Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2383-1

Опубликовано: 12 июн. 2026
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700).
  • CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790).
  • CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093).
  • CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995).
  • CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551).
  • CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).
  • CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009).
  • CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711).
  • CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205).
  • CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).
  • CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901).
  • CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969).
  • CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238).

The following non security issues were fixed:

  • arm64: tlb: Allow XZR argument to TLBI ops (git-fixes).
  • arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes).

Список пакетов

Container suse/sle-micro-rancher/5.3:latest
kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS-Aliyun
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-BYOS
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-BYOS-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-BYOS-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-BYOS-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-HPC-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-Hardened-BYOS
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-Hardened-BYOS-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-Hardened-BYOS-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-Hardened-BYOS-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-BYOS
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-BYOS-Azure
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-BYOS-EC2
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-BYOS-GCE
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-GCE
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-Azure
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-BYOS
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAP-Hardened-GCE
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAPCAL
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAPCAL-Azure
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAPCAL-EC2
kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-SAPCAL-GCE
kernel-default-5.14.21-150400.24.222.1
SUSE Linux Enterprise High Availability Extension 15 SP4
cluster-md-kmp-default-5.14.21-150400.24.222.1
dlm-kmp-default-5.14.21-150400.24.222.1
gfs2-kmp-default-5.14.21-150400.24.222.1
ocfs2-kmp-default-5.14.21-150400.24.222.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
kernel-64kb-5.14.21-150400.24.222.1
kernel-64kb-devel-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-default-devel-5.14.21-150400.24.222.1
kernel-devel-5.14.21-150400.24.222.1
kernel-docs-5.14.21-150400.24.222.1
kernel-macros-5.14.21-150400.24.222.1
kernel-obs-build-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
kernel-syms-5.14.21-150400.24.222.1
reiserfs-kmp-default-5.14.21-150400.24.222.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
kernel-64kb-5.14.21-150400.24.222.1
kernel-64kb-devel-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-default-devel-5.14.21-150400.24.222.1
kernel-devel-5.14.21-150400.24.222.1
kernel-docs-5.14.21-150400.24.222.1
kernel-macros-5.14.21-150400.24.222.1
kernel-obs-build-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
kernel-syms-5.14.21-150400.24.222.1
reiserfs-kmp-default-5.14.21-150400.24.222.1
SUSE Linux Enterprise Live Patching 15 SP4
kernel-default-livepatch-5.14.21-150400.24.222.1
kernel-default-livepatch-devel-5.14.21-150400.24.222.1
kernel-livepatch-5_14_21-150400_24_222-default-1-150400.9.3.1
SUSE Linux Enterprise Micro 5.3
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-macros-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
SUSE Linux Enterprise Micro 5.4
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-macros-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
SUSE Linux Enterprise Server 15 SP4-LTSS
kernel-64kb-5.14.21-150400.24.222.1
kernel-64kb-devel-5.14.21-150400.24.222.1
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-default-devel-5.14.21-150400.24.222.1
kernel-devel-5.14.21-150400.24.222.1
kernel-docs-5.14.21-150400.24.222.1
kernel-macros-5.14.21-150400.24.222.1
kernel-obs-build-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
kernel-syms-5.14.21-150400.24.222.1
kernel-zfcpdump-5.14.21-150400.24.222.1
reiserfs-kmp-default-5.14.21-150400.24.222.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
kernel-default-5.14.21-150400.24.222.1
kernel-default-base-5.14.21-150400.24.222.1.150400.24.112.1
kernel-default-devel-5.14.21-150400.24.222.1
kernel-devel-5.14.21-150400.24.222.1
kernel-docs-5.14.21-150400.24.222.1
kernel-macros-5.14.21-150400.24.222.1
kernel-obs-build-5.14.21-150400.24.222.1
kernel-source-5.14.21-150400.24.222.1
kernel-syms-5.14.21-150400.24.222.1
reiserfs-kmp-default-5.14.21-150400.24.222.1

Описание

In the Linux kernel, the following vulnerability has been resolved: media: dvb-net: fix OOB access in ULE extension header tables The ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables in handle_one_ule_extension() are declared with 255 elements (valid indices 0-254), but the index htype is derived from network-controlled data as (ule_sndu_type & 0x00FF), giving a range of 0-255. When htype equals 255, an out-of-bounds read occurs on the function pointer table, and the OOB value may be called as a function pointer. Add a bounds check on htype against the array size before either table is accessed. Out-of-range values now cause the SNDU to be discarded.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading to a use-after-free. Add the missing return statements after the LLCP_CLOSED branches in both functions to prevent the fall-through.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: usbtmc: Flush anchored URBs in usbtmc_release When calling usbtmc_release, pending anchored URBs must be flushed or killed to prevent use-after-free errors (e.g. in the HCD giveback path). Call usbtmc_draw_down() to allow anchored URBs to be completed.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as struct inet6_skb_parm. icmp_send() passes IPCB(skb2) to __ip_options_echo(), which interprets that cb[] region as struct inet_skb_parm (IPv4). The layouts differ: inet6_skb_parm.nhoff at offset 14 overlaps inet_skb_parm.opt.rr, producing a non-zero rr value. __ip_options_echo() then reads optlen from attacker-controlled packet data at sptr[rr+1] and copies that many bytes into dopt->__data, a fixed 40-byte stack buffer (IP_OPTIONS_DATA_FIXED_SIZE). To fix this we clear skb2->cb[], as suggested by Oskar Kjos. Also add minimal IPv4 header validation (version == 4, ihl >= 5).


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() The kfd_event_page_set() function writes KFD_SIGNAL_EVENT_LIMIT * 8 bytes via memset without checking the buffer size parameter. This allows unprivileged userspace to trigger an out-of bounds kernel memory write by passing a small buffer, leading to potential privilege escalation.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked from futex_requeue(). In the latter case waiter::task is not current, but remove_waiter() operates on current for the dequeue operation. That results in several problems: 1) the rbtree dequeue happens without waiter::task::pi_lock being held 2) the waiter task's pi_blocked_on state is not cleared, which leaves a dangling pointer primed for UAF around. 3) rt_mutex_adjust_prio_chain() operates on the wrong top priority waiter task Use waiter::task instead of current in all related operations in remove_waiter() to cure those problems. [ tglx: Fixup rt_mutex_adjust_prio_chain(), add a comment and amend the changelog ]


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows ipv6_rpl_srh_rcv() decompresses an RFC 6554 Source Routing Header, swaps the next segment into ipv6_hdr->daddr, recompresses, then pulls the old header and pushes the new one plus the IPv6 header back. The recompressed header can be larger than the received one when the swap reduces the common-prefix length the segments share with daddr (CmprI=0, CmprE>0, seg[0][0] != daddr[0] gives the maximum +8 bytes). pskb_expand_head() was gated on segments_left == 0, so on earlier segments the push consumed unchecked headroom. Once skb_push() leaves fewer than skb->mac_len bytes in front of data, skb_mac_header_rebuild()'s call to: skb_set_mac_header(skb, -skb->mac_len); will store (data - head) - mac_len into the u16 mac_header field, which wraps to ~65530, and the following memmove() writes mac_len bytes ~64KiB past skb->head. A single AF_INET6/SOCK_RAW/IPV6_HDRINCL packet over lo with a two segment type-3 SRH (CmprI=0, CmprE=15) reaches headroom 8 after one pass; KASAN reports a 14-byte OOB write in ipv6_rthdr_rcv. Fix this by expanding the head whenever the remaining room is less than the push size plus mac_len, and request that much extra so the rebuilt MAC header fits afterwards.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix double free in rxe_srq_from_init In rxe_srq_from_init(), the queue pointer 'q' is assigned to 'srq->rq.queue' before copying the SRQ number to user space. If copy_to_user() fails, the function calls rxe_queue_cleanup() to free the queue, but leaves the now-invalid pointer in 'srq->rq.queue'. The caller of rxe_srq_from_init() (rxe_create_srq) eventually calls rxe_srq_cleanup() upon receiving the error, which triggers a second rxe_queue_cleanup() on the same memory, leading to a double free. The call trace looks like this: kmem_cache_free+0x.../0x... rxe_queue_cleanup+0x1a/0x30 [rdma_rxe] rxe_srq_cleanup+0x42/0x60 [rdma_rxe] rxe_elem_release+0x31/0x70 [rdma_rxe] rxe_create_srq+0x12b/0x1a0 [rdma_rxe] ib_create_srq_user+0x9a/0x150 [ib_core] Fix this by moving 'srq->rq.queue = q' after copy_to_user.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bonding: alb: fix UAF in rlb_arp_recv during bond up/down The ALB RX path may access rx_hashtbl concurrently with bond teardown. During rapid bond up/down cycles, rlb_deinitialize() frees rx_hashtbl while RX handlers are still running, leading to a null pointer dereference detected by KASAN. However, the root cause is that rlb_arp_recv() can still be accessed after setting recv_probe to NULL, which is actually a use-after-free (UAF) issue. That is the reason for using the referenced commit in the Fixes tag. [ 214.174138] Oops: general protection fault, probably for non-canonical address 0xdffffc000000001d: 0000 [#1] SMP KASAN PTI [ 214.186478] KASAN: null-ptr-deref in range [0x00000000000000e8-0x00000000000000ef] [ 214.194933] CPU: 30 UID: 0 PID: 2375 Comm: ping Kdump: loaded Not tainted 6.19.0-rc8+ #2 PREEMPT(voluntary) [ 214.205907] Hardware name: Dell Inc. PowerEdge R730/0WCJNT, BIOS 2.14.0 01/14/2022 [ 214.214357] RIP: 0010:rlb_arp_recv+0x505/0xab0 [bonding] [ 214.220320] Code: 0f 85 2b 05 00 00 48 b8 00 00 00 00 00 fc ff df 40 0f b6 ed 48 c1 e5 06 49 03 ad 78 01 00 00 48 8d 7d 28 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 06 0f 8e 12 05 00 00 80 7d 28 00 0f 84 8c 00 [ 214.241280] RSP: 0018:ffffc900073d8870 EFLAGS: 00010206 [ 214.247116] RAX: dffffc0000000000 RBX: ffff888168556822 RCX: ffff88816855681e [ 214.255082] RDX: 000000000000001d RSI: dffffc0000000000 RDI: 00000000000000e8 [ 214.263048] RBP: 00000000000000c0 R08: 0000000000000002 R09: ffffed11192021c8 [ 214.271013] R10: ffff8888c9010e43 R11: 0000000000000001 R12: 1ffff92000e7b119 [ 214.278978] R13: ffff8888c9010e00 R14: ffff888168556822 R15: ffff888168556810 [ 214.286943] FS: 00007f85d2d9cb80(0000) GS:ffff88886ccb3000(0000) knlGS:0000000000000000 [ 214.295966] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 214.302380] CR2: 00007f0d047b5e34 CR3: 00000008a1c2e002 CR4: 00000000001726f0 [ 214.310347] Call Trace: [ 214.313070] <IRQ> [ 214.315318] ? __pfx_rlb_arp_recv+0x10/0x10 [bonding] [ 214.320975] bond_handle_frame+0x166/0xb60 [bonding] [ 214.326537] ? __pfx_bond_handle_frame+0x10/0x10 [bonding] [ 214.332680] __netif_receive_skb_core.constprop.0+0x576/0x2710 [ 214.339199] ? __pfx_arp_process+0x10/0x10 [ 214.343775] ? sched_balance_find_src_group+0x98/0x630 [ 214.349513] ? __pfx___netif_receive_skb_core.constprop.0+0x10/0x10 [ 214.356513] ? arp_rcv+0x307/0x690 [ 214.360311] ? __pfx_arp_rcv+0x10/0x10 [ 214.364499] ? __lock_acquire+0x58c/0xbd0 [ 214.368975] __netif_receive_skb_one_core+0xae/0x1b0 [ 214.374518] ? __pfx___netif_receive_skb_one_core+0x10/0x10 [ 214.380743] ? lock_acquire+0x10b/0x140 [ 214.385026] process_backlog+0x3f1/0x13a0 [ 214.389502] ? process_backlog+0x3aa/0x13a0 [ 214.394174] __napi_poll.constprop.0+0x9f/0x370 [ 214.399233] net_rx_action+0x8c1/0xe60 [ 214.403423] ? __pfx_net_rx_action+0x10/0x10 [ 214.408193] ? lock_acquire.part.0+0xbd/0x260 [ 214.413058] ? sched_clock_cpu+0x6c/0x540 [ 214.417540] ? mark_held_locks+0x40/0x70 [ 214.421920] handle_softirqs+0x1fd/0x860 [ 214.426302] ? __pfx_handle_softirqs+0x10/0x10 [ 214.431264] ? __neigh_event_send+0x2d6/0xf50 [ 214.436131] do_softirq+0xb1/0xf0 [ 214.439830] </IRQ> The issue is reproducible by repeatedly running ip link set bond0 up/down while receiving ARP messages, where rlb_arp_recv() can race with rlb_deinitialize() and dereference a freed rx_hashtbl entry. Fix this by setting recv_probe to NULL and then calling synchronize_net() to wait for any concurrent RX processing to finish. This ensures that no RX handler can access rx_hashtbl after it is freed in bond_alb_deinitialize().


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thermal: core: Fix thermal zone governor cleanup issues If thermal_zone_device_register_with_trips() fails after adding a thermal governor to the thermal zone being registered, the governor is not removed from it as appropriate which may lead to a memory leak. In turn, thermal_zone_device_unregister() calls thermal_set_governor() without acquiring the thermal zone lock beforehand which may race with a governor update via sysfs and may lead to a use-after-free in that case. Address these issues by adding two thermal_set_governor() calls, one to thermal_release() to remove the governor from the given thermal zone, and one to the thermal zone registration error path to cover failures preceding the thermal zone device registration.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv rxe_rcv() currently checks only that the incoming packet is at least header_size(pkt) bytes long before payload_size() is used. However, payload_size() subtracts both the attacker-controlled BTH pad field and RXE_ICRC_SIZE from pkt->paylen: payload_size = pkt->paylen - offset[RXE_PAYLOAD] - bth_pad(pkt) - RXE_ICRC_SIZE This means a short packet can still make payload_size() underflow even if it includes enough bytes for the fixed headers. Simply requiring header_size(pkt) + RXE_ICRC_SIZE is not sufficient either, because a packet with a forged non-zero BTH pad can still leave payload_size() negative and pass an underflowed value to later receive-path users. Fix this by validating pkt->paylen against the full minimum length required by payload_size(): header_size(pkt) + bth_pad(pkt) + RXE_ICRC_SIZE.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN The shadow MMU computes GFNs for direct shadow pages using sp->gfn plus the SPTE index. This assumption breaks for shadow paging if the guest page tables are modified between VM entries (similar to commit aad885e77496, "KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE", 2026-03-27). The flow is as follows: - a PDE is installed for a 2MB mapping, and a page in that area is accessed. KVM creates a kvm_mmu_page consisting of 512 4KB pages; the kvm_mmu_page is marked by FNAME(fetch) as direct-mapped because the guest's mapping is a huge page (and thus contiguous). - the PDE mapping is changed from outside the guest. - the guest accesses another page in the same 2MB area. KVM installs a new leaf SPTE and rmap entry; the SPTE uses the "correct" GFN (i.e. based on the new mapping, as changed in the previous step) but that GFN is outside of the [sp->gfn, sp->gfn + 511] range; therefore the rmap entry cannot be found and removed when the kvm_mmu_page is zapped. - the memslot that covers the first 2MB mapping is deleted, and the kvm_mmu_page for the now-invalid GPA is zapped. However, rmap_remove() only looks at the [sp->gfn, sp->gfn + 511] range established in step 1, and fails to find the rmap entry that was recorded by step 3. - any operation that causes an rmap walk for the same page accessed by step 3 then walks a stale rmap and dereferences a freed kvm_mmu_page. This includes dirty logging or MMU notifier invalidations (e.g., from MADV_DONTNEED). The underlying issue is that KVM's walking of shadow PTEs assumes that if a SPTE is present when KVM wants to install a non-leaf SPTE, then the existing kvm_mmu_page must be for the correct gfn. Because the only way for the gfn to be wrong is if KVM messed up and failed to zap a SPTE... which shouldn't happen, but *actually* only happens in response to a guest write. That bug dates back literally forever, as even the first version of KVM assumes that the GFN matches and walks into the "wrong" shadow page. However, that was only an imprecision until 2032a93d66fa ("KVM: MMU: Don't allocate gfns page for direct mmu pages") came along. Fix it by checking for a target gfn mismatch and zapping the existing SPTE. That way the old SP and rmap entries are gone, KVM installs the rmap in the right location, and everyone is happy.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descriptions cifs.spnego key descriptions contain authority-bearing fields such as pid, uid, creduid, and upcall_target that cifs.upcall treats as kernel-originating inputs. However, userspace can also create keys of this type through request_key(2) or add_key(2), allowing those fields to be supplied without CIFS origin. Only accept cifs.spnego descriptions while CIFS is using its private spnego_cred to request the key.


Затронутые продукты
Container suse/sle-micro-rancher/5.3:latest:kernel-default-5.14.21-150400.24.222.1
Container suse/sle-micro-rancher/5.4:latest:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-Azure:kernel-default-5.14.21-150400.24.222.1
Image SLES15-SP4-BYOS-EC2:kernel-default-5.14.21-150400.24.222.1

Ссылки
Уязвимость SUSE-SU-2026:2383-1