FlawAtlas
Search the atlas
SUSE-SU-2026:2914-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31773: Bluetooth: SMP: derive legacy responder STK authentication from MITM state (bsc#1264039). - CVE-2026-31781: drm/ioc32: stop speculation on the drm_compat_ioctl path (bsc#1264033). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43043: crypto: af-alg - fix NULL pointer dereference in scatterwalk (bsc#1264088). - CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request (bsc#1264073). - CVE-2026-43051: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (bsc#1264065). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). - CVE-2026-43117: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1264414). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43279: ALSA: usb-audio: Add sanity check for OOB writes at silencing (bsc#1264618). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45960: hfsplus: return error when node already exists in hfs_bnode_create (bsc#1266971). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46082: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (bsc#1267473). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46275: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (bsc#1267968). - CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super() (bsc#1267920). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). - CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size (bsc#1269786). - CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator (bsc#1269386). - CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow (bsc#1269904). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). The following non security issues were fixed: - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (git-fixes). - libceph: add non-asserting rbtree insertion helper (bsc#1269137).

Exploit probability Not scored
Published July 13, 2026
Required by Not available
Last source change July 14, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 12 SP5 kernel-default
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_85
SUSE:Linux Enterprise Server 12 SP5-LTSS kernel-default
SUSE:Linux Enterprise Server 12 SP5-LTSS kernel-source
SUSE:Linux Enterprise Server 12 SP5-LTSS kernel-syms
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 kernel-default
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 kernel-source
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 kernel-syms

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2914-1

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31773: Bluetooth: SMP: derive legacy responder STK authentication from MITM state (bsc#1264039). - CVE-2026-31781: drm/ioc32: stop speculation on the drm_compat_ioctl path (bsc#1264033). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43043: crypto: af-alg - fix NULL pointer dereference in scatterwalk (bsc#1264088). - CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request (bsc#1264073). - CVE-2026-43051: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (bsc#1264065). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). - CVE-2026-43117: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1264414). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43279: ALSA: usb-audio: Add sanity check for OOB writes at silencing (bsc#1264618). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45960: hfsplus: return error when node already exists in hfs_bnode_create (bsc#1266971). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46082: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (bsc#1267473). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46275: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (bsc#1267968). - CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super() (bsc#1267920). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). - CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size (bsc#1269786). - CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator (bsc#1269386). - CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow (bsc#1269904). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). The following non security issues were fixed: - btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (git-fixes). - libceph: add non-asserting rbtree insertion helper (bsc#1269137).

View original source

05 / REFERENCES

Further evidence