FlawAtlas
Search the atlas
SUSE-SU-2026:3369-1 Not scored

Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise 15 SP7)

This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.63 fixes various security issues: The following security issues were fixed: - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). - CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370).

Exploit probability Not scored
Published July 28, 2026
Required by Not available
Last source change July 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP7 kernel-livepatch-SLE15-SP7_Update_17

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:3369-1

This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.63 fixes various security issues: The following security issues were fixed: - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (ipv6_frag_escape) (bsc#1269495). - CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370).

View original source

05 / REFERENCES

Further evidence