SUSE-SU-2026:4347-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264347-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4347-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4347-1
Upstream
CVE (84)
Related
Published
2026-09-24T14:36:21Z
Modified
2026-09-25T09:45:03Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues:

The following security issues were fixed:

  • CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731).
  • CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).
  • CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
  • CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).
  • CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023).
  • CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
  • CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).
  • CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004).
  • CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242).
  • CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).
  • CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
  • CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).
  • CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830).
  • CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230).
  • CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182).
  • CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179).
  • CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
  • CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).
  • CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).
  • CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868).
  • CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).
  • CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).
  • CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).
  • CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).
  • CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).
  • CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060).
  • CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484).
  • CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488).
  • CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).
  • CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).
  • CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).
  • CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276).
  • CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).
  • CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422).
  • CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).
  • CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523).
  • CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547).
  • CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).
  • CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311).
  • CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).
  • CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995).
  • CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014).
  • CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031).
  • CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).
  • CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497).
  • CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
  • CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474).
  • CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941).
  • CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472).
  • CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
  • CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).
  • CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).
  • CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696).
  • CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705).
  • CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).
  • CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).
  • CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528).
  • CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155).
  • CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523).
  • CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).
  • CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).
  • CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678).
  • CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886).
  • CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905).
  • CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
  • CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285).
  • CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).
  • CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).
  • CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088).
  • CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408).
  • CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).
  • CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).
  • CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).
  • CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798).
  • CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).
  • CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782).
  • CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784).
  • CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).
  • CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931).
  • CVE-2026-80722: wifi: mac80211: validate individual TWT params before driver setup (bsc#1277860).

The following non security issues were fixed:

  • mkspec-dtb: Move DTS prefix into package list.
  • mkspec-dtb: Move provides-obsoletes to package list.
  • mkspec-dtb: Put per-architecture package lists into a hash.
  • mkspec-dtb: re-indent.
  • net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes).
  • net: mana: Add handler for sriov configure (bsc#1272756).
  • net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792).
  • net: mana: Route ring-buffer access through offset-based helpers (git-fixes).
  • net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).
  • PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes).
  • powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290).
  • RDMA/mana_ib: drain QP references after partial table insertion (git-fixes).
  • RDMA/mana_ib: unify QP lookup table (git-fixes).
  • RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes).
  • RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes).
  • RDMA/siw: Introduce siw_free_cm_id (git-fixes).
  • RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes).
  • scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes).
  • smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).
  • smb: client: require net admin for CIFS SWN netlink (bsc#1273966).
References

Affected packages

SUSE:Linux Enterprise Micro 5.5 / kernel-rt

Package

Name
kernel-rt
Purl
pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.14.21-150500.13.161.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-devel-rt": "5.14.21-150500.13.161.1",
            "kernel-rt": "5.14.21-150500.13.161.1",
            "kernel-source-rt": "5.14.21-150500.13.161.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4347-1.json"

SUSE:Linux Enterprise Micro 5.5 / kernel-source-rt

Package

Name
kernel-source-rt
Purl
pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.14.21-150500.13.161.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-devel-rt": "5.14.21-150500.13.161.1",
            "kernel-rt": "5.14.21-150500.13.161.1",
            "kernel-source-rt": "5.14.21-150500.13.161.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4347-1.json"