Security update for the Linux Kernel
| Announcement ID: | SUSE-SU-2026:2631-1 |
|---|---|
| Release Date: | 2026-06-25T11:55:13Z |
| Rating: | important |
| References: | |
| Cross-References: |
|
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 21 vulnerabilities and has two security fixes can now be installed.
Description:
The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues
The following security issues were fixed:
- CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
- CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416).
- CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).
- CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663).
- CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993).
- CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769).
- CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).
- CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).
- CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).
- CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).
- CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
- CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).
- CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214).
- CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).
- CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640).
- CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).
- CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
- CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652).
- CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).
- CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697).
The following non security issues were fixed:
- smb: client: correctly handle ErrorContextData as a flexible array (git-fixes).
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Micro for Rancher 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2631=1 -
SUSE Linux Enterprise Micro 5.3
zypper in -t patch SUSE-SLE-Micro-5.3-2026-2631=1 -
SUSE Linux Enterprise Micro for Rancher 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-2631=1 -
SUSE Linux Enterprise Micro 5.4
zypper in -t patch SUSE-SLE-Micro-5.4-2026-2631=1
Package List:
-
SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.173.1
- kernel-rt-debugsource-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro for Rancher 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.3 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.3 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.173.1
- kernel-rt-debugsource-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.3 (noarch)
- kernel-source-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.173.1
- kernel-rt-debugsource-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro for Rancher 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.4 (nosrc x86_64)
- kernel-rt-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.4 (x86_64)
- kernel-rt-debuginfo-5.14.21-150400.15.173.1
- kernel-rt-debugsource-5.14.21-150400.15.173.1
-
SUSE Linux Enterprise Micro 5.4 (noarch)
- kernel-source-rt-5.14.21-150400.15.173.1
References:
- https://www.suse.com/security/cve/CVE-2025-10263.html
- https://www.suse.com/security/cve/CVE-2025-68324.html
- https://www.suse.com/security/cve/CVE-2026-23392.html
- https://www.suse.com/security/cve/CVE-2026-31473.html
- https://www.suse.com/security/cve/CVE-2026-31500.html
- https://www.suse.com/security/cve/CVE-2026-31613.html
- https://www.suse.com/security/cve/CVE-2026-31697.html
- https://www.suse.com/security/cve/CVE-2026-31698.html
- https://www.suse.com/security/cve/CVE-2026-31699.html
- https://www.suse.com/security/cve/CVE-2026-31759.html
- https://www.suse.com/security/cve/CVE-2026-43077.html
- https://www.suse.com/security/cve/CVE-2026-43198.html
- https://www.suse.com/security/cve/CVE-2026-45984.html
- https://www.suse.com/security/cve/CVE-2026-46037.html
- https://www.suse.com/security/cve/CVE-2026-46116.html
- https://www.suse.com/security/cve/CVE-2026-46120.html
- https://www.suse.com/security/cve/CVE-2026-46123.html
- https://www.suse.com/security/cve/CVE-2026-46150.html
- https://www.suse.com/security/cve/CVE-2026-46159.html
- https://www.suse.com/security/cve/CVE-2026-46197.html
- https://www.suse.com/security/cve/CVE-2026-46227.html
- https://bugzilla.suse.com/show_bug.cgi?id=1255416
- https://bugzilla.suse.com/show_bug.cgi?id=1258538
- https://bugzilla.suse.com/show_bug.cgi?id=1260531
- https://bugzilla.suse.com/show_bug.cgi?id=1262663
- https://bugzilla.suse.com/show_bug.cgi?id=1262993
- https://bugzilla.suse.com/show_bug.cgi?id=1263769
- https://bugzilla.suse.com/show_bug.cgi?id=1263879
- https://bugzilla.suse.com/show_bug.cgi?id=1263880
- https://bugzilla.suse.com/show_bug.cgi?id=1264076
- https://bugzilla.suse.com/show_bug.cgi?id=1264116
- https://bugzilla.suse.com/show_bug.cgi?id=1264470
- https://bugzilla.suse.com/show_bug.cgi?id=1264610
- https://bugzilla.suse.com/show_bug.cgi?id=1266214
- https://bugzilla.suse.com/show_bug.cgi?id=1266290
- https://bugzilla.suse.com/show_bug.cgi?id=1267214
- https://bugzilla.suse.com/show_bug.cgi?id=1267361
- https://bugzilla.suse.com/show_bug.cgi?id=1267369
- https://bugzilla.suse.com/show_bug.cgi?id=1267381
- https://bugzilla.suse.com/show_bug.cgi?id=1267387
- https://bugzilla.suse.com/show_bug.cgi?id=1267621
- https://bugzilla.suse.com/show_bug.cgi?id=1267640
- https://bugzilla.suse.com/show_bug.cgi?id=1267652
- https://bugzilla.suse.com/show_bug.cgi?id=1267697