gpp_maybe Security update for the linux kernel
SUSE-SLE-Micro-5.5-2026-4347


The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). - CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). - CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). - CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). - CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). - CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). - CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). - CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). - CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). - CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). - CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). - CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). - CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). - CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). - CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). - CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). - CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). - CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). - CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). - CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). - CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). - CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). - CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). - CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). - CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). - CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). - CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). - CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). - CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). - CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). - CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). - CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). - CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). - CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). - CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). - CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). - CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). - CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). - CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). - CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). - CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). - CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). - CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). - CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). - CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). - CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). - CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). - CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). - CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). - CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). - CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). - CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). - CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). - CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). - CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). - CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). - CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). - CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). - CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). - CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). - CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). - CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). - CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). - CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). - CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). - CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). - CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). - CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). - CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). - CVE-2026-80722: wifi: mac80211: validate individual TWT params before driver setup (bsc#1277860). The following non security issues were fixed: - mkspec-dtb: Move DTS prefix into package list. - mkspec-dtb: Move provides-obsoletes to package list. - mkspec-dtb: Put per-architecture package lists into a hash. - mkspec-dtb: re-indent. - net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). - net: mana: Add handler for sriov configure (bsc#1272756). - net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). - net: mana: Route ring-buffer access through offset-based helpers (git-fixes). - net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). - PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes). - powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). - RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). - RDMA/mana_ib: unify QP lookup table (git-fixes). - RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes). - RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes). - RDMA/siw: Introduce siw_free_cm_id (git-fixes). - RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes). - scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). - smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). - smb: client: require net admin for CIFS SWN netlink (bsc#1273966).


cloud_download Downloads

SUSE Linux Enterprise Micro 5.5 x86_64
  • Packages
    kernel-devel-rt
    Development files needed for building kernel modules
    5.14.21-150500.13.161.1 lock rpm
    kernel-rt
    Kernel with PREEMPT_RT (realtime) support
    5.14.21-150500.13.161.1 lock rpm lock nosrc
    kernel-source-rt
    The Linux Kernel Sources
    5.14.21-150500.13.161.1 lock rpm lock src