Security update for the Linux Kernel
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018). - CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638). - CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668). - CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). - CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848). - CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126). - CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018). - CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638). - CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600). - CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668). - CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). - CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634). - CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848). - CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126). - CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1260018
- https://bugzilla.suse.com/1261638
- https://bugzilla.suse.com/1263600
- https://bugzilla.suse.com/1263668
- https://bugzilla.suse.com/1263995
- https://bugzilla.suse.com/1264634
- https://bugzilla.suse.com/1264848
- https://bugzilla.suse.com/1265126
- https://bugzilla.suse.com/1266001
- https://www.suse.com/security/cve/CVE-2026-23271
- https://www.suse.com/security/cve/CVE-2026-31402
- https://www.suse.com/security/cve/CVE-2026-31607
- https://www.suse.com/security/cve/CVE-2026-31685
- https://www.suse.com/security/cve/CVE-2026-43037
- https://www.suse.com/security/cve/CVE-2026-43126
- https://www.suse.com/security/cve/CVE-2026-43190
- https://www.suse.com/security/cve/CVE-2026-43437
- https://www.suse.com/security/cve/CVE-2026-43499
- https://www.suse.com/security/cve/CVE-2026-46243
- https://www.suse.com/support/update/announcement/2026/suse-su-20262317-1/