SUSE-SU-2025:02849-1

Advisory lineage Upstream: 28 Downstream: 0
Published: 18 Aug 2025, 15:57
Last modified:04 Feb 2026, 02:41

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Aug 2025, 15:57
Published
Vulnerability first disclosed
04 Feb 2026, 02:41
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49138: Bluetooth: hci_event: Fix checking conn for le_conn_complete_evt (bsc#1238160). - CVE-2023-52923: netfilter: nf_tables: split async and sync catchall in two functions (bsc#1236104). - CVE-2023-52927: netfilter: allow exp not to be removed in nf_ct_find_expectation (bsc#1239644). - CVE-2023-53117: fs: prevent out-of-bounds array speculation when closing a file descriptor (bsc#1242780). - CVE-2024-26643: Fixed mark set as dead when unbinding anonymous set with timeout (bsc#1221829). - CVE-2024-42265: protect the fetch of ->fd[fd] in do_dup2() from mispredictions (bsc#1229334). - CVE-2024-53164: net: sched: fix ordering of qlen adjustment (bsc#1234863). - CVE-2025-21881: uprobes: Reject the shared zeropage in uprobe_write_opcode() (bsc#1240185). - CVE-2025-21971: net_sched: Prevent creation of classes with TC_H_ROOT (bsc#1240799). - CVE-2025-38079: crypto: algif_hash - fix double free in hash_accept (bsc#1245217). - CVE-2025-38181: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr() (bsc#1246000). - CVE-2025-38200: i40e: fix MMIO write access to an invalid page in i40e_clear_hw (bsc#1246045). - CVE-2025-38206: exfat: fix double free in delayed_free (bsc#1246073). - CVE-2025-38212: ipc: fix to protect IPCS lookups using RCU (bsc#1246029). - CVE-2025-38213: vgacon: Add check for vc_origin address range in vgacon_scroll() (bsc#1246037). - CVE-2025-38257: s390/pkey: Prevent overflow in size calculation for memdup_user() (bsc#1246186). - CVE-2025-38350: net/sched: Always pass notifications when child class becomes empty (bsc#1246781). - CVE-2025-38468: net/sched: Return NULL when htb_lookup_leaf encounters an empty rbtree (bsc#1247437). - CVE-2025-38477: net/sched: sch_qfq: Avoid triggering might_sleep in atomic context in qfq_delete_class (bsc#1247314). - CVE-2025-38494: HID: core: do not bypass hid_hw_raw_request (bsc#1247349). - CVE-2025-38495: HID: core: ensure the allocated report buffer can contain the reserved report ID (bsc#1247348). - CVE-2025-38497: usb: gadget: configfs: Fix OOB read on empty string write (bsc#1247347). The following non-security bugs were fixed: - Revert 'hugetlb: unshare some PMDs when splitting VMAs (bsc#1245431).' - Revert 'mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race' - Revert 'mm/hugetlb: unshare page tables during VMA split, not before'

Affected Systems

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-64kb&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Manager Proxy LTS 4.3

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default-base&distro=SUSE Manager Server LTS 4.3

    < 5.14.21-150400.24.173.1.150400.24.88.1

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Manager Proxy LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-default&distro=SUSE Manager Server LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-livepatch-SLE15-SP4_Update_43&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 1-150400.9.3.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Manager Proxy LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-source&distro=SUSE Manager Server LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Manager Proxy LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-syms&distro=SUSE Manager Server LTS 4.3

    < 5.14.21-150400.24.173.1

  • susekernel-zfcpdump&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.173.1

  • susekernel-zfcpdump&distro=SUSE Manager Server LTS 4.3

    < 5.14.21-150400.24.173.1

References (59)