FlawAtlas
Search the atlas
SUSE-SU-2025:4167-1 Not scored

Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 15 SP7)

This update for the SUSE Linux Enterprise kernel 6.4.0-150700.5 fixes various security issues The following security issues were fixed: - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882). - CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). - CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537).

Exploit probability Not scored
Published November 22, 2025
Required by Not available
Last source change March 23, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP6 kernel-livepatch-SLE15-SP6-RT_Update_7
SUSE:Linux Enterprise Live Patching 15 SP7 kernel-livepatch-SLE15-SP7-RT_Update_0

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2025:4167-1

This update for the SUSE Linux Enterprise kernel 6.4.0-150700.5 fixes various security issues The following security issues were fixed: - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882). - CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). - CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537).

View original source

05 / REFERENCES

Further evidence