Security update for the Linux Kernel
The SUSE Linux Enterprise 15 SP3 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50282: chardev: fix error handling in cdev_device_add() (bsc#1249739). - CVE-2022-50630: mm: hugetlb: fix UAF in hugetlb_handle_userfault (bsc#1254785). - CVE-2022-50700: wifi: ath10k: Delay the unmapping of the buffer (bsc#1255576). - CVE-2022-50717: nvmet-tcp: add bounds check on Transfer Tag (bsc#1255844). - CVE-2022-50726: net/mlx5: Fix possible use-after-free in async command interface (bsc#1256040). - CVE-2022-50736: RDMA/siw: Fix immediate work request flush to completion queue (bsc#1256137). - CVE-2022-50756: nvme-core: replace ctrl page size with a macro (bsc#1256216). - CVE-2023-53215: sched/fair: Don't balance task to its current running CPU (bsc#1250397). - CVE-2023-53254: cacheinfo: Fix shared_cpu_map to handle shared caches at different levels (bsc#1249871). - CVE-2023-53761: USB: usbtmc: Fix direction for 0-length ioctl control messages (bsc#1255002). - CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254751). - CVE-2023-54142: gtp: Fix use-after-free in __gtp_encap_destroy() (bsc#1256095). - CVE-2023-54168: RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() (bsc#1256053). - CVE-2023-54243: netfilter: ebtables: fix table blob use-after-free (bsc#1255908). - CVE-2025-38068: crypto: lzo - Fix compression buffer overrun (bsc#1245210). - CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1245751). - CVE-2025-40019: crypto: essiv - Check ssize for decryption and in-place encryption (bsc#1252678). - CVE-2025-40215: kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959). - CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520). - CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813). - CVE-2025-40277: drm/vmwgfx: Validate command header size against (bsc#1254894). - CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847). - CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256641). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256779).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 15 SP3 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50282: chardev: fix error handling in cdev_device_add() (bsc#1249739). - CVE-2022-50630: mm: hugetlb: fix UAF in hugetlb_handle_userfault (bsc#1254785). - CVE-2022-50700: wifi: ath10k: Delay the unmapping of the buffer (bsc#1255576). - CVE-2022-50717: nvmet-tcp: add bounds check on Transfer Tag (bsc#1255844). - CVE-2022-50726: net/mlx5: Fix possible use-after-free in async command interface (bsc#1256040). - CVE-2022-50736: RDMA/siw: Fix immediate work request flush to completion queue (bsc#1256137). - CVE-2022-50756: nvme-core: replace ctrl page size with a macro (bsc#1256216). - CVE-2023-53215: sched/fair: Don't balance task to its current running CPU (bsc#1250397). - CVE-2023-53254: cacheinfo: Fix shared_cpu_map to handle shared caches at different levels (bsc#1249871). - CVE-2023-53761: USB: usbtmc: Fix direction for 0-length ioctl control messages (bsc#1255002). - CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254751). - CVE-2023-54142: gtp: Fix use-after-free in __gtp_encap_destroy() (bsc#1256095). - CVE-2023-54168: RDMA/mlx4: Prevent shift wrapping in set_user_sq_size() (bsc#1256053). - CVE-2023-54243: netfilter: ebtables: fix table blob use-after-free (bsc#1255908). - CVE-2025-38068: crypto: lzo - Fix compression buffer overrun (bsc#1245210). - CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1245751). - CVE-2025-40019: crypto: essiv - Check ssize for decryption and in-place encryption (bsc#1252678). - CVE-2025-40215: kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959). - CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520). - CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813). - CVE-2025-40277: drm/vmwgfx: Validate command header size against (bsc#1254894). - CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847). - CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256641). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256779).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1065729
- https://bugzilla.suse.com/1196823
- https://bugzilla.suse.com/1204957
- https://bugzilla.suse.com/1206889
- https://bugzilla.suse.com/1207051
- https://bugzilla.suse.com/1207088
- https://bugzilla.suse.com/1207653
- https://bugzilla.suse.com/1209799
- https://bugzilla.suse.com/1213653
- https://bugzilla.suse.com/1213969
- https://bugzilla.suse.com/1225109
- https://bugzilla.suse.com/1228015
- https://bugzilla.suse.com/1245210
- https://bugzilla.suse.com/1245751
- https://bugzilla.suse.com/1249739
- https://bugzilla.suse.com/1249871
- https://bugzilla.suse.com/1250397
- https://bugzilla.suse.com/1252678
- https://bugzilla.suse.com/1254520
- https://bugzilla.suse.com/1254592
- https://bugzilla.suse.com/1254614
- https://bugzilla.suse.com/1254615
- https://bugzilla.suse.com/1254632
- https://bugzilla.suse.com/1254634
- https://bugzilla.suse.com/1254686
- https://bugzilla.suse.com/1254711
- https://bugzilla.suse.com/1254751
- https://bugzilla.suse.com/1254763
- https://bugzilla.suse.com/1254775
- https://bugzilla.suse.com/1254785
- https://bugzilla.suse.com/1254792
- https://bugzilla.suse.com/1254813
- https://bugzilla.suse.com/1254847
- https://bugzilla.suse.com/1254851
- https://bugzilla.suse.com/1254894
- https://bugzilla.suse.com/1254902
- https://bugzilla.suse.com/1254959
- https://bugzilla.suse.com/1255002
- https://bugzilla.suse.com/1255565
- https://bugzilla.suse.com/1255576
- https://bugzilla.suse.com/1255607
- https://bugzilla.suse.com/1255609
- https://bugzilla.suse.com/1255636
- https://bugzilla.suse.com/1255844
- https://bugzilla.suse.com/1255901
- https://bugzilla.suse.com/1255908
- https://bugzilla.suse.com/1255919
- https://bugzilla.suse.com/1256040
- https://bugzilla.suse.com/1256045
- https://bugzilla.suse.com/1256048
- https://bugzilla.suse.com/1256049
- https://bugzilla.suse.com/1256053
- https://bugzilla.suse.com/1256056
- https://bugzilla.suse.com/1256064
- https://bugzilla.suse.com/1256095
- https://bugzilla.suse.com/1256127
- https://bugzilla.suse.com/1256132
- https://bugzilla.suse.com/1256136
- https://bugzilla.suse.com/1256137
- https://bugzilla.suse.com/1256143
- https://bugzilla.suse.com/1256154
- https://bugzilla.suse.com/1256165
- https://bugzilla.suse.com/1256194
- https://bugzilla.suse.com/1256203
- https://bugzilla.suse.com/1256207
- https://bugzilla.suse.com/1256208
- https://bugzilla.suse.com/1256216
- https://bugzilla.suse.com/1256230
- https://bugzilla.suse.com/1256242
- https://bugzilla.suse.com/1256248
- https://bugzilla.suse.com/1256333
- https://bugzilla.suse.com/1256344
- https://bugzilla.suse.com/1256353
- https://bugzilla.suse.com/1256426
- https://bugzilla.suse.com/1256641
- https://bugzilla.suse.com/1256779
- https://www.suse.com/security/cve/CVE-2022-0854
- https://www.suse.com/security/cve/CVE-2022-48853
- https://www.suse.com/security/cve/CVE-2022-50282
- https://www.suse.com/security/cve/CVE-2022-50623
- https://www.suse.com/security/cve/CVE-2022-50630
- https://www.suse.com/security/cve/CVE-2022-50635
- https://www.suse.com/security/cve/CVE-2022-50640
- https://www.suse.com/security/cve/CVE-2022-50641
- https://www.suse.com/security/cve/CVE-2022-50644
- https://www.suse.com/security/cve/CVE-2022-50646
- https://www.suse.com/security/cve/CVE-2022-50649
- https://www.suse.com/security/cve/CVE-2022-50668
- https://www.suse.com/security/cve/CVE-2022-50671
- https://www.suse.com/security/cve/CVE-2022-50678
- https://www.suse.com/security/cve/CVE-2022-50700
- https://www.suse.com/security/cve/CVE-2022-50703
- https://www.suse.com/security/cve/CVE-2022-50709
- https://www.suse.com/security/cve/CVE-2022-50717
- https://www.suse.com/security/cve/CVE-2022-50726
- https://www.suse.com/security/cve/CVE-2022-50730
- https://www.suse.com/security/cve/CVE-2022-50731
- https://www.suse.com/security/cve/CVE-2022-50733
- https://www.suse.com/security/cve/CVE-2022-50736
- https://www.suse.com/security/cve/CVE-2022-50742
- https://www.suse.com/security/cve/CVE-2022-50744
- https://www.suse.com/security/cve/CVE-2022-50756
- https://www.suse.com/security/cve/CVE-2022-50758
- https://www.suse.com/security/cve/CVE-2022-50767
- https://www.suse.com/security/cve/CVE-2022-50814
- https://www.suse.com/security/cve/CVE-2022-50821
- https://www.suse.com/security/cve/CVE-2022-50823
- https://www.suse.com/security/cve/CVE-2022-50827
- https://www.suse.com/security/cve/CVE-2022-50828
- https://www.suse.com/security/cve/CVE-2022-50840
- https://www.suse.com/security/cve/CVE-2022-50843
- https://www.suse.com/security/cve/CVE-2022-50850
- https://www.suse.com/security/cve/CVE-2022-50870
- https://www.suse.com/security/cve/CVE-2022-50876
- https://www.suse.com/security/cve/CVE-2022-50880
- https://www.suse.com/security/cve/CVE-2022-50884
- https://www.suse.com/security/cve/CVE-2022-50889
- https://www.suse.com/security/cve/CVE-2023-23559
- https://www.suse.com/security/cve/CVE-2023-4132
- https://www.suse.com/security/cve/CVE-2023-53215
- https://www.suse.com/security/cve/CVE-2023-53254
- https://www.suse.com/security/cve/CVE-2023-53761
- https://www.suse.com/security/cve/CVE-2023-53781
- https://www.suse.com/security/cve/CVE-2023-54019
- https://www.suse.com/security/cve/CVE-2023-54024
- https://www.suse.com/security/cve/CVE-2023-54110
- https://www.suse.com/security/cve/CVE-2023-54142
- https://www.suse.com/security/cve/CVE-2023-54168
- https://www.suse.com/security/cve/CVE-2023-54170
- https://www.suse.com/security/cve/CVE-2023-54242
- https://www.suse.com/security/cve/CVE-2023-54243
- https://www.suse.com/security/cve/CVE-2023-54270
- https://www.suse.com/security/cve/CVE-2025-38068
- https://www.suse.com/security/cve/CVE-2025-38159
- https://www.suse.com/security/cve/CVE-2025-40019
- https://www.suse.com/security/cve/CVE-2025-40215
- https://www.suse.com/security/cve/CVE-2025-40220
- https://www.suse.com/security/cve/CVE-2025-40233
- https://www.suse.com/security/cve/CVE-2025-40256
- https://www.suse.com/security/cve/CVE-2025-40277
- https://www.suse.com/security/cve/CVE-2025-40280
- https://www.suse.com/security/cve/CVE-2025-40331
- https://www.suse.com/security/cve/CVE-2025-68813
- https://www.suse.com/security/cve/CVE-2025-71120
- https://www.suse.com/support/update/announcement/2026/suse-su-20260369-1/