FlawAtlas
Search the atlas
SUSE-SU-2025:01633-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49111: Bluetooth: Fix use after free in hci_send_acl (bsc#1237984). - CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865). - CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747). - CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512). - CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835). - CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280). - CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371).

Exploit probability Not scored
Published May 21, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-syms
SUSE:Enterprise Storage 7.1 kernel-obs-build
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-livepatch-SLE15-SP3_Update_57
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-preempt
SUSE:Enterprise Storage 7.1 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-docs
SUSE:Linux Enterprise Micro 5.2 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-preempt
SUSE:Linux Enterprise Micro 5.2 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Micro 5.1 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Micro 5.1 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise High Availability Extension 15 SP3 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-source
SUSE:Enterprise Storage 7.1 kernel-64kb
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-preempt
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-zfcpdump
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-default
SUSE:Enterprise Storage 7.1 kernel-preempt
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01633-1

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-49111: Bluetooth: Fix use after free in hci_send_acl (bsc#1237984). - CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865). - CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747). - CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512). - CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835). - CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280). - CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371).

View original source

05 / REFERENCES

Further evidence