Security update for the Linux Kernel
The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50053: iavf: Fix reset error handling (bsc#1245038). - CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1. (bsc#1243603). - CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500 bsc#1262778). - CVE-2025-68185: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (bsc#1255135). - CVE-2025-71118: ACPICA: Avoid walking the Namespace if start_node is NULL (bsc#1256763). - CVE-2025-71238: scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1259186). - CVE-2026-23193: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (bsc#1258414). - CVE-2026-23216: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (bsc#1258447). - CVE-2026-23276: net: add xmit recursion limit to tunnel xmit functions (bsc#1260012). - CVE-2026-23290: net: usb: pegasus: validate USB endpoints (bsc#1260533). - CVE-2026-23292: scsi: target: Fix recursive locking in __configfs_open_file() (bsc#1260500). - CVE-2026-23293: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260486). - CVE-2026-23312: net: usb: kaweth: validate USB endpoints (bsc#1260561). - CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523). - CVE-2026-23378: act_ife: load meta modules before tcf_idr_check_alloc() (bsc#1260546). - CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566). - CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581). - CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779). - CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687). - CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703). - CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686). - CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781). - CVE-2026-23461: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (bsc#1261707). - CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710). - CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692). - CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636). - CVE-2026-31393: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (bsc#1261719). - CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645). - CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638). - CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796). - CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632). - CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (bsc#1261797). - CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752). - CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100). - CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054). - CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063). - CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053). - CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074). - CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086). - CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087). - CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673). - CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085). - CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095). - CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (bsc#1262734). - CVE-2026-31524: HID: asus: avoid memory leak in asus_report_fixup() (bsc#1262605). - CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723). - CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600). - CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582). - CVE-2026-31667: Input: uinput - fix circular locking dependency with ff-core (bsc#1263139). - CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556). - CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668). - CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882). - CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059). - CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181). - CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931). - CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469). - CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482). - CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848). - CVE-2026-43255: wifi: libertas: fix WARNING in usb_tx_block (bsc#1264473). - CVE-2026-43264: fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (bsc#1264424). - CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090). - CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126). The following non security issues were fixed: - list: add 'list_del_init_careful()' to go with 'list_empty_careful()' (bsc#1262778). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2022-50053: iavf: Fix reset error handling (bsc#1245038). - CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1. (bsc#1243603). - CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500 bsc#1262778). - CVE-2025-68185: nfs4_setup_readdir(): insufficient locking for ->d_parent->d_inode dereferencing (bsc#1255135). - CVE-2025-71118: ACPICA: Avoid walking the Namespace if start_node is NULL (bsc#1256763). - CVE-2025-71238: scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1259186). - CVE-2026-23193: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (bsc#1258414). - CVE-2026-23216: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (bsc#1258447). - CVE-2026-23276: net: add xmit recursion limit to tunnel xmit functions (bsc#1260012). - CVE-2026-23290: net: usb: pegasus: validate USB endpoints (bsc#1260533). - CVE-2026-23292: scsi: target: Fix recursive locking in __configfs_open_file() (bsc#1260500). - CVE-2026-23293: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260486). - CVE-2026-23312: net: usb: kaweth: validate USB endpoints (bsc#1260561). - CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523). - CVE-2026-23378: act_ife: load meta modules before tcf_idr_check_alloc() (bsc#1260546). - CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566). - CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581). - CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779). - CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687). - CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703). - CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686). - CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781). - CVE-2026-23461: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (bsc#1261707). - CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710). - CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692). - CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636). - CVE-2026-31393: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (bsc#1261719). - CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645). - CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638). - CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796). - CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632). - CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (bsc#1261797). - CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752). - CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100). - CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054). - CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063). - CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053). - CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074). - CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086). - CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087). - CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673). - CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085). - CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095). - CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv() (bsc#1262734). - CVE-2026-31524: HID: asus: avoid memory leak in asus_report_fixup() (bsc#1262605). - CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723). - CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600). - CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582). - CVE-2026-31667: Input: uinput - fix circular locking dependency with ff-core (bsc#1263139). - CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556). - CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668). - CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882). - CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059). - CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181). - CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931). - CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469). - CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482). - CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848). - CVE-2026-43255: wifi: libertas: fix WARNING in usb_tx_block (bsc#1264473). - CVE-2026-43264: fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (bsc#1264424). - CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090). - CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126). The following non security issues were fixed: - list: add 'list_del_init_careful()' to go with 'list_empty_careful()' (bsc#1262778). - ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718). - ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1232500
- https://bugzilla.suse.com/1243603
- https://bugzilla.suse.com/1245038
- https://bugzilla.suse.com/1255135
- https://bugzilla.suse.com/1256763
- https://bugzilla.suse.com/1256774
- https://bugzilla.suse.com/1258414
- https://bugzilla.suse.com/1258447
- https://bugzilla.suse.com/1258518
- https://bugzilla.suse.com/1258718
- https://bugzilla.suse.com/1258849
- https://bugzilla.suse.com/1258850
- https://bugzilla.suse.com/1258854
- https://bugzilla.suse.com/1258857
- https://bugzilla.suse.com/1259186
- https://bugzilla.suse.com/1259857
- https://bugzilla.suse.com/1260010
- https://bugzilla.suse.com/1260012
- https://bugzilla.suse.com/1260486
- https://bugzilla.suse.com/1260500
- https://bugzilla.suse.com/1260523
- https://bugzilla.suse.com/1260533
- https://bugzilla.suse.com/1260546
- https://bugzilla.suse.com/1260561
- https://bugzilla.suse.com/1260566
- https://bugzilla.suse.com/1261287
- https://bugzilla.suse.com/1261295
- https://bugzilla.suse.com/1261581
- https://bugzilla.suse.com/1261632
- https://bugzilla.suse.com/1261636
- https://bugzilla.suse.com/1261638
- https://bugzilla.suse.com/1261645
- https://bugzilla.suse.com/1261686
- https://bugzilla.suse.com/1261687
- https://bugzilla.suse.com/1261692
- https://bugzilla.suse.com/1261703
- https://bugzilla.suse.com/1261707
- https://bugzilla.suse.com/1261710
- https://bugzilla.suse.com/1261719
- https://bugzilla.suse.com/1261752
- https://bugzilla.suse.com/1261779
- https://bugzilla.suse.com/1261781
- https://bugzilla.suse.com/1261796
- https://bugzilla.suse.com/1261797
- https://bugzilla.suse.com/1262053
- https://bugzilla.suse.com/1262054
- https://bugzilla.suse.com/1262063
- https://bugzilla.suse.com/1262074
- https://bugzilla.suse.com/1262086
- https://bugzilla.suse.com/1262087
- https://bugzilla.suse.com/1262100
- https://bugzilla.suse.com/1262181
- https://bugzilla.suse.com/1262605
- https://bugzilla.suse.com/1262673
- https://bugzilla.suse.com/1262734
- https://bugzilla.suse.com/1262778
- https://bugzilla.suse.com/1263085
- https://bugzilla.suse.com/1263095
- https://bugzilla.suse.com/1263139
- https://bugzilla.suse.com/1263556
- https://bugzilla.suse.com/1263582
- https://bugzilla.suse.com/1263593
- https://bugzilla.suse.com/1263600
- https://bugzilla.suse.com/1263668
- https://bugzilla.suse.com/1263723
- https://bugzilla.suse.com/1263882
- https://bugzilla.suse.com/1263931
- https://bugzilla.suse.com/1264059
- https://bugzilla.suse.com/1264424
- https://bugzilla.suse.com/1264449
- https://bugzilla.suse.com/1264469
- https://bugzilla.suse.com/1264473
- https://bugzilla.suse.com/1264482
- https://bugzilla.suse.com/1264634
- https://bugzilla.suse.com/1264848
- https://bugzilla.suse.com/1265090
- https://bugzilla.suse.com/1265126
- https://bugzilla.suse.com/1265308
- https://www.suse.com/security/cve/CVE-2022-50053
- https://www.suse.com/security/cve/CVE-2023-20585
- https://www.suse.com/security/cve/CVE-2024-50082
- https://www.suse.com/security/cve/CVE-2025-68185
- https://www.suse.com/security/cve/CVE-2025-71108
- https://www.suse.com/security/cve/CVE-2025-71118
- https://www.suse.com/security/cve/CVE-2025-71238
- https://www.suse.com/security/cve/CVE-2026-23193
- https://www.suse.com/security/cve/CVE-2026-23209
- https://www.suse.com/security/cve/CVE-2026-23216
- https://www.suse.com/security/cve/CVE-2026-23268
- https://www.suse.com/security/cve/CVE-2026-23269
- https://www.suse.com/security/cve/CVE-2026-23273
- https://www.suse.com/security/cve/CVE-2026-23276
- https://www.suse.com/security/cve/CVE-2026-23290
- https://www.suse.com/security/cve/CVE-2026-23292
- https://www.suse.com/security/cve/CVE-2026-23293
- https://www.suse.com/security/cve/CVE-2026-23312
- https://www.suse.com/security/cve/CVE-2026-23340
- https://www.suse.com/security/cve/CVE-2026-23378
- https://www.suse.com/security/cve/CVE-2026-23391
- https://www.suse.com/security/cve/CVE-2026-23403
- https://www.suse.com/security/cve/CVE-2026-23404
- https://www.suse.com/security/cve/CVE-2026-23405
- https://www.suse.com/security/cve/CVE-2026-23408
- https://www.suse.com/security/cve/CVE-2026-23442
- https://www.suse.com/security/cve/CVE-2026-23449
- https://www.suse.com/security/cve/CVE-2026-23455
- https://www.suse.com/security/cve/CVE-2026-23456
- https://www.suse.com/security/cve/CVE-2026-23457
- https://www.suse.com/security/cve/CVE-2026-23458
- https://www.suse.com/security/cve/CVE-2026-23461
- https://www.suse.com/security/cve/CVE-2026-23462
- https://www.suse.com/security/cve/CVE-2026-23468
- https://www.suse.com/security/cve/CVE-2026-23472
- https://www.suse.com/security/cve/CVE-2026-31393
- https://www.suse.com/security/cve/CVE-2026-31400
- https://www.suse.com/security/cve/CVE-2026-31402
- https://www.suse.com/security/cve/CVE-2026-31403
- https://www.suse.com/security/cve/CVE-2026-31407
- https://www.suse.com/security/cve/CVE-2026-31408
- https://www.suse.com/security/cve/CVE-2026-31411
- https://www.suse.com/security/cve/CVE-2026-31416
- https://www.suse.com/security/cve/CVE-2026-31422
- https://www.suse.com/security/cve/CVE-2026-31423
- https://www.suse.com/security/cve/CVE-2026-31424
- https://www.suse.com/security/cve/CVE-2026-31425
- https://www.suse.com/security/cve/CVE-2026-31427
- https://www.suse.com/security/cve/CVE-2026-31428
- https://www.suse.com/security/cve/CVE-2026-31496
- https://www.suse.com/security/cve/CVE-2026-31504
- https://www.suse.com/security/cve/CVE-2026-31507
- https://www.suse.com/security/cve/CVE-2026-31512
- https://www.suse.com/security/cve/CVE-2026-31524
- https://www.suse.com/security/cve/CVE-2026-31602
- https://www.suse.com/security/cve/CVE-2026-31607
- https://www.suse.com/security/cve/CVE-2026-31649
- https://www.suse.com/security/cve/CVE-2026-31667
- https://www.suse.com/security/cve/CVE-2026-31675
- https://www.suse.com/security/cve/CVE-2026-31681
- https://www.suse.com/security/cve/CVE-2026-31685
- https://www.suse.com/security/cve/CVE-2026-31700
- https://www.suse.com/security/cve/CVE-2026-31738
- https://www.suse.com/security/cve/CVE-2026-31787
- https://www.suse.com/security/cve/CVE-2026-43025
- https://www.suse.com/security/cve/CVE-2026-43088
- https://www.suse.com/security/cve/CVE-2026-43110
- https://www.suse.com/security/cve/CVE-2026-43126
- https://www.suse.com/security/cve/CVE-2026-43190
- https://www.suse.com/security/cve/CVE-2026-43255
- https://www.suse.com/security/cve/CVE-2026-43264
- https://www.suse.com/security/cve/CVE-2026-43334
- https://www.suse.com/security/cve/CVE-2026-43437
- https://www.suse.com/security/cve/CVE-2026-46333
- https://www.suse.com/support/update/announcement/2026/suse-su-20262068-1/