SUSE-SU-2026:0617-1

Advisory lineage Upstream: 380 Downstream: 0
Published: 24 Feb 2026, 15:19
Last modified:26 Feb 2026, 16:16

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

24 Feb 2026, 15:19
Published
Vulnerability first disclosed
26 Feb 2026, 16:16
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50630: mm: hugetlb: fix UAF in hugetlb_handle_userfault (bsc#1254785). - CVE-2022-50697: mrp: introduce active flags to prevent UAF when applicant uninit (bsc#1255594). - CVE-2022-50700: wifi: ath10k: Delay the unmapping of the buffer (bsc#1255576). - CVE-2023-53215: sched/fair: Don't balance task to its current running CPU (bsc#1250397). - CVE-2023-53254: cacheinfo: Fix shared_cpu_map to handle shared caches at different levels (bsc#1249871). - CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254751). - CVE-2023-54142: gtp: Fix use-after-free in __gtp_encap_destroy() (bsc#1256095). - CVE-2023-54243: netfilter: ebtables: fix table blob use-after-free (bsc#1255908). - CVE-2024-28956: x86/its: Enumerate Indirect Target Selection (ITS) bug (bsc#1242006). - CVE-2024-36348: x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896). - CVE-2024-36349: x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896). - CVE-2024-36350: x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896). - CVE-2024-36357: x86/bugs: Add a Transient Scheduler Attacks mitigation (bsc#1238896). - CVE-2024-44987: ipv6: prevent UAF in ip6_send_skb() (bsc#1230185). - CVE-2024-46854: net: dpaa: Pad packets to ETH_ZLEN (bsc#1231084). - CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the allocated buffer (bsc#1238917). - CVE-2025-38068: crypto: lzo - Fix compression buffer overrun (bsc#1245210). - CVE-2025-38129: page_pool: fix inconsistency for page_pool_ring_lock() (bsc#1245723). - CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1245751). - CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1247177). - CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046). - CVE-2025-40019: crypto: essiv - Check ssize for decryption and in-place encryption (bsc#1252678). - CVE-2025-40139: net: ipv4: Consolidate ipv4_mtu and ip_dst_mtu_maybe_forward (bsc#1253409). - CVE-2025-40215: kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959). - CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520). - CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813). - CVE-2025-40257: mptcp: fix a race in mptcp_pm_del_add_timer() (bsc#1254842). - CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1254843). - CVE-2025-40277: drm/vmwgfx: Validate command header size against (bsc#1254894). - CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847). - CVE-2025-40300: Documentation/hw-vuln: Add VMSCAPE documentation (bsc#1247483). - CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615). - CVE-2025-68183: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (bsc#1255251). - CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255377). - CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255401). - CVE-2025-68312: usbnet: Prevents free active kevent (bsc#1255171). - CVE-2025-68732: gpu: host1x: Fix race in syncpt alloc/free (bsc#1255688). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256641). - CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256623). - CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256612). - CVE-2025-71112: net: hns3: add VLAN id validation before using (bsc#1256726). - CVE-2025-71116: libceph: make decode_pool() more resilient against corrupted osdmaps (bsc#1256744). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256779). - CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257236). - CVE-2026-23001: macvlan: fix possible UAF in macvlan_forward_source() (bsc#1257232). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1257749). - CVE-2026-23089: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() (bsc#1257790). The following non security issues were fixed: - net: hv_netvsc: reject RSS hash key programming without RX indirection table (bsc#1257473). - net: tcp: allow zero-window ACK update the window (bsc#1254767). - net: tcp: send zero-window ACK when no memory (bsc#1254767). - scsi: storvsc: Process unsupported MODE_SENSE_10 (bsc#1257296). - tcp: correct handling of extreme memory squeeze (bsc#1254767). - x86/CPU/AMD: Add ZenX generations flags (bsc#1238896). - x86/its: Fix crash during dynamic its initialization (bsc#1257771). - x86/modules: Set VM_FLUSH_RESET_PERMS in module_alloc() (bsc#1257771). - x86: make page fault handling disable interrupts properly (git-fixes).

Affected Systems

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-64kb&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default-base&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default-base&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1.150400.24.98.3

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-livepatch-SLE15-SP4_Update_48&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 1-150400.9.7.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.194.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.194.1

  • susekernel-zfcpdump&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.194.1

References (802)