FlawAtlas
Search the atlas
SUSE-SU-2025:01620-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-48933: netfilter: nf_tables: fix memory leak during stateful obj update (bsc#1229621). - CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981). - CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (bsc#1238032). - CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493). - CVE-2024-46763: fou: Fix null-ptr-deref in GRO (bsc#1230764). - CVE-2024-50038: netfilter: xtables: avoid NFPROTO_UNSPEC where needed (bsc#1231910). - CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865). - CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747). - CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512). - CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471). - CVE-2025-21839: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (bsc#1239061). - CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835). - CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280). - CVE-2025-22045: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs (bsc#1241433). - CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371). - CVE-2025-22097: drm/vkms: Fix use after free and double free on init error (bsc#1241541). - CVE-2025-2312: CIFS: New mount option for cifs.upcall namespace resolution (bsc#1239684). - CVE-2025-23138: watch_queue: fix pipe accounting mismatch (bsc#1241648). - CVE-2025-39735: jfs: fix slab-out-of-bounds read in ea_get() (bsc#1241625). The following non-security bugs were fixed: - cpufreq: ACPI: Mark boost policy as enabled when setting boost (bsc#1236777). - cpufreq: Allow drivers to advertise boost enabled (bsc#1236777). - cpufreq: Fix per-policy boost behavior on SoCs using cpufreq_boost_set_sw() (bsc#1236777). - cpufreq: Support per-policy performance boost (bsc#1236777). - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778). - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778). - x86/bpf: Call branch history clearing sequence on exit (bsc#1242778).

Exploit probability Not scored
Published May 21, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-syms
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-default-base
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-obs-build
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-docs
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-source
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-syms
SUSE:Linux Enterprise Live Patching 15 SP5 kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-default-base
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-64kb
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-64kb
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-obs-build
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-zfcpdump
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-default-base
SUSE:Linux Enterprise Live Patching 15 SP5 kernel-livepatch-SLE15-SP5_Update_26
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-docs
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-64kb
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-source

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01620-1

The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-48933: netfilter: nf_tables: fix memory leak during stateful obj update (bsc#1229621). - CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981). - CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (bsc#1238032). - CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493). - CVE-2024-46763: fou: Fix null-ptr-deref in GRO (bsc#1230764). - CVE-2024-50038: netfilter: xtables: avoid NFPROTO_UNSPEC where needed (bsc#1231910). - CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865). - CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747). - CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512). - CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471). - CVE-2025-21839: KVM: x86: Load DR6 with guest value only before entering .vcpu_run() loop (bsc#1239061). - CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835). - CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280). - CVE-2025-22045: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs (bsc#1241433). - CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371). - CVE-2025-22097: drm/vkms: Fix use after free and double free on init error (bsc#1241541). - CVE-2025-2312: CIFS: New mount option for cifs.upcall namespace resolution (bsc#1239684). - CVE-2025-23138: watch_queue: fix pipe accounting mismatch (bsc#1241648). - CVE-2025-39735: jfs: fix slab-out-of-bounds read in ea_get() (bsc#1241625). The following non-security bugs were fixed: - cpufreq: ACPI: Mark boost policy as enabled when setting boost (bsc#1236777). - cpufreq: Allow drivers to advertise boost enabled (bsc#1236777). - cpufreq: Fix per-policy boost behavior on SoCs using cpufreq_boost_set_sw() (bsc#1236777). - cpufreq: Support per-policy performance boost (bsc#1236777). - x86/bhi: Do not set BHI_DIS_S in 32-bit mode (bsc#1242778). - x86/bpf: Add IBHF call at end of classic BPF (bsc#1242778). - x86/bpf: Call branch history clearing sequence on exit (bsc#1242778).

View original source

05 / REFERENCES

Further evidence