Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 15 SP6)
This update for the SUSE Linux Enterprise kernel 6.4.0-150600.23.30 fixes various security issues The following security issues were fixed: - CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1245778). - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882). - CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). - CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the SUSE Linux Enterprise kernel 6.4.0-150600.23.30 fixes various security issues The following security issues were fixed: - CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1245778). - CVE-2025-23145: mptcp: fix NULL pointer in can_accept_new_subflow (bsc#1242882). - CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). - CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1242882
- https://bugzilla.suse.com/1245778
- https://bugzilla.suse.com/1248672
- https://bugzilla.suse.com/1249537
- https://www.suse.com/security/cve/CVE-2024-53141
- https://www.suse.com/security/cve/CVE-2025-23145
- https://www.suse.com/security/cve/CVE-2025-38500
- https://www.suse.com/security/cve/CVE-2025-38616
- https://www.suse.com/support/update/announcement/2025/suse-su-20254261-1/