FlawAtlas
Search the atlas
SUSE-SU-2026:1606-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-38234: sched/rt: Fix race in push_rt_task (bsc#1246057). - CVE-2026-23103: ipvlan: Make the addrs_lock be per port (bsc#1257773). - CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259797). - CVE-2026-23272: netfilter: nf_tables: unconditionally bump set-nelems before insertion (bsc#1260009). - CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260005). - CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260562). The following non security issues were fixed: - nvme-fc: use ctrl state getter (git-fixes bsc#1215492). - nvme-pci: fix queue unquiesce check on slot_reset (git-fixes). - nvme-pci: skip nvme_write_sq_db on empty rqlist (git-fixes). - PCI: dwc: ep: Return -ENOMEM for allocation failures (git-fixes). - PCI: Fix lock symmetry in pci_slot_unlock() (git-fixes). - PCI: Fix pci_slot_trylock() error handling (git-fixes). - PCI: tegra194: Fix duplicate PLL disable in pex_ep_event_pex_rst_assert() (git-fixes). - PCI/ACS: Fix 'pci=config_acs=' parameter (git-fixes). - x86/platform/uv: Handle deconfigured sockets (bsc#1260347).

Exploit probability Not scored
Published April 24, 2026
Required by Not available
Last source change April 25, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-docs
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-syms
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-default-base
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-obs-build
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-syms
SUSE:Linux Enterprise Live Patching 15 SP5 kernel-livepatch-SLE15-SP5_Update_37
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-docs
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-syms
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-source
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-docs
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-source
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-syms
SUSE:Linux Enterprise Live Patching 15 SP5 kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-default-base
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-64kb
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-default
SUSE:Linux Enterprise Micro 5.5 kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-64kb
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-obs-build
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-zfcpdump
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-default-base
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-docs
SUSE:Linux Enterprise Server 15 SP5-LTSS kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-64kb
SUSE:Linux Enterprise Server for SAP Applications 15 SP5 kernel-default
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS kernel-obs-build
SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS kernel-source

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1606-1

The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-38234: sched/rt: Fix race in push_rt_task (bsc#1246057). - CVE-2026-23103: ipvlan: Make the addrs_lock be per port (bsc#1257773). - CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259797). - CVE-2026-23272: netfilter: nf_tables: unconditionally bump set-nelems before insertion (bsc#1260009). - CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260005). - CVE-2026-23317: drm/vmwgfx: Return the correct value in vmw_translate_ptr functions (bsc#1260562). The following non security issues were fixed: - nvme-fc: use ctrl state getter (git-fixes bsc#1215492). - nvme-pci: fix queue unquiesce check on slot_reset (git-fixes). - nvme-pci: skip nvme_write_sq_db on empty rqlist (git-fixes). - PCI: dwc: ep: Return -ENOMEM for allocation failures (git-fixes). - PCI: Fix lock symmetry in pci_slot_unlock() (git-fixes). - PCI: Fix pci_slot_trylock() error handling (git-fixes). - PCI: tegra194: Fix duplicate PLL disable in pex_ep_event_pex_rst_assert() (git-fixes). - PCI/ACS: Fix 'pci=config_acs=' parameter (git-fixes). - x86/platform/uv: Handle deconfigured sockets (bsc#1260347).

View original source

05 / REFERENCES

Further evidence