves 7 vulnerabilities can now be installed.. # trivy-0.70.0-1.1 on GA media Announcement ID: openSUSE-SU-2026:10651-1 Rating: moderate Cross-References: * CVE-2025-69725 * CVE-2026-25934 * CVE-2026-33186 * CVE-2026-33747 * CVE-2026-33748 * CVE-2026-34986 * CVE-2026-39984 CVSS scores: * CVE-2025-69725 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-69725 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N * CVE-2026-25934 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25934 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33747 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33747 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-33748 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33748 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves 7 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the trivy-0.70.0-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * trivy 0.70.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69725.html * https://www.suse.com/security/cve/CVE-2026-25934.html * https://www.suse.com/security/cve/CVE-2026-33186.html *https://www.suse.com/security/cve/CVE-2026-33747.html * https://www.suse.com/security/cve/CVE-2026-33748.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39984.html . An essential update for openSUSE addressing 7 key vulnerabilities in Trivy, rated as moderate severity. Update promptly.. openSUSE vulnerabilities trivy security advisory. . LinuxSecurity.com Team
An update that contains two features and has 10 fixes can now be installed.. # Security update for kernel-livepatch-MICRO-6-0-RT_Update_19 Announcement ID: SUSE-SU-2026:21265-1 Release Date: 2026-04-17T15:23:06Z Rating: moderate References: * bsc#1103203 * bsc#1149841 * bsc#1196281 * bsc#1244337 * bsc#1248108 * bsc#904970 * bsc#907150 * bsc#920615 * bsc#920633 * bsc#930408 * jsc#PED-14811 * jsc#PED-7906 Affected Products: * SUSE Linux Micro 6.1 An update that contains two features and has 10 fixes can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_19 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 19 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-343=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-1-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-1-1.1 * kernel-livepatch-6_4_0-41-rt-1-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1103203 * https://bugzilla.suse.com/show_bug.cgi?id=1149841 * https://bugzilla.suse.com/show_bug.cgi?id=1196281 * https://bugzilla.suse.com/show_bug.cgi?id=1244337 * https://bugzilla.suse.com/show_bug.cgi?id=1248108 * https://bugzilla.suse.com/show_bug.cgi?id=904970 * https://bugzilla.suse.com/show_bug.cgi?id=907150 * https://bugzilla.suse.com/show_bug.cgi?id=920615 * https://bugzilla.suse.com/show_bug.cgi?id=920633 * https://bugzilla.suse.com/show_bug.cgi?id=930408 * https://jira.suse.com/browse/PED-14811 * https://jira.suse.com/browse/PED-7906 . Update contains two features and ten important fixes for SUSE Linux Micro 6.1 kernel-livepatch.. SUSE Livepatch, Kernel Update, Linux Micro, System Patching. .LinuxSecurity.com Team
* bsc#1203397 * bsc#1203399 * bsc#1206798 * bsc#1215943 * bsc#1217580 . # Security update for busybox, busybox-links Announcement ID: SUSE-SU-2025:03205-1 Release Date: 2025-09-12T15:57:35Z Rating: moderate References: * bsc#1203397 * bsc#1203399 * bsc#1206798 * bsc#1215943 * bsc#1217580 * bsc#1217584 * bsc#1217585 * bsc#1217883 * bsc#1243201 * jsc#PED-13039 * jsc#SLE-24210 * jsc#SLE-24211 Cross-References: * CVE-2023-42363 * CVE-2023-42364 * CVE-2023-42365 CVSS scores: * CVE-2023-42363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42364 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2023-42364 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42364 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42364 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities, contains three features and has six security fixes can now be installed. ## Description: This update for busybox, busybox-links fixes the following issues: Updated to version 1.37.0 (jsc#PED-13039): \- CVE-2023-42363: Fixed use-after- free vulnerability in xasprintf function in xfuncs_printf.c (bsc#1217580) \- CVE-2023-42364: Fixed use-after-free in the awk.c evaluate function (bsc#1217584) \- CVE-2023-42365: Fixed use-after-free in the awk.c copyvar function (bsc#1217585) Other fixes: \- fix generation of file lists via Dockerfile \- add copy of busybox.links from thecontainer to catch changes to busybox config \- Blacklist creating links for halt, reboot, shutdown commands to avoid accidental use in a fully booted system (bsc#1243201) \- Add getfattr applet to attr filelist \- busybox-udhcpc conflicts with udhcp. \- Add new sub-package for udhcpc \- zgrep: don't set the label option as only the real grep supports it (bsc#1215943) \- Add conflict for coreutils-systemd, package got splitted \- Check in filelists instead of buildrequiring all non-busybox utils \- Replace transitional %usrmerged macro with regular version check (bsc#1206798) \- Create sub-package "hexedit" [bsc#1203399] \- Create sub-package "sha3sum" [bsc#1203397] \- Drop update-alternatives support \- Add provides smtp_daemon to busybox-sendmail \- Add conflicts: mawk to busybox-gawk \- fix mkdir path to point to /usr/bin instead of /bin \- add placeholder variable and ignore applet logic to busybox.install \- enable halt, poweroff, reboot commands (bsc#1243201) \- Fully enable udhcpc and document that this tool needs special configuration and does not work out of the box [bsc#1217883] \- Replace transitional %usrmerged macro with regular version check (bsc#1206798) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-3205=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * busybox-static-1.37.0-150700.18.4.1 * busybox-1.37.0-150700.18.4.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42363.html * https://www.suse.com/security/cve/CVE-2023-42364.html * https://www.suse.com/security/cve/CVE-2023-42365.html * https://bugzilla.suse.com/show_bug.cgi?id=1203397 * https://bugzilla.suse.com/show_bug.cgi?id=1203399 * https://bugzilla.suse.com/show_bug.cgi?id=1206798 *https://bugzilla.suse.com/show_bug.cgi?id=1215943 * https://bugzilla.suse.com/show_bug.cgi?id=1217580 * https://bugzilla.suse.com/show_bug.cgi?id=1217584 * https://bugzilla.suse.com/show_bug.cgi?id=1217585 * https://bugzilla.suse.com/show_bug.cgi?id=1217883 * https://bugzilla.suse.com/show_bug.cgi?id=1243201 * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FPED-13039&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FSLE-24210&page_caps=&user_role= * https://jira.suse.com/login.jsp?permissionViolation=true&os_destination=%2Fbrowse%2FSLE-24211&page_caps=&user_role= . This advisory outlines the latest update from SUSE for busybox, tackling moderate concerns and essential corrections for maintaining system security.. busybox update,SUSE security advisory,system patching. . LinuxSecurity.com Team
* bsc#1244925 Cross-References: * CVE-2025-50181 . # Security update for python-urllib3 Announcement ID: SUSE-SU-2025:02985-1 Release Date: 2025-08-25T13:55:30Z Rating: moderate References: * bsc#1244925 Cross-References: * CVE-2025-50181 CVSS scores: * CVE-2025-50181 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-50181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-50181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-urllib3 fixes the following issues: * CVE-2025-50181: Pool managers now properly control redirects when retries is passed. (bsc#1244925) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-2985=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-2985=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patchSUSE-SLE-Micro-5.3-2025-2985=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2985=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-2985=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-2985=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2985=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2025-2985=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2025-2985=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2985=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-2985=1 ## Package List: * openSUSE Leap 15.3 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * Basesystem Module 15-SP6 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * Basesystem Module 15-SP7 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro 5.1 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro 5.2 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (noarch) * python3-urllib3-1.25.10-150300.4.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-50181.html * https://bugzilla.suse.com/show_bug.cgi?id=1244925 . SUSE patches for Python-urllib3 tackle linked CVE-2025-50182 with moderate risk,fortifying system integrity.. SUSE Python Urllib3 Security Update, Python Urllib3 Patch, SUSE CVE-2025-50181. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-8669 http://linux.oracle.com/errata/ELSA-2025-8669.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable LinuxNetwork: x86_64: kernel-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-abi-stablelists-6.12.0-55.19.1.0.1.el10_0.noarch.rpm kernel-core-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-cross-headers-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-core-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-devel-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-devel-matched-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-core-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-modules-extra-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-debug-uki-virt-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-devel-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-devel-matched-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-doc-6.12.0-55.19.1.0.1.el10_0.noarch.rpm kernel-headers-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-modules-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-modules-core-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-modules-extra-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-tools-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-tools-libs-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-tools-libs-devel-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-uki-virt-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm kernel-uki-virt-addons-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm libperf-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm perf-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm python3-perf-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm rtla-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm rv-6.12.0-55.19.1.0.1.el10_0.x86_64.rpm aarch64: kernel-cross-headers-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm kernel-headers-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm kernel-tools-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm kernel-tools-libs-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm kernel-tools-libs-devel-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm libperf-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm perf-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm python3-perf-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm rtla-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm rv-6.12.0-55.19.1.0.1.el10_0.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/kernel-6.12.0-55.19.1.0.1.el10_0.src.rpm Related CVEs: CVE-2025-21669 CVE-2025-21926 CVE-2025-21997 CVE-2025-22055 CVE-2025-37943 Description of changes: [6.12.0-55.19.1.0.1.el10_0.OL10] - nvme-pci: remove two deallocate zeroes quirks [Orabug: 37756650] - Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985782] - Disable UKI signing [Orabug: 36571828] - Update Oracle Linux certificates (Kevin Lyons) - Disable signing for aarch64 (Ilya Okomin) - Oracle Linux RHCK Module Signing Key was added to the kernel trusted keys list (olkmod_signing_key.pem) [Orabug: 29539237] - Update x509.genkey [Orabug: 24817676] - Conflict with shim-ia32 and shim-x64
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-20323 http://linux.oracle.com/errata/ELSA-2025-20323.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: bpftool-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-core-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-debug-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-debug-core-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-debug-devel-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-debug-modules-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-debug-modules-extra-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-devel-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-doc-5.15.0-308.179.6.2.el9uek.noarch.rpm kernel-uek-modules-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-modules-extra-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-container-5.15.0-308.179.6.2.el9uek.x86_64.rpm kernel-uek-container-debug-5.15.0-308.179.6.2.el9uek.x86_64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//kernel-uek-5.15.0-308.179.6.2.el9uek.src.rpm Related CVEs: CVE-2024-28956 Description of changes: [5.15.0-308.179.6.2.el9uek] - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (Pawan Gupta) [Orabug: 37920681] - x86/bpf: Add IBHF call at end of classic BPF (Daniel Sneddon) [Orabug: 37920681] - x86/bpf: Call branch history clearing sequence on exit (Daniel Sneddon) [Orabug: 37920681] - selftest/x86/bugs: Add selftests for ITS (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Align RETs in BHB clear sequence to avoid thunking (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Add "vmexit" option to skip mitigation on some CPUs (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Enable Indirect Target Selection mitigation (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Add support for ITS-safe return thunk (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Add support for ITS-safe indirect thunk (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/its: Enumerate Indirect Target Selection (ITS) bug (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - Documentation: x86/bugs/its: Add ITS documentation (Pawan Gupta) [Orabug: 37863726] {CVE-2024-28956} - x86/alternatives: Remove faulty optimization (Josh Poimboeuf) [Orabug: 37863726] {CVE-2024-28956} - x86/alternative: Optimize returns patching (Borislav Petkov (AMD)) [Orabug: 37863726] {CVE-2024-28956} _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.