Security update for the Linux Kernel (Live Patch 73 for SUSE Linux Enterprise 12 SP5)
This update for the SUSE Linux Enterprise Kernel 4.12.14-122.275 fixes various security issues The following security issues were fixed: - CVE-2023-53794: cifs: fix session state check in reconnect to avoid use-after-free issue (bsc#1255235). - CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036). - CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252689). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256780). - CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257238). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1258051). - CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258784).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the SUSE Linux Enterprise Kernel 4.12.14-122.275 fixes various security issues The following security issues were fixed: - CVE-2023-53794: cifs: fix session state check in reconnect to avoid use-after-free issue (bsc#1255235). - CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036). - CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252689). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256780). - CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257238). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1258051). - CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258784).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1252036
- https://bugzilla.suse.com/1252689
- https://bugzilla.suse.com/1255235
- https://bugzilla.suse.com/1256780
- https://bugzilla.suse.com/1257238
- https://bugzilla.suse.com/1258051
- https://bugzilla.suse.com/1258784
- https://www.suse.com/security/cve/CVE-2023-53794
- https://www.suse.com/security/cve/CVE-2025-39973
- https://www.suse.com/security/cve/CVE-2025-40018
- https://www.suse.com/security/cve/CVE-2025-71120
- https://www.suse.com/security/cve/CVE-2026-22999
- https://www.suse.com/security/cve/CVE-2026-23074
- https://www.suse.com/security/cve/CVE-2026-23209
- https://www.suse.com/support/update/announcement/2026/suse-su-20261304-1/