Security update for the Linux Kernel
The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: Add workaround for Cortex-A76 erratum 1286807 (bsc#1266290). - CVE-2025-40253: s390/ctcm: Fix double-kfree (bsc#1255084). - CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). - CVE-2026-3150: bcache: fix cached_dev.sb_bio use-after-free and crash (bsc#1263169). - CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018). - CVE-2026-23279: wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (bsc#1260468). - CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). - CVE-2026-23367: wifi: radiotap: reject radiotap with unknown bits (bsc#1260731). - CVE-2026-23396: wifi: mac80211: fix NULL deref in mesh_matches_local() (bsc#1260729). - CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). - CVE-2026-23448: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check (bsc#1261750). - CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700). - CVE-2026-31415: ipv6: avoid overflows in ip6_datagram_send_ctl() (bsc#1262099). - CVE-2026-31421: net/sched: cls_fw: fix NULL pointer dereference on shared blocks (bsc#1262061). - CVE-2026-31447: ext4: reject mount if bigalloc with s_first_data_block != 0 (bsc#1262614). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). - CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). - CVE-2026-31498: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (bsc#1262751). - CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). - CVE-2026-31515: af_key: validate families in pfkey_send_migrate() (bsc#1262752). - CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). - CVE-2026-31532: can: af_can: export can_sock_destruct() (bsc#1262757). - CVE-2026-31540: drm/i915/gt: Check set_default_submission() before deferencing (bsc#1263011). - CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). - CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165). - CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). - CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). - CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). - CVE-2026-31668: seg6: separate dst_cache for input and output paths in seg6 lwtunnel (bsc#1263140). - CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). - CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-31778: ALSA: caiaq: fix stack out-of-bounds read in init_card (bsc#1263923). - CVE-2026-43020: Bluetooth: MGMT: validate LTK enc_size on load (bsc#1264006). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). - CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). - CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- leak (bsc#1264091). - CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43140: HID: magicmouse: Do not crash on missing msc->input (bsc#1264630). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). - CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). - CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). - CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). - CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). - CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). - CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). - CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). - CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960). - CVE-2026-45835: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (bsc#1266411). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). - CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). - CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). - CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). - CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). - CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). - CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). - CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size (bsc#1267713). - CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). - CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non security issues were fixed: - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes). - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes). - bcache: fix uninitialized closure object (git-fixes). - check-for-config-changes: Exclude CC_MS_EXTENSIONS. - check-for-config-changes: Exclude HAVE_CFI_ICALL_NORMALIZE_INTEGERS{,_RUSTC}. - kvm/svm: PKU not currently supported (bsc#1263887). - KVM: x86: Handle PKU CPUID adjustment in VMX code (bsc#1263887). - mkspec: Add signature to source list only when it exists. - net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (git-fixes).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: Add workaround for Cortex-A76 erratum 1286807 (bsc#1266290). - CVE-2025-40253: s390/ctcm: Fix double-kfree (bsc#1255084). - CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). - CVE-2026-3150: bcache: fix cached_dev.sb_bio use-after-free and crash (bsc#1263169). - CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018). - CVE-2026-23279: wifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame() (bsc#1260468). - CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). - CVE-2026-23367: wifi: radiotap: reject radiotap with unknown bits (bsc#1260731). - CVE-2026-23396: wifi: mac80211: fix NULL deref in mesh_matches_local() (bsc#1260729). - CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). - CVE-2026-23448: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check (bsc#1261750). - CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700). - CVE-2026-31415: ipv6: avoid overflows in ip6_datagram_send_ctl() (bsc#1262099). - CVE-2026-31421: net/sched: cls_fw: fix NULL pointer dereference on shared blocks (bsc#1262061). - CVE-2026-31447: ext4: reject mount if bigalloc with s_first_data_block != 0 (bsc#1262614). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). - CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). - CVE-2026-31498: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (bsc#1262751). - CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). - CVE-2026-31515: af_key: validate families in pfkey_send_migrate() (bsc#1262752). - CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). - CVE-2026-31532: can: af_can: export can_sock_destruct() (bsc#1262757). - CVE-2026-31540: drm/i915/gt: Check set_default_submission() before deferencing (bsc#1263011). - CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). - CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165). - CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). - CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). - CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). - CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). - CVE-2026-31668: seg6: separate dst_cache for input and output paths in seg6 lwtunnel (bsc#1263140). - CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). - CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). - CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). - CVE-2026-31778: ALSA: caiaq: fix stack out-of-bounds read in init_card (bsc#1263923). - CVE-2026-43020: Bluetooth: MGMT: validate LTK enc_size on load (bsc#1264006). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995). - CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). - CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- leak (bsc#1264091). - CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). - CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). - CVE-2026-43140: HID: magicmouse: Do not crash on missing msc->input (bsc#1264630). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). - CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). - CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). - CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). - CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). - CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). - CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). - CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). - CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960). - CVE-2026-45835: Bluetooth: L2CAP: Fix null-ptr-deref in l2cap_sock_new_connection_cb() (bsc#1266411). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). - CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). - CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). - CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). - CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). - CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). - CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). - CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size (bsc#1267713). - CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). - CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non security issues were fixed: - arm64: tlb: Allow XZR argument to TLBI ops (git-fixes). - arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes). - bcache: fix uninitialized closure object (git-fixes). - check-for-config-changes: Exclude CC_MS_EXTENSIONS. - check-for-config-changes: Exclude HAVE_CFI_ICALL_NORMALIZE_INTEGERS{,_RUSTC}. - kvm/svm: PKU not currently supported (bsc#1263887). - KVM: x86: Handle PKU CPUID adjustment in VMX code (bsc#1263887). - mkspec: Add signature to source list only when it exists. - net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (git-fixes).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1255084
- https://bugzilla.suse.com/1255416
- https://bugzilla.suse.com/1256668
- https://bugzilla.suse.com/1258538
- https://bugzilla.suse.com/1260018
- https://bugzilla.suse.com/1260468
- https://bugzilla.suse.com/1260502
- https://bugzilla.suse.com/1260729
- https://bugzilla.suse.com/1260731
- https://bugzilla.suse.com/1261700
- https://bugzilla.suse.com/1261750
- https://bugzilla.suse.com/1262061
- https://bugzilla.suse.com/1262099
- https://bugzilla.suse.com/1262614
- https://bugzilla.suse.com/1262620
- https://bugzilla.suse.com/1262656
- https://bugzilla.suse.com/1262751
- https://bugzilla.suse.com/1262752
- https://bugzilla.suse.com/1262755
- https://bugzilla.suse.com/1262757
- https://bugzilla.suse.com/1262993
- https://bugzilla.suse.com/1263006
- https://bugzilla.suse.com/1263011
- https://bugzilla.suse.com/1263012
- https://bugzilla.suse.com/1263115
- https://bugzilla.suse.com/1263140
- https://bugzilla.suse.com/1263143
- https://bugzilla.suse.com/1263152
- https://bugzilla.suse.com/1263165
- https://bugzilla.suse.com/1263169
- https://bugzilla.suse.com/1263319
- https://bugzilla.suse.com/1263562
- https://bugzilla.suse.com/1263568
- https://bugzilla.suse.com/1263578
- https://bugzilla.suse.com/1263790
- https://bugzilla.suse.com/1263887
- https://bugzilla.suse.com/1263923
- https://bugzilla.suse.com/1263930
- https://bugzilla.suse.com/1263932
- https://bugzilla.suse.com/1263934
- https://bugzilla.suse.com/1263945
- https://bugzilla.suse.com/1263995
- https://bugzilla.suse.com/1264006
- https://bugzilla.suse.com/1264076
- https://bugzilla.suse.com/1264091
- https://bugzilla.suse.com/1264097
- https://bugzilla.suse.com/1264409
- https://bugzilla.suse.com/1264470
- https://bugzilla.suse.com/1264551
- https://bugzilla.suse.com/1264595
- https://bugzilla.suse.com/1264603
- https://bugzilla.suse.com/1264610
- https://bugzilla.suse.com/1264630
- https://bugzilla.suse.com/1264669
- https://bugzilla.suse.com/1264671
- https://bugzilla.suse.com/1264716
- https://bugzilla.suse.com/1264719
- https://bugzilla.suse.com/1264722
- https://bugzilla.suse.com/1264763
- https://bugzilla.suse.com/1265020
- https://bugzilla.suse.com/1265456
- https://bugzilla.suse.com/1265960
- https://bugzilla.suse.com/1266001
- https://bugzilla.suse.com/1266214
- https://bugzilla.suse.com/1266238
- https://bugzilla.suse.com/1266290
- https://bugzilla.suse.com/1266307
- https://bugzilla.suse.com/1266390
- https://bugzilla.suse.com/1266395
- https://bugzilla.suse.com/1266400
- https://bugzilla.suse.com/1266411
- https://bugzilla.suse.com/1266697
- https://bugzilla.suse.com/1266704
- https://bugzilla.suse.com/1266711
- https://bugzilla.suse.com/1266826
- https://bugzilla.suse.com/1266901
- https://bugzilla.suse.com/1266969
- https://bugzilla.suse.com/1267205
- https://bugzilla.suse.com/1267218
- https://bugzilla.suse.com/1267220
- https://bugzilla.suse.com/1267369
- https://bugzilla.suse.com/1267387
- https://bugzilla.suse.com/1267531
- https://bugzilla.suse.com/1267624
- https://bugzilla.suse.com/1267651
- https://bugzilla.suse.com/1267652
- https://bugzilla.suse.com/1267685
- https://bugzilla.suse.com/1267713
- https://bugzilla.suse.com/1267726
- https://bugzilla.suse.com/1267732
- https://bugzilla.suse.com/1267816
- https://www.suse.com/security/cve/CVE-2025-10263
- https://www.suse.com/security/cve/CVE-2025-40253
- https://www.suse.com/security/cve/CVE-2025-68324
- https://www.suse.com/security/cve/CVE-2025-68822
- https://www.suse.com/security/cve/CVE-2026-23271
- https://www.suse.com/security/cve/CVE-2026-23279
- https://www.suse.com/security/cve/CVE-2026-23303
- https://www.suse.com/security/cve/CVE-2026-23367
- https://www.suse.com/security/cve/CVE-2026-23396
- https://www.suse.com/security/cve/CVE-2026-23444
- https://www.suse.com/security/cve/CVE-2026-23448
- https://www.suse.com/security/cve/CVE-2026-31405
- https://www.suse.com/security/cve/CVE-2026-31415
- https://www.suse.com/security/cve/CVE-2026-31421
- https://www.suse.com/security/cve/CVE-2026-31447
- https://www.suse.com/security/cve/CVE-2026-31452
- https://www.suse.com/security/cve/CVE-2026-31464
- https://www.suse.com/security/cve/CVE-2026-31469
- https://www.suse.com/security/cve/CVE-2026-31498
- https://www.suse.com/security/cve/CVE-2026-3150
- https://www.suse.com/security/cve/CVE-2026-31500
- https://www.suse.com/security/cve/CVE-2026-31515
- https://www.suse.com/security/cve/CVE-2026-31516
- https://www.suse.com/security/cve/CVE-2026-31532
- https://www.suse.com/security/cve/CVE-2026-31540
- https://www.suse.com/security/cve/CVE-2026-31546
- https://www.suse.com/security/cve/CVE-2026-31588
- https://www.suse.com/security/cve/CVE-2026-31590
- https://www.suse.com/security/cve/CVE-2026-31596
- https://www.suse.com/security/cve/CVE-2026-31629
- https://www.suse.com/security/cve/CVE-2026-31664
- https://www.suse.com/security/cve/CVE-2026-31668
- https://www.suse.com/security/cve/CVE-2026-31671
- https://www.suse.com/security/cve/CVE-2026-31673
- https://www.suse.com/security/cve/CVE-2026-31674
- https://www.suse.com/security/cve/CVE-2026-31678
- https://www.suse.com/security/cve/CVE-2026-31759
- https://www.suse.com/security/cve/CVE-2026-31778
- https://www.suse.com/security/cve/CVE-2026-43020
- https://www.suse.com/security/cve/CVE-2026-43024
- https://www.suse.com/security/cve/CVE-2026-43026
- https://www.suse.com/security/cve/CVE-2026-43028
- https://www.suse.com/security/cve/CVE-2026-43037
- https://www.suse.com/security/cve/CVE-2026-43038
- https://www.suse.com/security/cve/CVE-2026-43040
- https://www.suse.com/security/cve/CVE-2026-43052
- https://www.suse.com/security/cve/CVE-2026-43077
- https://www.suse.com/security/cve/CVE-2026-43140
- https://www.suse.com/security/cve/CVE-2026-43158
- https://www.suse.com/security/cve/CVE-2026-43187
- https://www.suse.com/security/cve/CVE-2026-43198
- https://www.suse.com/security/cve/CVE-2026-43206
- https://www.suse.com/security/cve/CVE-2026-43234
- https://www.suse.com/security/cve/CVE-2026-43338
- https://www.suse.com/security/cve/CVE-2026-43339
- https://www.suse.com/security/cve/CVE-2026-43359
- https://www.suse.com/security/cve/CVE-2026-43361
- https://www.suse.com/security/cve/CVE-2026-43407
- https://www.suse.com/security/cve/CVE-2026-43413
- https://www.suse.com/security/cve/CVE-2026-43414
- https://www.suse.com/security/cve/CVE-2026-43499
- https://www.suse.com/security/cve/CVE-2026-43503
- https://www.suse.com/security/cve/CVE-2026-45835
- https://www.suse.com/security/cve/CVE-2026-45841
- https://www.suse.com/security/cve/CVE-2026-45842
- https://www.suse.com/security/cve/CVE-2026-45843
- https://www.suse.com/security/cve/CVE-2026-45852
- https://www.suse.com/security/cve/CVE-2026-45870
- https://www.suse.com/security/cve/CVE-2026-45970
- https://www.suse.com/security/cve/CVE-2026-45983
- https://www.suse.com/security/cve/CVE-2026-46021
- https://www.suse.com/security/cve/CVE-2026-46024
- https://www.suse.com/security/cve/CVE-2026-46043
- https://www.suse.com/security/cve/CVE-2026-46090
- https://www.suse.com/security/cve/CVE-2026-46113
- https://www.suse.com/security/cve/CVE-2026-46116
- https://www.suse.com/security/cve/CVE-2026-46150
- https://www.suse.com/security/cve/CVE-2026-46157
- https://www.suse.com/security/cve/CVE-2026-46159
- https://www.suse.com/security/cve/CVE-2026-46160
- https://www.suse.com/security/cve/CVE-2026-46169
- https://www.suse.com/security/cve/CVE-2026-46181
- https://www.suse.com/security/cve/CVE-2026-46259
- https://www.suse.com/security/cve/CVE-2026-46273
- https://www.suse.com/support/update/announcement/2026/suse-su-20262450-1/