Security update for the Linux Kernel (Live Patch 67 for SUSE Linux Enterprise 12 SP5)
This update for the SUSE Linux Enterprise kernel 4.12.14-122.255 fixes various security issues The following security issues were fixed: - CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1258073). - CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). - CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). - CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the SUSE Linux Enterprise kernel 4.12.14-122.255 fixes various security issues The following security issues were fixed: - CVE-2025-38375: virtio-net: ensure the received length does not exceed allocated size (bsc#1258073). - CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1258655). - CVE-2026-23204: net/sched: cls_u32: use skb_header_pointer_careful() (bsc#1259126). - CVE-2026-31431: crypto: algif_aead - Revert to operating out-of-place (bsc#1263689).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1258073
- https://bugzilla.suse.com/1258655
- https://bugzilla.suse.com/1259126
- https://bugzilla.suse.com/1263689
- https://www.suse.com/security/cve/CVE-2025-38375
- https://www.suse.com/security/cve/CVE-2026-23004
- https://www.suse.com/security/cve/CVE-2026-23204
- https://www.suse.com/security/cve/CVE-2026-31431
- https://www.suse.com/support/update/announcement/2026/suse-su-20261780-1/