SUSE-SU-2026:0984-1

Advisory lineage Upstream: 11 Downstream: 0
Published: 23 Mar 2026, 22:20
Last modified:25 Mar 2026, 08:31

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Mar 2026, 22:20
Published
Vulnerability first disclosed
25 Mar 2026, 08:31
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the allocated buffer (bsc#1238917). - CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075). - CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change (bsc#1256645). - CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231). - CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (bsc#1257735). - CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258395). - CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1258340). - CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258518). - CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1258850). - CVE-2026-23269: apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1259857). The following non-security bugs were fixed: - Disable CONFIG_NET_SCH_ATM (jsc#PED-12836). - apparmor: Fix double free of ns_name in aa_replace_profiles() (bsc#1258849). - apparmor: fix differential encoding verification (bsc#1258849). - apparmor: fix memory leak in verify_header (bsc#1258849). - apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (bsc#1258849). - apparmor: fix race between freeing data and fs accessing it (bsc#1258849). - apparmor: fix race on rawdata dereference (bsc#1258849). - apparmor: fix side-effect bug in match_char() macro usage (bsc#1258849). - apparmor: fix unprivileged local user can do privileged policy management (bsc#1258849). - apparmor: fix: limit the number of levels of policy namespaces (bsc#1258849). - apparmor: replace recursive profile removal with iterative approach (bsc#1258849). - apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1258849).

Affected Systems

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-64kb&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-64kb&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default-base&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default-base&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1.150400.24.100.1

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.3

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise Micro 5.4

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-livepatch-SLE15-SP4_Update_49&distro=SUSE Linux Enterprise Live Patching 15 SP4

    < 1-150400.9.3.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS

    < 5.14.21-150400.24.197.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4

    < 5.14.21-150400.24.197.1

  • susekernel-zfcpdump&distro=SUSE Linux Enterprise Server 15 SP4-LTSS

    < 5.14.21-150400.24.197.1

References (25)