SUSE-SU-2026:4415-1
Vulnerability from csaf_suse - Published: 2026-10-02 08:33 - Updated: 2026-10-02 17:47Summary
Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 15 SP7)
Severity
Important
Notes
Title of the patch: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 15 SP7)
Description of the patch:
This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.44 fixes various security issues:
The following security issues were fixed:
- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267370).
- CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272283).
- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391).
- CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272837).
- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1273015).
- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012).
- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1273011).
- CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1273003).
- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272679).
- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (bsc#1273051).
- CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273052).
- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1276493).
- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273833).
- CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273837).
- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272208).
- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228).
- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275162).
- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277409).
- CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277506).
Patchnames: SUSE-2026-4415,SUSE-SLE-Module-Live-Patching-15-SP7-2026-4415
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
7.8 (High)
Affected products
Recommended
1 product
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64 | — |
Vendor Fix
|
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.1 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.8 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.1 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
8.7 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.5 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.1 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.1 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.8 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.1 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.3 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.8 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
7.8 (High)
Affected products
Recommended
1 product, the same list as for
CVE-2026-46116
Threats
Impact
important
References
102 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "important"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 15 SP7)",
"title": "Title of the patch"
},
{
"category": "description",
"text": "\nThis update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.44 fixes various security issues:\n\nThe following security issues were fixed:\n\n- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267370).\n- CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272283).\n- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391).\n- CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272837).\n- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1273015).\n- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012).\n- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1273011).\n- CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1273003).\n- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272679).\n- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (bsc#1273051).\n- CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273052).\n- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1276493).\n- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5 (bsc#1273833).\n- CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273837).\n- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272208).\n- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228).\n- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275162).\n- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277409).\n- CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277506).\n",
"title": "Description of the patch"
},
{
"category": "details",
"text": "SUSE-2026-4415,SUSE-SLE-Module-Live-Patching-15-SP7-2026-4415",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_4415-1.json"
},
{
"category": "self",
"summary": "URL for SUSE-SU-2026:4415-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264415-1/"
},
{
"category": "self",
"summary": "E-Mail link for SUSE-SU-2026:4415-1",
"url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264415-1/"
},
{
"category": "self",
"summary": "SUSE Bug 1267370",
"url": "https://bugzilla.suse.com/1267370"
},
{
"category": "self",
"summary": "SUSE Bug 1272208",
"url": "https://bugzilla.suse.com/1272208"
},
{
"category": "self",
"summary": "SUSE Bug 1272283",
"url": "https://bugzilla.suse.com/1272283"
},
{
"category": "self",
"summary": "SUSE Bug 1272391",
"url": "https://bugzilla.suse.com/1272391"
},
{
"category": "self",
"summary": "SUSE Bug 1272679",
"url": "https://bugzilla.suse.com/1272679"
},
{
"category": "self",
"summary": "SUSE Bug 1272837",
"url": "https://bugzilla.suse.com/1272837"
},
{
"category": "self",
"summary": "SUSE Bug 1273003",
"url": "https://bugzilla.suse.com/1273003"
},
{
"category": "self",
"summary": "SUSE Bug 1273011",
"url": "https://bugzilla.suse.com/1273011"
},
{
"category": "self",
"summary": "SUSE Bug 1273012",
"url": "https://bugzilla.suse.com/1273012"
},
{
"category": "self",
"summary": "SUSE Bug 1273015",
"url": "https://bugzilla.suse.com/1273015"
},
{
"category": "self",
"summary": "SUSE Bug 1273051",
"url": "https://bugzilla.suse.com/1273051"
},
{
"category": "self",
"summary": "SUSE Bug 1273052",
"url": "https://bugzilla.suse.com/1273052"
},
{
"category": "self",
"summary": "SUSE Bug 1273833",
"url": "https://bugzilla.suse.com/1273833"
},
{
"category": "self",
"summary": "SUSE Bug 1273837",
"url": "https://bugzilla.suse.com/1273837"
},
{
"category": "self",
"summary": "SUSE Bug 1275162",
"url": "https://bugzilla.suse.com/1275162"
},
{
"category": "self",
"summary": "SUSE Bug 1275228",
"url": "https://bugzilla.suse.com/1275228"
},
{
"category": "self",
"summary": "SUSE Bug 1276493",
"url": "https://bugzilla.suse.com/1276493"
},
{
"category": "self",
"summary": "SUSE Bug 1277409",
"url": "https://bugzilla.suse.com/1277409"
},
{
"category": "self",
"summary": "SUSE Bug 1277506",
"url": "https://bugzilla.suse.com/1277506"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-46116 page",
"url": "https://www.suse.com/security/cve/CVE-2026-46116/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63802 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63802/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63888 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63888/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63912 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63912/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63917 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63917/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63920 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63920/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63921 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63921/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63944 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63944/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63971 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63971/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-63994 page",
"url": "https://www.suse.com/security/cve/CVE-2026-63994/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-64000 page",
"url": "https://www.suse.com/security/cve/CVE-2026-64000/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-64011 page",
"url": "https://www.suse.com/security/cve/CVE-2026-64011/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-64114 page",
"url": "https://www.suse.com/security/cve/CVE-2026-64114/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-64121 page",
"url": "https://www.suse.com/security/cve/CVE-2026-64121/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-64189 page",
"url": "https://www.suse.com/security/cve/CVE-2026-64189/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-68121 page",
"url": "https://www.suse.com/security/cve/CVE-2026-68121/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-68202 page",
"url": "https://www.suse.com/security/cve/CVE-2026-68202/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-74394 page",
"url": "https://www.suse.com/security/cve/CVE-2026-74394/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2026-74612 page",
"url": "https://www.suse.com/security/cve/CVE-2026-74612/"
}
],
"title": "Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 15 SP7)",
"tracking": {
"current_release_date": "2026-10-02T17:47:47Z",
"generator": {
"date": "2026-10-02T08:33:42Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "SUSE-SU-2026:4415-1",
"initial_release_date": "2026-10-02T08:33:42Z",
"revision_history": [
{
"date": "2026-10-02T08:33:42Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-10-02T17:47:47Z",
"number": "2",
"summary": "unknown changes"
}
],
"status": "final",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64",
"product": {
"name": "kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64",
"product_id": "kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-livepatch-6_4_0-150700_7_44-rt@8-150700.2.1?arch=x86_64\u0026upstream=kernel-livepatch-SLE15-SP7-RT_Update_13-0:8-150700.2.1.src.rpm"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "SUSE Linux Enterprise Live Patching 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Live Patching 15 SP7",
"product_id": "SUSE Linux Enterprise Live Patching 15 SP7",
"product_identification_helper": {
"cpe": "cpe:/o:suse:sle-module-live-patching:15:sp7"
}
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64 as component of SUSE Linux Enterprise Live Patching 15 SP7",
"product_id": "SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
},
"product_reference": "kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64",
"relates_to_product_reference": "SUSE Linux Enterprise Live Patching 15 SP7"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-46116",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-46116"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: defensively unhash xfrm_state lists in __xfrm_state_delete\n\nKASAN reproduces a slab-use-after-free in __xfrm_state_delete()\u0027s\nhlist_del_rcu calls under syzkaller load on linux-6.12.y stable\n(reproduced on 6.12.47, also reachable via the same code path on\ntorvalds/master and on the ipsec tree). Nine unique signatures cluster\nin the xfrm_state lifecycle, the load-bearing one being:\n\n BUG: KASAN: slab-use-after-free in __hlist_del include/linux/list.h:990 [inline]\n BUG: KASAN: slab-use-after-free in hlist_del_rcu include/linux/rculist.h:516 [inline]\n BUG: KASAN: slab-use-after-free in __xfrm_state_delete net/xfrm/xfrm_state.c\n Write of size 8 at addr ffff8881198bcb70 by task kworker/u8:9/435\n\n Workqueue: netns cleanup_net\n Call Trace:\n __hlist_del / hlist_del_rcu\n __xfrm_state_delete\n xfrm_state_delete\n xfrm_state_flush\n xfrm_state_fini\n ops_exit_list\n cleanup_net\n\nThe other observed signatures hit the same slab object from\n__xfrm_state_lookup, xfrm_alloc_spi, __xfrm_state_insert and an OOB\nwrite variant of __xfrm_state_delete, all on the byseq/byspi\nhash chains.\n\n__xfrm_state_delete() guards its byseq and byspi unhashes with\nvalue-based predicates:\n\n\tif (x-\u003ekm.seq)\n\t\thlist_del_rcu(\u0026x-\u003ebyseq);\n\tif (x-\u003eid.spi)\n\t\thlist_del_rcu(\u0026x-\u003ebyspi);\n\nwhile everywhere else in the file (e.g. state_cache, state_cache_input)\nthe safer hlist_unhashed() check is used. xfrm_alloc_spi() sets\nx-\u003eid.spi = newspi inside xfrm_state_lock and then immediately inserts\ninto byspi, but a path that observes x-\u003eid.spi != 0 outside of\nxfrm_state_lock can still skip-or-hit the byspi unhash inconsistently\nwith whether x is actually on the list. The same holds for x-\u003ekm.seq\nversus byseq, and the bydst/bysrc unhashes have no predicate at all,\nso a second __xfrm_state_delete() on the same object writes through\nLIST_POISON pprev.\n\nThe defensive change here:\n\n - Use hlist_del_init_rcu() instead of hlist_del_rcu() on bydst,\n bysrc, byseq and byspi so a second deletion is a no-op rather\n than a write through LIST_POISON pprev. The byseq/byspi nodes\n are already initialised in xfrm_state_alloc().\n - Test hlist_unhashed() rather than the value predicate for\n byseq/byspi, so the unhash decision tracks list state rather than\n mutable scalar fields.\n\nEmpirical verification: applied this patch on top of v6.12.47, rebuilt,\nand re-ran the same syzkaller harness for 1h16m on a previously-crashy\nconfiguration that produced ~100 hits each of slab-use-after-free\nRead in xfrm_alloc_spi / Read in __xfrm_state_lookup / Write in\n__xfrm_state_delete. After the patch, 7.1M execs across 32 VMs at\n~1550 exec/sec produced zero xfrm_state UAF/OOB hits. /proc/slabinfo\nconfirms the xfrm_state slab is actively allocated and freed during\nthe run (~143 KiB resident), so the fuzzer is still exercising those\ncode paths -- they just no longer crash.\n\nReproduction:\n\n - Linux 6.12.47 x86_64 + KASAN_GENERIC + KASAN_INLINE + KCOV\n - syzkaller @ 746545b8b1e4c3a128db8652b340d3df90ce61db\n - 32 QEMU/KVM VMs x 2 vCPU on AWS c5.metal bare metal\n - 9 unique signatures collected in ~9h, all within xfrm_state\n lifecycle",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-46116",
"url": "https://www.suse.com/security/cve/CVE-2026-46116"
},
{
"category": "external",
"summary": "SUSE Bug 1267369 for CVE-2026-46116",
"url": "https://bugzilla.suse.com/1267369"
},
{
"category": "external",
"summary": "SUSE Bug 1267370 for CVE-2026-46116",
"url": "https://bugzilla.suse.com/1267370"
},
{
"category": "external",
"summary": "SUSE Bug 1274780 for CVE-2026-46116",
"url": "https://bugzilla.suse.com/1274780"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-46116"
},
{
"cve": "CVE-2026-63802",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63802"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: fix UAF in __blkcg_rstat_flush()\n\nWhen multiple blkgs in the same blkcg are released concurrently,\na use-after-free can occur. The race happens when one blkg\u0027s\n__blkcg_rstat_flush() removes another blkg\u0027s iostat entries via\nllist_del_all(). The second blkg sees an empty list and proceeds\nto free itself while the first is still iterating over its entries.\n\nMove the flush from __blkg_release() (RCU callback) to blkg_release()\n(before call_rcu). This ensures the RCU grace period waits for any\nconcurrent flush\u0027s rcu_read_lock() section to complete before freeing.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63802",
"url": "https://www.suse.com/security/cve/CVE-2026-63802"
},
{
"category": "external",
"summary": "SUSE Bug 1272282 for CVE-2026-63802",
"url": "https://bugzilla.suse.com/1272282"
},
{
"category": "external",
"summary": "SUSE Bug 1272283 for CVE-2026-63802",
"url": "https://bugzilla.suse.com/1272283"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63802"
},
{
"cve": "CVE-2026-63888",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63888"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n text_in is kzalloc()\u0027d at ALIGN(payload_length, 4). rx_size is then\n incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n in the iovec, but the same (now-bumped) rx_size is passed as the\n buffer length to iscsit_crc_buf():\n\n if (conn-\u003econn_ops-\u003eDataDigest) {\n ...\n rx_size += ISCSI_CRC_LEN;\n }\n ...\n if (conn-\u003econn_ops-\u003eDataDigest) {\n data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n when DataDigest is negotiated it reads 4 bytes past the end of the\n text_in allocation. KASAN reproduces this directly on the unpatched\n mainline tree as slab-out-of-bounds in crc32c() called from the Text\n PDU path. The OOB bytes feed crc32c() and are then compared against\n the initiator-supplied checksum, so the value does not flow back to\n the attacker, but the kernel does read past the buffer on every Text\n PDU with DataDigest=CRC32C.\n\n Fix by passing the actual padded payload length\n (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd-\u003etext_in_ptr re-free (double-free) on ERL\u003e0 bad DataDigest\n drop.\n\n On DataDigest mismatch with ErrorRecoveryLevel \u003e 0 the handler\n silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n kfree(text_in);\n return 0;\n\n cmd-\u003etext_in_ptr still points at the freed buffer. The next Text\n Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n unconditionally does\n\n kfree(cmd-\u003etext_in_ptr);\n cmd-\u003etext_in_ptr = NULL;\n\n freeing the same pointer a second time. Session teardown via\n iscsit_release_cmd() has the same shape and hits the same double-free\n if the connection is dropped before a second Text Request arrives.\n\n On an unmodified mainline tree the bug-1 CRC overread fires first on\n the initial valid Text Request and perturbs the subsequent state, so\n #4 was isolated by building a kernel with only the bug-1 hunk of this\n patch applied plus temporary printk() observability around the three\n relevant kfree() sites. The observability prints are not part of\n this patch. On that build, a three-PDU Text Request sequence after\n login produces two back-to-back splats:\n\n BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n showing the same pointer freed in the ERL\u003e0 drop path and again in\n iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n more in iscsit_release_cmd() (session teardown). On distro kernels\n with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n the slab freelist.\n\n Fix by clearing cmd-\u003etext_in_ptr after the kfree() in the ERL\u003e0 drop\n path. With both hunks applied #4 is directly observable on the stock\n tree without observability printks; fixing bug-1 alone would mask #4\n less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners. The Text PDU state machine is unchanged and\nthe wire protocol is unaffected.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63888",
"url": "https://www.suse.com/security/cve/CVE-2026-63888"
},
{
"category": "external",
"summary": "SUSE Bug 1272390 for CVE-2026-63888",
"url": "https://bugzilla.suse.com/1272390"
},
{
"category": "external",
"summary": "SUSE Bug 1272391 for CVE-2026-63888",
"url": "https://bugzilla.suse.com/1272391"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63888"
},
{
"cve": "CVE-2026-63912",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63912"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: restore combined single-frag length gate\n\nThe ESP out-of-place fast path appends the trailer in esp_output_head()\nbefore esp_output_tail() allocates the destination page frag. The\nhead-side gate currently checks skb-\u003edata_len and tailen separately, but\nthe tail code allocates a single destination frag from the combined\npost-trailer skb-\u003edata_len.\n\nReject the page-frag fast path when the combined aligned length exceeds a\npage. Otherwise skb_page_frag_refill() may fall back to a single page while\nthe destination sg still spans the combined skb-\u003edata_len.\n\nRestore this combined-length page gate for both IPv4 and IPv6.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63912",
"url": "https://www.suse.com/security/cve/CVE-2026-63912"
},
{
"category": "external",
"summary": "SUSE Bug 1272836 for CVE-2026-63912",
"url": "https://bugzilla.suse.com/1272836"
},
{
"category": "external",
"summary": "SUSE Bug 1272837 for CVE-2026-63912",
"url": "https://bugzilla.suse.com/1272837"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63912"
},
{
"cve": "CVE-2026-63917",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63917"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6: vti: Use ip6_tnl.net in vti6_changelink().\n\nip netns add ns1\nip netns add ns2\nip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7\nip -n ns1 link set vti6_test netns ns2\nip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9\nip netns del ns2\nip netns del ns1\n[ 132.495484] ------------[ cut here ]------------\n[ 132.497609] kernel BUG at net/core/dev.c:12376!\n\nCommit 61220ab34948 (\"vti6: Enable namespace changing\") dropped\nNETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then\nmove through IFLA_NET_NS_FD. After the move dev_net(dev) points\nat the new netns while t-\u003enet stays at the creation netns.\n\nvti6_changelink() and vti6_update() still use dev_net(dev) and\ndev_net(t-\u003edev). They unlink from one per netns hash and relink\ninto another. The creation netns is left with a stale entry.\ncleanup_net() of that netns later walks freed memory.\n\nReachable from an unprivileged user namespace (unshare --user\n--map-root-user --net). Cross tenant scope on container hosts.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63917",
"url": "https://www.suse.com/security/cve/CVE-2026-63917"
},
{
"category": "external",
"summary": "SUSE Bug 1272904 for CVE-2026-63917",
"url": "https://bugzilla.suse.com/1272904"
},
{
"category": "external",
"summary": "SUSE Bug 1273015 for CVE-2026-63917",
"url": "https://bugzilla.suse.com/1273015"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63917"
},
{
"cve": "CVE-2026-63920",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63920"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: validate extension header length before copying to cmsg\n\nip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR}\ncmsgs (and their IPV6_2292* legacy counterparts) by trusting the\non-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.\nThe length was validated only at parse time (ipv6_parse_hopopts(),\netc.). An nftables payload-write expression can rewrite hdrlen after\nparsing and before the skb reaches recvmsg; the write itself is\nin-bounds but put_cmsg() then reads up to ((hdrlen+1) \u003c\u003c 3) = 2040\nbytes from an 8-byte header. nftables is reachable from an\nunprivileged user namespace, so this is an unprivileged\nslab-out-of-bounds read:\n\n BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540\n put_cmsg+0x3ac/0x540\n udpv6_recvmsg+0xca0/0x1250\n sock_recvmsg+0xdf/0x190\n ____sys_recvmsg+0x1b1/0x620\n\nAdd ipv6_get_exthdr_len() which validates that at least two bytes\nare accessible before reading the hdrlen field, then checks the\ncomputed length against skb_tail_pointer(skb), returning 0 on\nfailure. Extension headers are kept in the linear skb area by\npskb_may_pull() during input, so skb_tail_pointer() is the correct\nbound.\n\nUse ipv6_get_exthdr_len() at all non-AH call sites: the five\nstandalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR)\nand the three standard cases in the extension-header walk loop\n(DSTOPTS, ROUTING, default). AH retains an inline bounds check\nbecause its length formula differs ((ptr[1]+2)\u003c\u003c2).\n\nThe walk loop also gets a pre-read bounds check at the top to\nvalidate ptr before any case accesses ptr[0] or ptr[1].\n\nWhen the walk loop detects a corrupted header, return from the\nfunction instead of continuing to process later socket options.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63920",
"url": "https://www.suse.com/security/cve/CVE-2026-63920"
},
{
"category": "external",
"summary": "SUSE Bug 1272877 for CVE-2026-63920",
"url": "https://bugzilla.suse.com/1272877"
},
{
"category": "external",
"summary": "SUSE Bug 1273012 for CVE-2026-63920",
"url": "https://bugzilla.suse.com/1273012"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63920"
},
{
"cve": "CVE-2026-63921",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63921"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().\n\nAfter patch 1/2 in this series, vti6_update() unlinks and relinks\nthe tunnel through t-\u003enet. vti6_siocdevprivate() still uses\ndev_net(dev) for the collision lookup. For a tunnel moved through\nIFLA_NET_NS_FD, dev_net(dev) is the new netns, not t-\u003enet.\n\nSIOCCHGTUNNEL on a migrated tunnel then runs:\n\n net = dev_net(dev) /* migrated netns */\n t = vti6_locate(net, \u0026p1, false) /* misses target in t-\u003enet */\n ...\n t = netdev_priv(dev)\n vti6_update(t, \u0026p1, false) /* mutates t-\u003enet\u0027s hash */\n\nA caller in the migrated netns picks params that match a tunnel\nin the creation netns. The lookup in dev_net(dev) finds nothing.\nvti6_update() prepends the migrated tunnel at the head of the\ncreation netns hash bucket for those params. Later lookups in\nthe creation netns resolve to the migrated device. xfrm receive\ndelivers the matched packets through a device the caller controls.\n\nReachable from an unprivileged user namespace (unshare --user\n--map-root-user --net). Cross tenant scope on container hosts.\n\nSwitch the SIOCCHGTUNNEL path on a non fallback device to use\nt-\u003enet for the lookup. The lookup now matches the netns\nvti6_update() operates on.\n\nAlso add ns_capable(self-\u003enet-\u003euser_ns, CAP_NET_ADMIN) before\nthe lookup. The check at the top of the case is against\ndev_net(dev)-\u003euser_ns, which after migration is the attacker\u0027s\nnetns. A caller there can pick params absent from self-\u003enet,\nthe lookup returns NULL, t becomes self, and vti6_update()\ninserts the device into the creation netns hash. The new check\nrequires CAP_NET_ADMIN in the creation netns user_ns too.\n\nSIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep\ndev_net(dev), which equals init_net there.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63921",
"url": "https://www.suse.com/security/cve/CVE-2026-63921"
},
{
"category": "external",
"summary": "SUSE Bug 1272918 for CVE-2026-63921",
"url": "https://bugzilla.suse.com/1272918"
},
{
"category": "external",
"summary": "SUSE Bug 1273011 for CVE-2026-63921",
"url": "https://bugzilla.suse.com/1273011"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 8.7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63921"
},
{
"cve": "CVE-2026-63944",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63944"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: fix UAF in hci_le_create_cis_sync\n\nhci_le_create_cis_sync() dereferences conn-\u003econn_timeout after releasing\nboth rcu_read_lock() and hci_dev_lock(hdev). The conn pointer was\nobtained from an RCU-protected iteration over hdev-\u003econn_hash.list and\nis not valid once these locks are dropped. A concurrent disconnect can\nfree the hci_conn between the unlock and the dereference, causing a\nuse-after-free read.\n\nThe cancellation mechanism in hci_conn_del() cannot prevent this because\nhci_le_create_cis_pending() queues hci_create_cis_sync with data=NULL:\n\n hci_cmd_sync_queue(hdev, hci_create_cis_sync, NULL, NULL);\n\nWhile hci_conn_del() dequeues with data=conn:\n\n hci_cmd_sync_dequeue(hdev, NULL, conn, NULL);\n\nSince NULL != conn, the lookup in _hci_cmd_sync_lookup_entry() never\nmatches, and the pending work item is not cancelled.\n\nFix this by saving conn-\u003econn_timeout into a local variable while the\nlocks are still held, so the stale conn pointer is never dereferenced\nafter unlock.\n\nThis is the same class of bug as the one fixed by commit 035c25007c9e\n(\"Bluetooth: hci_sync: Fix UAF on le_read_features_complete\") which\naddressed the identical pattern in a different function.\n\nThis vulnerability was identified using 0sec.ai, an open-source\nautomated security auditing platform (https://github.com/0sec-labs).",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63944",
"url": "https://www.suse.com/security/cve/CVE-2026-63944"
},
{
"category": "external",
"summary": "SUSE Bug 1272662 for CVE-2026-63944",
"url": "https://bugzilla.suse.com/1272662"
},
{
"category": "external",
"summary": "SUSE Bug 1273003 for CVE-2026-63944",
"url": "https://bugzilla.suse.com/1273003"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63944"
},
{
"cve": "CVE-2026-63971",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63971"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix race between sctp_wait_for_connect and peeloff\n\nsctp_wait_for_connect() drops and re-acquires the socket lock while\nwaiting for the association to reach ESTABLISHED state. During this\nwindow, another thread can peeloff the association to a new socket via\ngetsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc-\u003ebase.sk. After\nre-acquiring the old socket lock, sctp_wait_for_connect() returns\nsuccess without noticing the migration - the caller then accesses\nthe association under the wrong lock in sctp_datamsg_from_user().\n\nAdd the same sk != asoc-\u003ebase.sk check that sctp_wait_for_sndbuf()\nalready has, returning an error if the association was migrated while\nwe slept.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63971",
"url": "https://www.suse.com/security/cve/CVE-2026-63971"
},
{
"category": "external",
"summary": "SUSE Bug 1272678 for CVE-2026-63971",
"url": "https://bugzilla.suse.com/1272678"
},
{
"category": "external",
"summary": "SUSE Bug 1272679 for CVE-2026-63971",
"url": "https://bugzilla.suse.com/1272679"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63971"
},
{
"cve": "CVE-2026-63994",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-63994"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()\n\nSashiko found that iptunnel_pmtud_build_icmp() and\niptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr()\nbefore an skb_cow() call which can reallocate skb-\u003ehead.\n\nFix this possible UAF by initializing the local variables\nafter the skb_cow() call.\n\nRemove skb_reset_network_header() calls which were not needed.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-63994",
"url": "https://www.suse.com/security/cve/CVE-2026-63994"
},
{
"category": "external",
"summary": "SUSE Bug 1273035 for CVE-2026-63994",
"url": "https://bugzilla.suse.com/1273035"
},
{
"category": "external",
"summary": "SUSE Bug 1273051 for CVE-2026-63994",
"url": "https://bugzilla.suse.com/1273051"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-63994"
},
{
"cve": "CVE-2026-64000",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-64000"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix potential OOB access in supervision frame handling\n\nEnsure the entire TLV header is linearized before access by adding\nsizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,\na truncated frame could cause an out-of-bounds access.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-64000",
"url": "https://www.suse.com/security/cve/CVE-2026-64000"
},
{
"category": "external",
"summary": "SUSE Bug 1273030 for CVE-2026-64000",
"url": "https://bugzilla.suse.com/1273030"
},
{
"category": "external",
"summary": "SUSE Bug 1273052 for CVE-2026-64000",
"url": "https://bugzilla.suse.com/1273052"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-64000"
},
{
"cve": "CVE-2026-64011",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-64011"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: Fix use-after-free in llcp_sock_release()\n\nllcp_sock_release() unconditionally unlinks the socket from the local\nsockets list. However, if the socket is still in connecting state, it\nis on the connecting list.\n\nFix this by checking the socket state and unlinking from the correct list.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-64011",
"url": "https://www.suse.com/security/cve/CVE-2026-64011"
},
{
"category": "external",
"summary": "SUSE Bug 1273891 for CVE-2026-64011",
"url": "https://bugzilla.suse.com/1273891"
},
{
"category": "external",
"summary": "SUSE Bug 1276493 for CVE-2026-64011",
"url": "https://bugzilla.suse.com/1276493"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-64011"
},
{
"cve": "CVE-2026-64114",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-64114"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: raw: reject IP_HDRINCL packets with ihl \u003c 5\n\nraw_send_hdrinc() validates that the caller-supplied IPv4 header\nfits within the message length:\n\n iphlen = iph-\u003eihl * 4;\n err = -EINVAL;\n if (iphlen \u003e length)\n goto error_free;\n\n if (iphlen \u003e= sizeof(*iph)) {\n /* fix up saddr, tot_len, id, csum, transport_header */\n }\n\nIt does not, however, reject ihl \u003c 5. For such a packet the\n\"if (iphlen \u003e= sizeof(*iph))\" branch is skipped, leaving the\ncrafted iphdr untouched, but the packet is still handed to\n__ip_local_out() and onward. Downstream consumers that read\niph-\u003eihl assume a sane value: net/ipv4/ah4.c:ah_output() in\nparticular subtracts sizeof(struct iphdr) from top_iph-\u003eihl * 4\nand passes the (signed-int-negative, then cast to size_t)\nresult to memcpy(), producing an OOB access of length close to\nSIZE_MAX and a host kernel panic.\n\nAn IPv4 header with ihl \u003c 5 is malformed by definition (RFC 791:\n\"Internet Header Length is the length of the internet header in\n32 bit words ... Note that the minimum value for a correct header\nis 5.\"). The kernel should not be willing to inject such a\npacket into its own output path.\n\nReject \"iphlen \u003c sizeof(*iph)\" alongside the existing\n\"iphlen \u003e length\" check. This matches the principle that locally\nconstructed packets that re-enter the IP stack must pass the same\nbasic sanity tests that a foreign packet would be subjected to.\n\nOnce this lands, the \"if (iphlen \u003e= sizeof(*iph))\" wrapper around\nthe fixup branch becomes redundant; left in place to keep the\npatch minimal and backport-friendly. A follow-up can unwrap it.\n\nNote that commit 86f4c90a1c5c (\"ipv4, ipv6: ensure raw socket\nmessage is big enough to hold an IP header\") ensures the message\nbuffer is large enough to hold an iphdr, but does not constrain\nthe self-reported iph-\u003eihl.\n\nReachability: the malformed packet source is any caller with\nCAP_NET_RAW, including an unprivileged process in a user+net\nnamespace on a kernel with CONFIG_USER_NS=y. The reproduced AH\ncrash also requires a matching xfrm AH policy on the outgoing\nroute; a container granted CAP_NET_ADMIN can install that state\nand policy in its netns. Loopback bypasses xfrm_output, so the\ntrigger uses a real netdev.\n\nReproduced on UML + KASAN: kernel-mode fault at addr 0x0 with\nmemcpy_orig at the crash site. Same shape reproduces inside a\nrootless Docker container with --cap-add NET_ADMIN on a stock\ndistro kernel.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-64114",
"url": "https://www.suse.com/security/cve/CVE-2026-64114"
},
{
"category": "external",
"summary": "SUSE Bug 1273742 for CVE-2026-64114",
"url": "https://bugzilla.suse.com/1273742"
},
{
"category": "external",
"summary": "SUSE Bug 1273833 for CVE-2026-64114",
"url": "https://bugzilla.suse.com/1273833"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-64114"
},
{
"cve": "CVE-2026-64121",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-64121"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ifb: report ethtool stats over num_tx_queues\n\nifb_dev_init() allocates dp-\u003etx_private to dev-\u003enum_tx_queues\nentries via kzalloc_objs(*txp, dev-\u003enum_tx_queues). Both IFB\nper-queue RX and TX stats live in those entries: ifb_xmit() updates\ntxp-\u003erx_stats using the skb queue mapping, ifb_ri_tasklet() updates\ntxp-\u003etx_stats, and ifb_stats64() aggregates both over\ndev-\u003enum_tx_queues.\n\nThe ethtool stats callbacks instead size and walk the per-queue\nstats with dev-\u003ereal_num_rx_queues and dev-\u003ereal_num_tx_queues. With\nan asymmetric device where the RX queue count exceeds the TX queue\ncount, for example:\n\n ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb\n ethtool -S ifb10\n\nifb_get_ethtool_stats() indexes past the tx_private allocation and\ncopies adjacent slab data through ETHTOOL_GSTATS.\n\nUse dev-\u003enum_tx_queues consistently for the stats strings, the\nstats count, and the stats data walks. This reports one RX stats\ngroup and one TX stats group for each backing ifb_q_private entry,\nwhich is the queue set IFB can actually populate.\n\nReproduced under UML+KASAN at v7.1-rc2:\n\n BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae\n Read of size 8 at addr 0000000062dbd228 by task ethtool/36\n ifb_fill_stats_data+0x3c/0xae\n ifb_get_ethtool_stats+0xc0/0x129\n __dev_ethtool+0x1ca5/0x363c\n dev_ethtool+0x123/0x1b3\n dev_ioctl+0x56c/0x744\n sock_do_ioctl+0x15f/0x1b2\n sock_ioctl+0x4d5/0x50a\n sys_ioctl+0xd8b/0xde9\n\nWith the patch applied, the same UML+KASAN repro is silent and\nethtool -S ifb10 reports only the stats backed by the single\nallocated tx_private entry.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-64121",
"url": "https://www.suse.com/security/cve/CVE-2026-64121"
},
{
"category": "external",
"summary": "SUSE Bug 1273743 for CVE-2026-64121",
"url": "https://bugzilla.suse.com/1273743"
},
{
"category": "external",
"summary": "SUSE Bug 1273837 for CVE-2026-64121",
"url": "https://bugzilla.suse.com/1273837"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-64121"
},
{
"cve": "CVE-2026-64189",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-64189"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix race between dump and ip_set_list resize\n\nThe release path of ip_set_dump_do() and ip_set_dump_done() read\ninst-\u003eip_set_list via ip_set_ref_netlink(), a plain rcu_dereference_raw()\nof the array pointer. These run from netlink_recvmsg() without the nfnl\nmutex and without an RCU read-side critical section.\n\nA concurrent ip_set_create() can grow the array: it publishes the new\narray, calls synchronize_net() and then kvfree()s the old one. Since the\ndump paths read the array outside any RCU reader, synchronize_net() does\nnot wait for them and the old array can be freed while they still index\ninto it, causing a use-after-free.\n\nThe dumped set itself stays pinned via set-\u003eref_netlink, so only the\narray load needs protecting. Take rcu_read_lock() around it, matching\nip_set_get_byname() and __ip_set_put_byindex().\n\n BUG: KASAN: slab-use-after-free in ip_set_dump_do (net/netfilter/ipset/ip_set_core.c:1697)\n Read of size 8 at addr ffff88800b5c4018 by task exploit/150\n Call Trace:\n ...\n kasan_report (mm/kasan/report.c:595)\n ip_set_dump_do (net/netfilter/ipset/ip_set_core.c:1697)\n netlink_dump (net/netlink/af_netlink.c:2325)\n netlink_recvmsg (net/netlink/af_netlink.c:1976)\n sock_recvmsg (net/socket.c:1159)\n __sys_recvfrom (net/socket.c:2315)\n ...\n Oops: general protection fault, probably for non-canonical address ... KASAN NOPTI\n KASAN: maybe wild-memory-access in range [0x02d6...d0-0x02d6...d7]\n RIP: 0010:ip_set_dump_do (net/netfilter/ipset/ip_set_core.c:1698)\n Kernel panic - not syncing: Fatal exception",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-64189",
"url": "https://www.suse.com/security/cve/CVE-2026-64189"
},
{
"category": "external",
"summary": "SUSE Bug 1272207 for CVE-2026-64189",
"url": "https://bugzilla.suse.com/1272207"
},
{
"category": "external",
"summary": "SUSE Bug 1272208 for CVE-2026-64189",
"url": "https://bugzilla.suse.com/1272208"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-64189"
},
{
"cve": "CVE-2026-68121",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-68121"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team\u0027s delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb\u0027s network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-68121",
"url": "https://www.suse.com/security/cve/CVE-2026-68121"
},
{
"category": "external",
"summary": "SUSE Bug 1274888 for CVE-2026-68121",
"url": "https://bugzilla.suse.com/1274888"
},
{
"category": "external",
"summary": "SUSE Bug 1275228 for CVE-2026-68121",
"url": "https://bugzilla.suse.com/1275228"
},
{
"category": "external",
"summary": "SUSE Bug 1282946 for CVE-2026-68121",
"url": "https://bugzilla.suse.com/1282946"
},
{
"category": "external",
"summary": "SUSE Bug 1282953 for CVE-2026-68121",
"url": "https://bugzilla.suse.com/1282953"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-68121"
},
{
"cve": "CVE-2026-68202",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-68202"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q-\u003etimer-\u003etimeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q-\u003etimer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q-\u003etimer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, -\u003etimeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq-\u003etimer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q-\u003etimer (via snd_seq_check_queue()),\nso q-\u003etimer must stay valid until it drains.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-68202",
"url": "https://www.suse.com/security/cve/CVE-2026-68202"
},
{
"category": "external",
"summary": "SUSE Bug 1275161 for CVE-2026-68202",
"url": "https://bugzilla.suse.com/1275161"
},
{
"category": "external",
"summary": "SUSE Bug 1275162 for CVE-2026-68202",
"url": "https://bugzilla.suse.com/1275162"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-68202"
},
{
"cve": "CVE-2026-74394",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-74394"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: fix integer overflow in immediate data length check\n\nimm_buf-\u003elen is a user-controlled uint32_t received from the network.\nAdding it to imm_data_offset without overflow checking allows a\nmalicious initiator to send len=0xFFFFFFFF, causing req_size to wrap\naround to a small value, bypassing the bounds check, and subsequently\npassing a ~4GB length to sg_init_one().\n\nUse check_add_overflow() to detect wrapping before the comparison.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-74394",
"url": "https://www.suse.com/security/cve/CVE-2026-74394"
},
{
"category": "external",
"summary": "SUSE Bug 1277408 for CVE-2026-74394",
"url": "https://bugzilla.suse.com/1277408"
},
{
"category": "external",
"summary": "SUSE Bug 1277409 for CVE-2026-74394",
"url": "https://bugzilla.suse.com/1277409"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-74394"
},
{
"cve": "CVE-2026-74612",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-74612"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nveth: fix skb length accounting after XDP frag adjustment\n\nveth exposes non-linear skb fragments through an xdp_buff. If an XDP\nprogram adjusts the fragment area, veth_xdp_rcv_skb() copies\nxdp_frags_size back to skb-\u003edata_len but leaves skb-\u003elen containing the\nold fragment contribution.\n\nAfter a fragment shrink, this makes skb_headlen() larger than the actual\nlinear area. In the reproduced UDP receive path, __skb_datagram_iter()\ncopied 1024 bytes past the actual linear tail to userspace, starting at\nstruct skb_shared_info. The copied bytes included the affected skb\u0027s\nnr_frags, xdp_frags_size, and a kernel pointer from\nskb_shinfo(skb)-\u003efrags[0]. Real packet data was displaced by the same\namount and truncated at the end.\n\nSubtract the old data_len before replacing it and add the new data_len\nafterwards, keeping skb-\u003elen and skb-\u003edata_len synchronized.\n\nAdditionally, bpf_xdp_pull_data() can advance data_end while leaving\nfrags present. The skb is then still non-linear, so the old\n__skb_put(skb, off) triggers SKB_LINEAR_ASSERT().\n\nUse skb_set_tail_pointer() and update skb-\u003elen explicitly instead,\nfollowing bpf_prog_run_generic_xdp(). Unlike __skb_put(),\nskb_set_tail_pointer() does not require a linear skb.\n\nA 60000-byte UDP datagram on a veth pair with MTU 64000 was shortened by\n1024 bytes from its fragment area. Before the fix, all 10 runs produced\ncorrupted payloads. After the fix, all 10 runs matched the expected\npayload exactly. A forced-tailroom reproducer also exercises\nbpf_xdp_pull_data() with frags still present; the old code triggers\nSKB_LINEAR_ASSERT(), while this fix passes 10/10 runs.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-74612",
"url": "https://www.suse.com/security/cve/CVE-2026-74612"
},
{
"category": "external",
"summary": "SUSE Bug 1277505 for CVE-2026-74612",
"url": "https://bugzilla.suse.com/1277505"
},
{
"category": "external",
"summary": "SUSE Bug 1277506 for CVE-2026-74612",
"url": "https://bugzilla.suse.com/1277506"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Linux Enterprise Live Patching 15 SP7:kernel-livepatch-6_4_0-150700_7_44-rt-0:8-150700.2.1.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-10-02T08:33:42Z",
"details": "important"
}
],
"title": "CVE-2026-74612"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…