FlawAtlas
Search the atlas
SUSE-SU-2025:01982-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-32399: Fixed a race condition when removing the HCI controller (bsc#1184611). - CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981). - CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (bsc#1238032). - CVE-2022-49320: dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type (bsc#1238394). - CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493). - CVE-2022-49769: gfs2: Check sb_bsize_shift after reading superblock (bsc#1242440). - CVE-2022-49770: ceph: avoid putting the realm twice when decoding snaps fails (bsc#1242597). - CVE-2022-49775: tcp: cdg: allow tcp_cdg_release() to be called multiple times (bsc#1242245). - CVE-2022-49789: scsi: zfcp: Fix double free of FSF request when qdio send fails (bsc#1242366). - CVE-2023-53039: HID: intel-ish-hid: ipc: Fix potential use-after-free in work function (bsc#1242745). - CVE-2024-53168: net: make sock_inuse_add() available (bsc#1234887). - CVE-2024-56558: nfsd: make sure exp active before svc_export_show (bsc#1235100). - CVE-2024-56705: media: atomisp: add check for rgby_data memory allocation failure (bsc#1235568). - CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471). - CVE-2025-21999: proc: fix UAF in proc_get_inode() (bsc#1240802). - CVE-2025-22028: media: vimc: skip .s_stream() for stopped entities (bsc#1241362). - CVE-2025-22121: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() (bsc#1241593). - CVE-2025-37789: net: openvswitch: fix nested key length validation in the set() action (bsc#1242762). - CVE-2025-37846: arm64: mops: Do not dereference src reg for a set operation (bsc#1242963). - CVE-2025-40364: io_uring: fix io_req_prep_async with provided buffers (bsc#1241637). The following non-security bugs were fixed: - blk: Drop a couple of block layer git-fixes (bsc#1170891 bsc#1173139). - x86/entry: Remove skip_r11rcx (bsc#1201644, bsc#1201664, bsc#1201672, bsc#1201673, bsc#1201676). - HID: intel-ish-hid: ipc: Fix dev_err usage with uninitialized dev->devc (bsc#1242745) - kernel: Remove debug flavor (bsc#1243919). - devm-helpers: Add resource managed version of work init (bsc#1242745). - rpm: fixup 'rpm: support gz and zst compression methods' once more (bsc#1190428, bsc#1190358). - mtd: phram: Add the kernel lock down check (bsc#1232649). - ocfs2: fix the issue with discontiguous allocation in the global_bitmap (git-fixes). - usb: roles: Call try_module_get() from usb_role_switch_find_by_fwnode() (git-fixes). - usb: typec: tps6598x: Fix return value check in tps6598x_probe() (git-fixes). - workqueue: Add resource managed version of delayed work init (bsc#1242745)

Exploit probability Not scored
Published June 17, 2025
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-syms
SUSE:Enterprise Storage 7.1 kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-preempt
SUSE:Enterprise Storage 7.1 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-docs
SUSE:Linux Enterprise Micro 5.2 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-preempt
SUSE:Linux Enterprise Micro 5.2 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-64kb
SUSE:Linux Enterprise Micro 5.1 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-obs-build
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-livepatch-SLE15-SP3_Update_58
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-preempt
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-default-base
SUSE:Linux Enterprise Micro 5.1 kernel-default-base
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-syms
SUSE:Linux Enterprise High Availability Extension 15 SP3 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 kernel-source
SUSE:Enterprise Storage 7.1 kernel-64kb
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS kernel-source
SUSE:Enterprise Storage 7.1 kernel-default-base
SUSE:Enterprise Storage 7.1 kernel-default
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-zfcpdump
SUSE:Linux Enterprise Live Patching 15 SP3 kernel-default
SUSE:Enterprise Storage 7.1 kernel-preempt
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-obs-build
SUSE:Linux Enterprise Server 15 SP3-LTSS kernel-default

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:01982-1

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2021-32399: Fixed a race condition when removing the HCI controller (bsc#1184611). - CVE-2022-49110: netfilter: conntrack: revisit gc autotuning (bsc#1237981). - CVE-2022-49139: Bluetooth: fix null ptr deref on hci_sync_conn_complete_evt (bsc#1238032). - CVE-2022-49320: dmaengine: zynqmp_dma: In struct zynqmp_dma_chan fix desc_size data type (bsc#1238394). - CVE-2022-49767: 9p/trans_fd: always use O_NONBLOCK read/write (bsc#1242493). - CVE-2022-49769: gfs2: Check sb_bsize_shift after reading superblock (bsc#1242440). - CVE-2022-49770: ceph: avoid putting the realm twice when decoding snaps fails (bsc#1242597). - CVE-2022-49775: tcp: cdg: allow tcp_cdg_release() to be called multiple times (bsc#1242245). - CVE-2022-49789: scsi: zfcp: Fix double free of FSF request when qdio send fails (bsc#1242366). - CVE-2023-53039: HID: intel-ish-hid: ipc: Fix potential use-after-free in work function (bsc#1242745). - CVE-2024-53168: net: make sock_inuse_add() available (bsc#1234887). - CVE-2024-56558: nfsd: make sure exp active before svc_export_show (bsc#1235100). - CVE-2024-56705: media: atomisp: add check for rgby_data memory allocation failure (bsc#1235568). - CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471). - CVE-2025-21999: proc: fix UAF in proc_get_inode() (bsc#1240802). - CVE-2025-22028: media: vimc: skip .s_stream() for stopped entities (bsc#1241362). - CVE-2025-22121: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() (bsc#1241593). - CVE-2025-37789: net: openvswitch: fix nested key length validation in the set() action (bsc#1242762). - CVE-2025-37846: arm64: mops: Do not dereference src reg for a set operation (bsc#1242963). - CVE-2025-40364: io_uring: fix io_req_prep_async with provided buffers (bsc#1241637). The following non-security bugs were fixed: - blk: Drop a couple of block layer git-fixes (bsc#1170891 bsc#1173139). - x86/entry: Remove skip_r11rcx (bsc#1201644, bsc#1201664, bsc#1201672, bsc#1201673, bsc#1201676). - HID: intel-ish-hid: ipc: Fix dev_err usage with uninitialized dev->devc (bsc#1242745) - kernel: Remove debug flavor (bsc#1243919). - devm-helpers: Add resource managed version of work init (bsc#1242745). - rpm: fixup 'rpm: support gz and zst compression methods' once more (bsc#1190428, bsc#1190358). - mtd: phram: Add the kernel lock down check (bsc#1232649). - ocfs2: fix the issue with discontiguous allocation in the global_bitmap (git-fixes). - usb: roles: Call try_module_get() from usb_role_switch_find_by_fwnode() (git-fixes). - usb: typec: tps6598x: Fix return value check in tps6598x_probe() (git-fixes). - workqueue: Add resource managed version of delayed work init (bsc#1242745)

View original source

05 / REFERENCES

Further evidence