SUSE-SU-2025:1573-1

Advisory lineage Upstream: 14 Downstream: 0
Published: 16 May 2025, 16:32
Last modified:04 Feb 2026, 03:47

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 May 2025, 16:32
Published
Vulnerability first disclosed
04 Feb 2026, 03:47
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865). - CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747). - CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512). - CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471). - CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835). - CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280). - CVE-2025-22029: exec: fix the racy usage of fs_struct->in_exec (bsc#1241378). - CVE-2025-22045: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs (bsc#1241433). - CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371). - CVE-2025-22097: drm/vkms: Fix use after free and double free on init error (bsc#1241541). The following non-security bugs were fixed: - scsi: smartpqi: Add ctrl ready timeout module parameter (jsc#PED-1557, bsc#1201855, bsc#1240553).

Affected Systems

  • susekernel-rt&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.15.118.1

  • susekernel-rt&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.15.118.1

  • susekernel-source-rt&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.15.118.1

  • susekernel-source-rt&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.15.118.1

References (33)