FlawAtlas
Search the atlas
SUSE-SU-2026:1049-1 Not scored

Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise 15 SP5)

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.100 fixes various security issues The following security issues were fixed: - CVE-2022-50697: mrp: introduce active flags to prevent UAF when applicant uninit (bsc#1255595). - CVE-2023-53257: wifi: mac80211: check S1G action frame size (bsc#1250730). - CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254755). - CVE-2025-21738: ata: libata-sff: ensure that we cannot write outside the allocated buffer (bsc#1257118). - CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1257629). - CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247240). - CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). - CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). - CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). - CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624).

Exploit probability Not scored
Published March 26, 2026
Required by Not available
Last source change March 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP5 kernel-livepatch-SLE15-SP5_Update_25

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1049-1

This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.100 fixes various security issues The following security issues were fixed: - CVE-2022-50697: mrp: introduce active flags to prevent UAF when applicant uninit (bsc#1255595). - CVE-2023-53257: wifi: mac80211: check S1G action frame size (bsc#1250730). - CVE-2023-53781: smc: Fix use-after-free in tcp_write_timer_handler() (bsc#1254755). - CVE-2025-21738: ata: libata-sff: ensure that we cannot write outside the allocated buffer (bsc#1257118). - CVE-2025-38159: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (bsc#1257629). - CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247240). - CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1255053). - CVE-2025-68284: libceph: prevent potential out-of-bounds writes in handle_auth_session_key() (bsc#1255378). - CVE-2025-68285: libceph: fix potential use-after-free in have_mon_and_osd_map() (bsc#1255402). - CVE-2025-68813: ipvs: fix ipv4 null-ptr-deref in route error path (bsc#1256644). - CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256624).

View original source

05 / REFERENCES

Further evidence