Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP6)
This update for the Linux Kernel 6.4.0-150600_23_25 fixes several issues. The following security issues were fixed: - CVE-2025-38177: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1246356). - CVE-2025-38109: net/mlx5: fix ECVF vports unload on shutdown flow (bsc#1245685). - CVE-2025-38181: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr() (bsc#1246001). - CVE-2025-21756: vsock: Keep the binding until socket destruction (bsc#1245795). - CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours mounts (bsc#1247499). - CVE-2025-38555: usb: gadget : fix use-after-free in composite_dev_cleanup() (bsc#1248298).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 6.4.0-150600_23_25 fixes several issues. The following security issues were fixed: - CVE-2025-38177: sch_hfsc: make hfsc_qlen_notify() idempotent (bsc#1246356). - CVE-2025-38109: net/mlx5: fix ECVF vports unload on shutdown flow (bsc#1245685). - CVE-2025-38181: calipso: Fix null-ptr-deref in calipso_req_{set,del}attr() (bsc#1246001). - CVE-2025-21756: vsock: Keep the binding until socket destruction (bsc#1245795). - CVE-2025-38498: do_change_type(): refuse to operate on unmounted/not ours mounts (bsc#1247499). - CVE-2025-38555: usb: gadget : fix use-after-free in composite_dev_cleanup() (bsc#1248298).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1245685
- https://bugzilla.suse.com/1245795
- https://bugzilla.suse.com/1246001
- https://bugzilla.suse.com/1246356
- https://bugzilla.suse.com/1247499
- https://bugzilla.suse.com/1248298
- https://www.suse.com/security/cve/CVE-2025-21756
- https://www.suse.com/security/cve/CVE-2025-38109
- https://www.suse.com/security/cve/CVE-2025-38177
- https://www.suse.com/security/cve/CVE-2025-38181
- https://www.suse.com/security/cve/CVE-2025-38498
- https://www.suse.com/security/cve/CVE-2025-38555
- https://www.suse.com/support/update/announcement/2025/suse-su-202503408-1/