Security update for the Linux Kernel
| Announcement ID: | SUSE-SU-2026:2068-1 |
|---|---|
| Release Date: | 2026-05-26T07:29:54Z |
| Rating: | important |
| References: |
|
| Cross-References: |
|
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 74 vulnerabilities and has four security fixes can now be installed.
Description:
The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues
The following security issues were fixed:
- CVE-2022-50053: iavf: Fix reset error handling (bsc#1245038).
- CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1. (bsc#1243603).
- CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500 bsc#1262778).
- CVE-2025-68185: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (bsc#1255135).
- CVE-2025-71118: ACPICA: Avoid walking the Namespace if start_node is NULL (bsc#1256763).
- CVE-2025-71238: scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1259186).
- CVE-2026-23193: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (bsc#1258414).
- CVE-2026-23216: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (bsc#1258447).
- CVE-2026-23276: net: add xmit recursion limit to tunnel xmit functions (bsc#1260012).
- CVE-2026-23290: net: usb: pegasus: validate USB endpoints (bsc#1260533).
- CVE-2026-23292: scsi: target: Fix recursive locking in __configfs_open_file() (bsc#1260500).
- CVE-2026-23293: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260486).
- CVE-2026-23312: net: usb: kaweth: validate USB endpoints (bsc#1260561).
- CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523).
- CVE-2026-23378: act_ife: load meta modules before tcf_idr_check_alloc() (bsc#1260546).
- CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566).
- CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581).
- CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779).
- CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687).
- CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703).
- CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686).
- CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781).
- CVE-2026-23461: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (bsc#1261707).
- CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710).
- CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692).
- CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636).
- CVE-2026-31393: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (bsc#1261719).
- CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645).
- CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638).
- CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796).
- CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632).
- CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (bsc#1261797).
- CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752).
- CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100).
- CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054).
- CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063).
- CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053).
- CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074).
- CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086).
- CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087).
- CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673).
- CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085).
- CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095).
- CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (bsc#1262734).
- CVE-2026-31524: HID: asus: avoid memory leak in asus_report_fixup() (bsc#1262605).
- CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723).
- CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600).
- CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582).
- CVE-2026-31667: Input: uinput - fix circular locking dependency with ff-core (bsc#1263139).
- CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556).
- CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593).
- CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668).
- CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882).
- CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059).
- CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181).
- CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931).
- CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469).
- CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482).
- CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634).
- CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848).
- CVE-2026-43255: wifi: libertas: fix WARNING in usb_tx_block (bsc#1264473).
- CVE-2026-43264: fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (bsc#1264424).
- CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090).
- CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126).
The following non security issues were fixed:
- list: add "list_del_init_careful()" to go with "list_empty_careful()" (bsc#1262778).
- ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718).
- ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).
Special Instructions and Notes:
- Please reboot the system after installing this update.
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server 12 SP5 LTSS
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2068=1 -
SUSE Linux Enterprise Live Patching 12-SP5
zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2068=1 -
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security
zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2068=1
Package List:
-
SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64)
- kernel-default-base-4.12.14-122.310.1
- kernel-default-debugsource-4.12.14-122.310.1
- dlm-kmp-default-4.12.14-122.310.1
- cluster-md-kmp-default-4.12.14-122.310.1
- ocfs2-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-default-base-debuginfo-4.12.14-122.310.1
- ocfs2-kmp-default-4.12.14-122.310.1
- kernel-default-devel-4.12.14-122.310.1
- dlm-kmp-default-debuginfo-4.12.14-122.310.1
- cluster-md-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-syms-4.12.14-122.310.1
- gfs2-kmp-default-4.12.14-122.310.1
- gfs2-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-default-debuginfo-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64 nosrc)
- kernel-default-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (noarch)
- kernel-source-4.12.14-122.310.1
- kernel-devel-4.12.14-122.310.1
- kernel-macros-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (s390x)
- kernel-default-man-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64)
- kernel-default-devel-debuginfo-4.12.14-122.310.1
-
SUSE Linux Enterprise Live Patching 12-SP5 (nosrc)
- kernel-default-4.12.14-122.310.1
-
SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64)
- kernel-default-debugsource-4.12.14-122.310.1
- kernel-default-kgraft-4.12.14-122.310.1
- kgraft-patch-4_12_14-122_310-default-1-8.3.1
- kernel-default-debuginfo-4.12.14-122.310.1
- kernel-default-kgraft-devel-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64)
- kernel-default-base-4.12.14-122.310.1
- kernel-default-debugsource-4.12.14-122.310.1
- dlm-kmp-default-4.12.14-122.310.1
- cluster-md-kmp-default-4.12.14-122.310.1
- ocfs2-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-default-base-debuginfo-4.12.14-122.310.1
- ocfs2-kmp-default-4.12.14-122.310.1
- kernel-default-devel-4.12.14-122.310.1
- dlm-kmp-default-debuginfo-4.12.14-122.310.1
- cluster-md-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-syms-4.12.14-122.310.1
- gfs2-kmp-default-4.12.14-122.310.1
- gfs2-kmp-default-debuginfo-4.12.14-122.310.1
- kernel-default-devel-debuginfo-4.12.14-122.310.1
- kernel-default-debuginfo-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (nosrc x86_64)
- kernel-default-4.12.14-122.310.1
-
SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch)
- kernel-source-4.12.14-122.310.1
- kernel-devel-4.12.14-122.310.1
- kernel-macros-4.12.14-122.310.1
References:
- https://www.suse.com/security/cve/CVE-2022-50053.html
- https://www.suse.com/security/cve/CVE-2023-20585.html
- https://www.suse.com/security/cve/CVE-2024-50082.html
- https://www.suse.com/security/cve/CVE-2025-68185.html
- https://www.suse.com/security/cve/CVE-2025-71108.html
- https://www.suse.com/security/cve/CVE-2025-71118.html
- https://www.suse.com/security/cve/CVE-2025-71238.html
- https://www.suse.com/security/cve/CVE-2026-23193.html
- https://www.suse.com/security/cve/CVE-2026-23209.html
- https://www.suse.com/security/cve/CVE-2026-23216.html
- https://www.suse.com/security/cve/CVE-2026-23268.html
- https://www.suse.com/security/cve/CVE-2026-23269.html
- https://www.suse.com/security/cve/CVE-2026-23273.html
- https://www.suse.com/security/cve/CVE-2026-23276.html
- https://www.suse.com/security/cve/CVE-2026-23290.html
- https://www.suse.com/security/cve/CVE-2026-23292.html
- https://www.suse.com/security/cve/CVE-2026-23293.html
- https://www.suse.com/security/cve/CVE-2026-23312.html
- https://www.suse.com/security/cve/CVE-2026-23340.html
- https://www.suse.com/security/cve/CVE-2026-23378.html
- https://www.suse.com/security/cve/CVE-2026-23391.html
- https://www.suse.com/security/cve/CVE-2026-23403.html
- https://www.suse.com/security/cve/CVE-2026-23404.html
- https://www.suse.com/security/cve/CVE-2026-23405.html
- https://www.suse.com/security/cve/CVE-2026-23408.html
- https://www.suse.com/security/cve/CVE-2026-23442.html
- https://www.suse.com/security/cve/CVE-2026-23449.html
- https://www.suse.com/security/cve/CVE-2026-23455.html
- https://www.suse.com/security/cve/CVE-2026-23456.html
- https://www.suse.com/security/cve/CVE-2026-23457.html
- https://www.suse.com/security/cve/CVE-2026-23458.html
- https://www.suse.com/security/cve/CVE-2026-23461.html
- https://www.suse.com/security/cve/CVE-2026-23462.html
- https://www.suse.com/security/cve/CVE-2026-23468.html
- https://www.suse.com/security/cve/CVE-2026-23472.html
- https://www.suse.com/security/cve/CVE-2026-31393.html
- https://www.suse.com/security/cve/CVE-2026-31400.html
- https://www.suse.com/security/cve/CVE-2026-31402.html
- https://www.suse.com/security/cve/CVE-2026-31403.html
- https://www.suse.com/security/cve/CVE-2026-31407.html
- https://www.suse.com/security/cve/CVE-2026-31408.html
- https://www.suse.com/security/cve/CVE-2026-31411.html
- https://www.suse.com/security/cve/CVE-2026-31416.html
- https://www.suse.com/security/cve/CVE-2026-31422.html
- https://www.suse.com/security/cve/CVE-2026-31423.html
- https://www.suse.com/security/cve/CVE-2026-31424.html
- https://www.suse.com/security/cve/CVE-2026-31425.html
- https://www.suse.com/security/cve/CVE-2026-31427.html
- https://www.suse.com/security/cve/CVE-2026-31428.html
- https://www.suse.com/security/cve/CVE-2026-31496.html
- https://www.suse.com/security/cve/CVE-2026-31504.html
- https://www.suse.com/security/cve/CVE-2026-31507.html
- https://www.suse.com/security/cve/CVE-2026-31512.html
- https://www.suse.com/security/cve/CVE-2026-31524.html
- https://www.suse.com/security/cve/CVE-2026-31602.html
- https://www.suse.com/security/cve/CVE-2026-31607.html
- https://www.suse.com/security/cve/CVE-2026-31649.html
- https://www.suse.com/security/cve/CVE-2026-31667.html
- https://www.suse.com/security/cve/CVE-2026-31675.html
- https://www.suse.com/security/cve/CVE-2026-31681.html
- https://www.suse.com/security/cve/CVE-2026-31685.html
- https://www.suse.com/security/cve/CVE-2026-31700.html
- https://www.suse.com/security/cve/CVE-2026-31738.html
- https://www.suse.com/security/cve/CVE-2026-31787.html
- https://www.suse.com/security/cve/CVE-2026-43025.html
- https://www.suse.com/security/cve/CVE-2026-43088.html
- https://www.suse.com/security/cve/CVE-2026-43110.html
- https://www.suse.com/security/cve/CVE-2026-43126.html
- https://www.suse.com/security/cve/CVE-2026-43190.html
- https://www.suse.com/security/cve/CVE-2026-43255.html
- https://www.suse.com/security/cve/CVE-2026-43264.html
- https://www.suse.com/security/cve/CVE-2026-43334.html
- https://www.suse.com/security/cve/CVE-2026-43437.html
- https://www.suse.com/security/cve/CVE-2026-46333.html
- https://bugzilla.suse.com/show_bug.cgi?id=1232500
- https://bugzilla.suse.com/show_bug.cgi?id=1243603
- https://bugzilla.suse.com/show_bug.cgi?id=1245038
- https://bugzilla.suse.com/show_bug.cgi?id=1255135
- https://bugzilla.suse.com/show_bug.cgi?id=1256763
- https://bugzilla.suse.com/show_bug.cgi?id=1256774
- https://bugzilla.suse.com/show_bug.cgi?id=1258414
- https://bugzilla.suse.com/show_bug.cgi?id=1258447
- https://bugzilla.suse.com/show_bug.cgi?id=1258518
- https://bugzilla.suse.com/show_bug.cgi?id=1258718
- https://bugzilla.suse.com/show_bug.cgi?id=1258849
- https://bugzilla.suse.com/show_bug.cgi?id=1258850
- https://bugzilla.suse.com/show_bug.cgi?id=1258854
- https://bugzilla.suse.com/show_bug.cgi?id=1258857
- https://bugzilla.suse.com/show_bug.cgi?id=1259186
- https://bugzilla.suse.com/show_bug.cgi?id=1259857
- https://bugzilla.suse.com/show_bug.cgi?id=1260010
- https://bugzilla.suse.com/show_bug.cgi?id=1260012
- https://bugzilla.suse.com/show_bug.cgi?id=1260486
- https://bugzilla.suse.com/show_bug.cgi?id=1260500
- https://bugzilla.suse.com/show_bug.cgi?id=1260523
- https://bugzilla.suse.com/show_bug.cgi?id=1260533
- https://bugzilla.suse.com/show_bug.cgi?id=1260546
- https://bugzilla.suse.com/show_bug.cgi?id=1260561
- https://bugzilla.suse.com/show_bug.cgi?id=1260566
- https://bugzilla.suse.com/show_bug.cgi?id=1261287
- https://bugzilla.suse.com/show_bug.cgi?id=1261295
- https://bugzilla.suse.com/show_bug.cgi?id=1261581
- https://bugzilla.suse.com/show_bug.cgi?id=1261632
- https://bugzilla.suse.com/show_bug.cgi?id=1261636
- https://bugzilla.suse.com/show_bug.cgi?id=1261638
- https://bugzilla.suse.com/show_bug.cgi?id=1261645
- https://bugzilla.suse.com/show_bug.cgi?id=1261686
- https://bugzilla.suse.com/show_bug.cgi?id=1261687
- https://bugzilla.suse.com/show_bug.cgi?id=1261692
- https://bugzilla.suse.com/show_bug.cgi?id=1261703
- https://bugzilla.suse.com/show_bug.cgi?id=1261707
- https://bugzilla.suse.com/show_bug.cgi?id=1261710
- https://bugzilla.suse.com/show_bug.cgi?id=1261719
- https://bugzilla.suse.com/show_bug.cgi?id=1261752
- https://bugzilla.suse.com/show_bug.cgi?id=1261779
- https://bugzilla.suse.com/show_bug.cgi?id=1261781
- https://bugzilla.suse.com/show_bug.cgi?id=1261796
- https://bugzilla.suse.com/show_bug.cgi?id=1261797
- https://bugzilla.suse.com/show_bug.cgi?id=1262053
- https://bugzilla.suse.com/show_bug.cgi?id=1262054
- https://bugzilla.suse.com/show_bug.cgi?id=1262063
- https://bugzilla.suse.com/show_bug.cgi?id=1262074
- https://bugzilla.suse.com/show_bug.cgi?id=1262086
- https://bugzilla.suse.com/show_bug.cgi?id=1262087
- https://bugzilla.suse.com/show_bug.cgi?id=1262100
- https://bugzilla.suse.com/show_bug.cgi?id=1262181
- https://bugzilla.suse.com/show_bug.cgi?id=1262605
- https://bugzilla.suse.com/show_bug.cgi?id=1262673
- https://bugzilla.suse.com/show_bug.cgi?id=1262734
- https://bugzilla.suse.com/show_bug.cgi?id=1262778
- https://bugzilla.suse.com/show_bug.cgi?id=1263085
- https://bugzilla.suse.com/show_bug.cgi?id=1263095
- https://bugzilla.suse.com/show_bug.cgi?id=1263139
- https://bugzilla.suse.com/show_bug.cgi?id=1263556
- https://bugzilla.suse.com/show_bug.cgi?id=1263582
- https://bugzilla.suse.com/show_bug.cgi?id=1263593
- https://bugzilla.suse.com/show_bug.cgi?id=1263600
- https://bugzilla.suse.com/show_bug.cgi?id=1263668
- https://bugzilla.suse.com/show_bug.cgi?id=1263723
- https://bugzilla.suse.com/show_bug.cgi?id=1263882
- https://bugzilla.suse.com/show_bug.cgi?id=1263931
- https://bugzilla.suse.com/show_bug.cgi?id=1264059
- https://bugzilla.suse.com/show_bug.cgi?id=1264424
- https://bugzilla.suse.com/show_bug.cgi?id=1264449
- https://bugzilla.suse.com/show_bug.cgi?id=1264469
- https://bugzilla.suse.com/show_bug.cgi?id=1264473
- https://bugzilla.suse.com/show_bug.cgi?id=1264482
- https://bugzilla.suse.com/show_bug.cgi?id=1264634
- https://bugzilla.suse.com/show_bug.cgi?id=1264848
- https://bugzilla.suse.com/show_bug.cgi?id=1265090
- https://bugzilla.suse.com/show_bug.cgi?id=1265126
- https://bugzilla.suse.com/show_bug.cgi?id=1265308