SUSE-SU-2026:4433-1

Vulnerability from csaf_suse - Published: 2026-10-02 15:03 - Updated: 2026-10-03 08:37
Summary
Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7)
Severity
Important
Notes
Title of the patch: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7)
Description of the patch: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.72 fixes various security issues: The following security issues were fixed: - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273052). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273833). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273837). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277409). - CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277506).
Patchnames: SUSE-2026-4433,SUSE-SLE-Module-Live-Patching-15-SP7-2026-4433
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Product Identifier Version Remediation
Unresolved product id: SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64 —
Vendor Fix
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
Affected products
Recommended 1 product, the same list as for CVE-2026-63888
Threats
Impact important
References
URL Category
https://www.suse.com/support/security/rating/ external
https://ftp.suse.com/pub/projects/security/csaf/s… self
https://www.suse.com/support/update/announcement/… self
https://www.suse.com/support/update/announcement/… self
https://bugzilla.suse.com/1272391 self
https://bugzilla.suse.com/1273012 self
https://bugzilla.suse.com/1273052 self
https://bugzilla.suse.com/1273833 self
https://bugzilla.suse.com/1273837 self
https://bugzilla.suse.com/1275228 self
https://bugzilla.suse.com/1277409 self
https://bugzilla.suse.com/1277506 self
https://www.suse.com/security/cve/CVE-2026-63888/ self
https://www.suse.com/security/cve/CVE-2026-63920/ self
https://www.suse.com/security/cve/CVE-2026-64000/ self
https://www.suse.com/security/cve/CVE-2026-64114/ self
https://www.suse.com/security/cve/CVE-2026-64121/ self
https://www.suse.com/security/cve/CVE-2026-68121/ self
https://www.suse.com/security/cve/CVE-2026-74394/ self
https://www.suse.com/security/cve/CVE-2026-74612/ self
https://www.suse.com/security/cve/CVE-2026-63888 external
https://bugzilla.suse.com/1272390 external
https://bugzilla.suse.com/1272391 external
https://www.suse.com/security/cve/CVE-2026-63920 external
https://bugzilla.suse.com/1272877 external
https://bugzilla.suse.com/1273012 external
https://www.suse.com/security/cve/CVE-2026-64000 external
https://bugzilla.suse.com/1273030 external
https://bugzilla.suse.com/1273052 external
https://www.suse.com/security/cve/CVE-2026-64114 external
https://bugzilla.suse.com/1273742 external
https://bugzilla.suse.com/1273833 external
https://www.suse.com/security/cve/CVE-2026-64121 external
https://bugzilla.suse.com/1273743 external
https://bugzilla.suse.com/1273837 external
https://www.suse.com/security/cve/CVE-2026-68121 external
https://bugzilla.suse.com/1274888 external
https://bugzilla.suse.com/1275228 external
https://bugzilla.suse.com/1282946 external
https://bugzilla.suse.com/1282953 external
https://www.suse.com/security/cve/CVE-2026-74394 external
https://bugzilla.suse.com/1277408 external
https://bugzilla.suse.com/1277409 external
https://www.suse.com/security/cve/CVE-2026-74612 external
https://bugzilla.suse.com/1277505 external
https://bugzilla.suse.com/1277506 external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7)",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "\nThis update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.72 fixes various security issues:\n\nThe following security issues were fixed:\n\n- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391).\n- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012).\n- CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273052).\n- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5 (bsc#1273833).\n- CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273837).\n- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228).\n- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277409).\n- CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277506).\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "SUSE-2026-4433,SUSE-SLE-Module-Live-Patching-15-SP7-2026-4433",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_4433-1.json"
      },
      {
        "category": "self",
        "summary": "URL for SUSE-SU-2026:4433-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264433-1/"
      },
      {
        "category": "self",
        "summary": "E-Mail link for SUSE-SU-2026:4433-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264433-1/"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272391",
        "url": "https://bugzilla.suse.com/1272391"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273012",
        "url": "https://bugzilla.suse.com/1273012"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273052",
        "url": "https://bugzilla.suse.com/1273052"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273833",
        "url": "https://bugzilla.suse.com/1273833"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273837",
        "url": "https://bugzilla.suse.com/1273837"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275228",
        "url": "https://bugzilla.suse.com/1275228"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277409",
        "url": "https://bugzilla.suse.com/1277409"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277506",
        "url": "https://bugzilla.suse.com/1277506"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63888 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63888/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63920 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63920/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64000 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64000/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64114 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64114/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64121 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64121/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68121 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68121/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74394 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74394/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74612 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74612/"
      }
    ],
    "title": "Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7)",
    "tracking": {
      "current_release_date": "2026-10-03T08:37:30Z",
      "generator": {
        "date": "2026-10-02T15:03:58Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "SUSE-SU-2026:4433-1",
      "initial_release_date": "2026-10-02T15:03:58Z",
      "revision_history": [
        {
          "date": "2026-10-02T15:03:58Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-10-03T08:37:30Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64",
                "product": {
                  "name": "kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64",
                  "product_id": "kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/kernel-livepatch-6_4_0-150700_7_72-rt@3-150700.2.1?arch=x86_64\u0026upstream=kernel-livepatch-SLE15-SP7-RT_Update_19-0:3-150700.2.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Live Patching 15 SP7",
                "product": {
                  "name": "SUSE Linux Enterprise Live Patching 15 SP7",
                  "product_id": "SUSE Linux Enterprise Live Patching 15 SP7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-module-live-patching:15:sp7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64 as component of SUSE Linux Enterprise Live Patching 15 SP7",
          "product_id": "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        },
        "product_reference": "kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Live Patching 15 SP7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-63888",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63888"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n   text_in is kzalloc()\u0027d at ALIGN(payload_length, 4).  rx_size is then\n   incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n   in the iovec, but the same (now-bumped) rx_size is passed as the\n   buffer length to iscsit_crc_buf():\n\n       if (conn-\u003econn_ops-\u003eDataDigest) {\n               ...\n               rx_size += ISCSI_CRC_LEN;\n       }\n       ...\n       if (conn-\u003econn_ops-\u003eDataDigest) {\n               data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n   iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n   when DataDigest is negotiated it reads 4 bytes past the end of the\n   text_in allocation.  KASAN reproduces this directly on the unpatched\n   mainline tree as slab-out-of-bounds in crc32c() called from the Text\n   PDU path.  The OOB bytes feed crc32c() and are then compared against\n   the initiator-supplied checksum, so the value does not flow back to\n   the attacker, but the kernel does read past the buffer on every Text\n   PDU with DataDigest=CRC32C.\n\n   Fix by passing the actual padded payload length\n   (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd-\u003etext_in_ptr re-free (double-free) on ERL\u003e0 bad DataDigest\n   drop.\n\n   On DataDigest mismatch with ErrorRecoveryLevel \u003e 0 the handler\n   silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n               kfree(text_in);\n               return 0;\n\n   cmd-\u003etext_in_ptr still points at the freed buffer.  The next Text\n   Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n   unconditionally does\n\n       kfree(cmd-\u003etext_in_ptr);\n       cmd-\u003etext_in_ptr = NULL;\n\n   freeing the same pointer a second time.  Session teardown via\n   iscsit_release_cmd() has the same shape and hits the same double-free\n   if the connection is dropped before a second Text Request arrives.\n\n   On an unmodified mainline tree the bug-1 CRC overread fires first on\n   the initial valid Text Request and perturbs the subsequent state, so\n   #4 was isolated by building a kernel with only the bug-1 hunk of this\n   patch applied plus temporary printk() observability around the three\n   relevant kfree() sites.  The observability prints are not part of\n   this patch.  On that build, a three-PDU Text Request sequence after\n   login produces two back-to-back splats:\n\n       BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n       BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n   showing the same pointer freed in the ERL\u003e0 drop path and again in\n   iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n   more in iscsit_release_cmd() (session teardown).  On distro kernels\n   with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n   becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n   the slab freelist.\n\n   Fix by clearing cmd-\u003etext_in_ptr after the kfree() in the ERL\u003e0 drop\n   path.  With both hunks applied #4 is directly observable on the stock\n   tree without observability printks; fixing bug-1 alone would mask #4\n   less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners.  The Text PDU state machine is unchanged and\nthe wire protocol is unaffected.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63888",
          "url": "https://www.suse.com/security/cve/CVE-2026-63888"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272390 for CVE-2026-63888",
          "url": "https://bugzilla.suse.com/1272390"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272391 for CVE-2026-63888",
          "url": "https://bugzilla.suse.com/1272391"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63888"
    },
    {
      "cve": "CVE-2026-63920",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63920"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: validate extension header length before copying to cmsg\n\nip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR}\ncmsgs (and their IPV6_2292* legacy counterparts) by trusting the\non-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.\nThe length was validated only at parse time (ipv6_parse_hopopts(),\netc.).  An nftables payload-write expression can rewrite hdrlen after\nparsing and before the skb reaches recvmsg; the write itself is\nin-bounds but put_cmsg() then reads up to ((hdrlen+1) \u003c\u003c 3) = 2040\nbytes from an 8-byte header.  nftables is reachable from an\nunprivileged user namespace, so this is an unprivileged\nslab-out-of-bounds read:\n\n  BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540\n   put_cmsg+0x3ac/0x540\n   udpv6_recvmsg+0xca0/0x1250\n   sock_recvmsg+0xdf/0x190\n   ____sys_recvmsg+0x1b1/0x620\n\nAdd ipv6_get_exthdr_len() which validates that at least two bytes\nare accessible before reading the hdrlen field, then checks the\ncomputed length against skb_tail_pointer(skb), returning 0 on\nfailure.  Extension headers are kept in the linear skb area by\npskb_may_pull() during input, so skb_tail_pointer() is the correct\nbound.\n\nUse ipv6_get_exthdr_len() at all non-AH call sites: the five\nstandalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR)\nand the three standard cases in the extension-header walk loop\n(DSTOPTS, ROUTING, default).  AH retains an inline bounds check\nbecause its length formula differs ((ptr[1]+2)\u003c\u003c2).\n\nThe walk loop also gets a pre-read bounds check at the top to\nvalidate ptr before any case accesses ptr[0] or ptr[1].\n\nWhen the walk loop detects a corrupted header, return from the\nfunction instead of continuing to process later socket options.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63920",
          "url": "https://www.suse.com/security/cve/CVE-2026-63920"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272877 for CVE-2026-63920",
          "url": "https://bugzilla.suse.com/1272877"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273012 for CVE-2026-63920",
          "url": "https://bugzilla.suse.com/1273012"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63920"
    },
    {
      "cve": "CVE-2026-64000",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64000"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix potential OOB access in supervision frame handling\n\nEnsure the entire TLV header is linearized before access by adding\nsizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,\na truncated frame could cause an out-of-bounds access.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64000",
          "url": "https://www.suse.com/security/cve/CVE-2026-64000"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273030 for CVE-2026-64000",
          "url": "https://bugzilla.suse.com/1273030"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273052 for CVE-2026-64000",
          "url": "https://bugzilla.suse.com/1273052"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64000"
    },
    {
      "cve": "CVE-2026-64114",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64114"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5\n\nraw_send_hdrinc() validates that the caller-supplied IPv4 header\nfits within the message length:\n\n    iphlen = iph-\u003eihl * 4;\n    err = -EINVAL;\n    if (iphlen \u003e length)\n        goto error_free;\n\n    if (iphlen \u003e= sizeof(*iph)) {\n        /* fix up saddr, tot_len, id, csum, transport_header */\n    }\n\nIt does not, however, reject ihl \u003c 5.  For such a packet the\n\"if (iphlen \u003e= sizeof(*iph))\" branch is skipped, leaving the\ncrafted iphdr untouched, but the packet is still handed to\n__ip_local_out() and onward.  Downstream consumers that read\niph-\u003eihl assume a sane value: net/ipv4/ah4.c:ah_output() in\nparticular subtracts sizeof(struct iphdr) from top_iph-\u003eihl * 4\nand passes the (signed-int-negative, then cast to size_t)\nresult to memcpy(), producing an OOB access of length close to\nSIZE_MAX and a host kernel panic.\n\nAn IPv4 header with ihl \u003c 5 is malformed by definition (RFC 791:\n\"Internet Header Length is the length of the internet header in\n32 bit words ... Note that the minimum value for a correct header\nis 5.\").  The kernel should not be willing to inject such a\npacket into its own output path.\n\nReject \"iphlen \u003c sizeof(*iph)\" alongside the existing\n\"iphlen \u003e length\" check.  This matches the principle that locally\nconstructed packets that re-enter the IP stack must pass the same\nbasic sanity tests that a foreign packet would be subjected to.\n\nOnce this lands, the \"if (iphlen \u003e= sizeof(*iph))\" wrapper around\nthe fixup branch becomes redundant; left in place to keep the\npatch minimal and backport-friendly.  A follow-up can unwrap it.\n\nNote that commit 86f4c90a1c5c (\"ipv4, ipv6: ensure raw socket\nmessage is big enough to hold an IP header\") ensures the message\nbuffer is large enough to hold an iphdr, but does not constrain\nthe self-reported iph-\u003eihl.\n\nReachability: the malformed packet source is any caller with\nCAP_NET_RAW, including an unprivileged process in a user+net\nnamespace on a kernel with CONFIG_USER_NS=y.  The reproduced AH\ncrash also requires a matching xfrm AH policy on the outgoing\nroute; a container granted CAP_NET_ADMIN can install that state\nand policy in its netns.  Loopback bypasses xfrm_output, so the\ntrigger uses a real netdev.\n\nReproduced on UML + KASAN: kernel-mode fault at addr 0x0 with\nmemcpy_orig at the crash site.  Same shape reproduces inside a\nrootless Docker container with --cap-add NET_ADMIN on a stock\ndistro kernel.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64114",
          "url": "https://www.suse.com/security/cve/CVE-2026-64114"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273742 for CVE-2026-64114",
          "url": "https://bugzilla.suse.com/1273742"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273833 for CVE-2026-64114",
          "url": "https://bugzilla.suse.com/1273833"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64114"
    },
    {
      "cve": "CVE-2026-64121",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64121"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ifb: report ethtool stats over num_tx_queues\n\nifb_dev_init() allocates dp-\u003etx_private to dev-\u003enum_tx_queues\nentries via kzalloc_objs(*txp, dev-\u003enum_tx_queues). Both IFB\nper-queue RX and TX stats live in those entries: ifb_xmit() updates\ntxp-\u003erx_stats using the skb queue mapping, ifb_ri_tasklet() updates\ntxp-\u003etx_stats, and ifb_stats64() aggregates both over\ndev-\u003enum_tx_queues.\n\nThe ethtool stats callbacks instead size and walk the per-queue\nstats with dev-\u003ereal_num_rx_queues and dev-\u003ereal_num_tx_queues. With\nan asymmetric device where the RX queue count exceeds the TX queue\ncount, for example:\n\n    ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb\n    ethtool -S ifb10\n\nifb_get_ethtool_stats() indexes past the tx_private allocation and\ncopies adjacent slab data through ETHTOOL_GSTATS.\n\nUse dev-\u003enum_tx_queues consistently for the stats strings, the\nstats count, and the stats data walks. This reports one RX stats\ngroup and one TX stats group for each backing ifb_q_private entry,\nwhich is the queue set IFB can actually populate.\n\nReproduced under UML+KASAN at v7.1-rc2:\n\n  BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae\n  Read of size 8 at addr 0000000062dbd228 by task ethtool/36\n  ifb_fill_stats_data+0x3c/0xae\n  ifb_get_ethtool_stats+0xc0/0x129\n  __dev_ethtool+0x1ca5/0x363c\n  dev_ethtool+0x123/0x1b3\n  dev_ioctl+0x56c/0x744\n  sock_do_ioctl+0x15f/0x1b2\n  sock_ioctl+0x4d5/0x50a\n  sys_ioctl+0xd8b/0xde9\n\nWith the patch applied, the same UML+KASAN repro is silent and\nethtool -S ifb10 reports only the stats backed by the single\nallocated tx_private entry.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64121",
          "url": "https://www.suse.com/security/cve/CVE-2026-64121"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273743 for CVE-2026-64121",
          "url": "https://bugzilla.suse.com/1273743"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273837 for CVE-2026-64121",
          "url": "https://bugzilla.suse.com/1273837"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64121"
    },
    {
      "cve": "CVE-2026-68121",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68121"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team\u0027s delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb\u0027s network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68121",
          "url": "https://www.suse.com/security/cve/CVE-2026-68121"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274888 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1274888"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275228 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1275228"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1282946 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1282946"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1282953 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1282953"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68121"
    },
    {
      "cve": "CVE-2026-74394",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74394"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: fix integer overflow in immediate data length check\n\nimm_buf-\u003elen is a user-controlled uint32_t received from the network.\nAdding it to imm_data_offset without overflow checking allows a\nmalicious initiator to send len=0xFFFFFFFF, causing req_size to wrap\naround to a small value, bypassing the bounds check, and subsequently\npassing a ~4GB length to sg_init_one().\n\nUse check_add_overflow() to detect wrapping before the comparison.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74394",
          "url": "https://www.suse.com/security/cve/CVE-2026-74394"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277408 for CVE-2026-74394",
          "url": "https://bugzilla.suse.com/1277408"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277409 for CVE-2026-74394",
          "url": "https://bugzilla.suse.com/1277409"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74394"
    },
    {
      "cve": "CVE-2026-74612",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74612"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb-\u003edata_len but leaves skb-\u003elen containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb\u0027s\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)-\u003efrags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb-\u003elen and skb-\u003edata_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb-\u003elen explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74612",
          "url": "https://www.suse.com/security/cve/CVE-2026-74612"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277505 for CVE-2026-74612",
          "url": "https://bugzilla.suse.com/1277505"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277506 for CVE-2026-74612",
          "url": "https://bugzilla.suse.com/1277506"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_72-rt-0:3-150700.2.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-10-02T15:03:58Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74612"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Detection rules are retrieved from Rulezet.

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…