FlawAtlas
Search the atlas
SUSE-SU-2026:2839-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).

Exploit probability Not scored
Published July 10, 2026
Required by Not available
Last source change July 11, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-syms
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-trace
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-xen
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-default
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-docs
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-ec2
SUSE:Linux Enterprise Server 11 SP4 LTSS EXTREME CORE kernel-source

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2839-1

The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).

View original source

05 / REFERENCES

Further evidence