Security update for the Linux Kernel
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). - CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). - CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1255416
- https://bugzilla.suse.com/1264610
- https://bugzilla.suse.com/1265421
- https://bugzilla.suse.com/1266214
- https://bugzilla.suse.com/1266969
- https://bugzilla.suse.com/1267205
- https://bugzilla.suse.com/1267531
- https://bugzilla.suse.com/1267684
- https://bugzilla.suse.com/1269100
- https://bugzilla.suse.com/1269574
- https://bugzilla.suse.com/1270059
- https://www.suse.com/security/cve/CVE-2025-68324
- https://www.suse.com/security/cve/CVE-2026-43198
- https://www.suse.com/security/cve/CVE-2026-45970
- https://www.suse.com/security/cve/CVE-2026-46090
- https://www.suse.com/security/cve/CVE-2026-46113
- https://www.suse.com/security/cve/CVE-2026-46266
- https://www.suse.com/security/cve/CVE-2026-46331
- https://www.suse.com/security/cve/CVE-2026-52918
- https://www.suse.com/security/cve/CVE-2026-53253
- https://www.suse.com/security/cve/CVE-2026-53359
- https://www.suse.com/support/update/announcement/2026/suse-su-20262839-1/