SUSE-SU-2026:0928-1
Vulnerability Summary
Timeline
Description
Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP3 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-53794: cifs: fix session state check in reconnect to avoid use-after-free issue (bsc#1255163). - CVE-2023-53827: Bluetooth: L2CAP: Fix use-after-free in l2cap_disconnect_{req,rsp} (bsc#1255049). - CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the allocated buffer (bsc#1238917). - CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1247177). - CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255401). - CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1256645). - CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231). - CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (bsc#1257735). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1257749). - CVE-2026-23089: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() (bsc#1257790). - CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258395). - CVE-2026-23204: net: add skb_header_pointer_careful() helper (bsc#1258340). The following non security issues were fixed: - apparmor: fix differential encoding verification (bsc#1258849). - apparmor: Fix double free of ns_name in aa_replace_profiles() (bsc#1258849). - apparmor: fix memory leak in verify_header (bsc#1258849). - apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (bsc#1258849). - apparmor: fix side-effect bug in match_char() macro usage (bsc#1258849). - apparmor: fix unprivileged local user can do privileged policy management (bsc#1258849). - apparmor: fix: limit the number of levels of policy namespaces (bsc#1258849). - apparmor: replace recursive profile removal with iterative approach (bsc#1258849). - apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1258849).
Affected Systems
- suse•kernel-default-base&distro=SUSE Linux Enterprise Micro 5.2
< 5.3.18-150300.59.238.1.150300.18.142.1
- suse•kernel-default&distro=SUSE Linux Enterprise Micro 5.2
< 5.3.18-150300.59.238.1
References (28)
- https://www.suse.com/support/update/announcement/2026/suse-su-20260928-1/
- https://bugzilla.suse.com/1238917
- https://bugzilla.suse.com/1246166
- https://bugzilla.suse.com/1247177
- https://bugzilla.suse.com/1255049
- https://bugzilla.suse.com/1255163
- https://bugzilla.suse.com/1255401
- https://bugzilla.suse.com/1256645
- https://bugzilla.suse.com/1257231
- https://bugzilla.suse.com/1257735
- https://bugzilla.suse.com/1257749
- https://bugzilla.suse.com/1257790
- https://bugzilla.suse.com/1258340
- https://bugzilla.suse.com/1258395
- https://bugzilla.suse.com/1258849
- https://www.suse.com/security/cve/CVE-2023-53794
- https://www.suse.com/security/cve/CVE-2023-53827
- https://www.suse.com/security/cve/CVE-2025-21738
- https://www.suse.com/security/cve/CVE-2025-38224
- https://www.suse.com/security/cve/CVE-2025-38375
- https://www.suse.com/security/cve/CVE-2025-68285
- https://www.suse.com/security/cve/CVE-2025-71066
- https://www.suse.com/security/cve/CVE-2026-23004
- https://www.suse.com/security/cve/CVE-2026-23060
- https://www.suse.com/security/cve/CVE-2026-23074
- https://www.suse.com/security/cve/CVE-2026-23089
- https://www.suse.com/security/cve/CVE-2026-23191
- https://www.suse.com/security/cve/CVE-2026-23204