FlawAtlas
Search the atlas
SUSE-SU-2025:4064-1 Not scored

Security update for the Linux Kernel (Live Patch 60 for SUSE Linux Enterprise 15 SP3)

This update for the SUSE Linux Enterprise kernel 5.3.18-150300.59.215 fixes various security issues The following security issues were fixed: - CVE-2022-50248: wifi: iwlwifi: mvm: fix double free on tx path (bsc#1249841). - CVE-2022-50252: igb: Do not free q_vector unless new one was allocated (bsc#1249847). - CVE-2025-38617: net/packet: fix a race in packet_set_ring() and packet_notifier() (bsc#1249208). - CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207). - CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631). The following non security issue was fixed: - bsc#1249208: fix livepatching target module name (bsc#1252946)

Exploit probability Not scored
Published November 12, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP3 kernel-livepatch-SLE15-SP3_Update_60

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:4064-1

This update for the SUSE Linux Enterprise kernel 5.3.18-150300.59.215 fixes various security issues The following security issues were fixed: - CVE-2022-50248: wifi: iwlwifi: mvm: fix double free on tx path (bsc#1249841). - CVE-2022-50252: igb: Do not free q_vector unless new one was allocated (bsc#1249847). - CVE-2025-38617: net/packet: fix a race in packet_set_ring() and packet_notifier() (bsc#1249208). - CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1249207). - CVE-2025-38664: ice: Fix a null pointer dereference in ice_copy_and_init_pkg() (bsc#1248631). The following non security issue was fixed: - bsc#1249208: fix livepatching target module name (bsc#1252946)

View original source

05 / REFERENCES

Further evidence