SUSE-SU-2026:22108-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622108-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22108-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22108-1
Upstream
  • CVE-2026-3150
Related
Published
2026-06-15T18:32:29Z
Modified
2026-06-17T09:15:06.724017524Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2025-38549: efivarfs: Fix memory leak of efivarfsfsinfo in fs_context error paths (bsc#1248235).
  • CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416).
  • CVE-2026-23303: smb: client: Don't log plaintext credentials in cifssetcifscreds (bsc#1260502).
  • CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxlpayloadfromuserallowed()
  • CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584).
  • CVE-2026-23438: net: mvpp2: guard flow control update with globaltxfc in buffer switching (bsc#1261619).
  • CVE-2026-23444: wifi: mac80211: always free skb on ieee80211txprepare_skb() failure (bsc#1266307).
  • CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791).
  • CVE-2026-31446: ext4: fix use-after-free in updatesuperwork when racing with umount (bsc#1262619).
  • CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622).
  • CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624).
  • CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615).
  • CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfcdiscovertargets_done() (bsc#1262656).
  • CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with reqqueuemutex (bsc#1262663).
  • CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634).
  • CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668).
  • CVE-2026-3150: bcache: fix cacheddev.sbbio use-after-free and crash (bsc#1263169).
  • CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755).
  • CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606).
  • CVE-2026-31546: net: bonding: fix NULL deref in bonddebugrlbhashshow (bsc#1263006).
  • CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVMMEMORYENCRYPTREGREGION (bsc#1263152).
  • CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2groupextend (bsc#1263319).
  • CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769).
  • CVE-2026-31614: smb: client: fix off-by-8 bounds check in checkwsleas() (bsc#1263774).
  • CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790).
  • CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724).
  • CVE-2026-31671: xfrmuser: fix info leak in buildreport() (bsc#1263115).
  • CVE-2026-31673: afunix: read UNIXDIAGVFS data under unixstate_lock (bsc#1263143).
  • CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562).
  • CVE-2026-31703: writeback: Fix use after free in inodeswitchwbsworkfn() (bsc#1263883).
  • CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093).
  • CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124).
  • CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011).
  • CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTAEXPECTNAT absent (bsc#1263932).
  • CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000).
  • CVE-2026-43040: net: ipv6: ndisc: fix ndiscrauseropt to initialize nduseropt_padX fields to zero (bsc#1264091).
  • CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211tdlsoper (bsc#1263945).
  • CVE-2026-43054: scsi: target: tcmloop: Drain commands in targetreset handler (bsc#1264063).
  • CVE-2026-43059: Bluetooth: MGMT: fix crash in setmeshsync and setmeshcomplete (bsc#1264184).
  • CVE-2026-43065: ext4: always drain queued discard work in ext4mbrelease() (bsc#1264243).
  • CVE-2026-43066: ext4: fix iloc.bh leak in ext4fcreplay_inode() error paths (bsc#1264245).
  • CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4mbfindbygoal() (bsc#1264255).
  • CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484).
  • CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfdeventpage_set() (bsc#1264551).
  • CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409).
  • CVE-2026-43249: 9p/xen: protect xen9pfsfront_free against concurrent calls (bsc#1264476).
  • CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300).
  • CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430).
  • CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805).
  • CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110).
  • CVE-2026-43333: bpf: reject direct access to nullable PTRTOBUF pointers (bsc#1264726).
  • CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716).
  • CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044).
  • CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719).
  • CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720).
  • CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722).
  • CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989).
  • CVE-2026-43406: libceph: prevent potential out-of-bounds reads in processmessageheader() (bsc#1265073).
  • CVE-2026-43407: libceph: Fix potential out-of-bounds access in cephhandleauth_reply() (bsc#1265020).
  • CVE-2026-43411: tipc: fix divide-by-zero in tipcskfilter_connect() (bsc#1264672).
  • CVE-2026-43413: scsi: hisisas: Fix NULL pointer exception during userscan() (bsc#1264671).
  • CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669).
  • CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765).
  • CVE-2026-43470: nfs: return EISDIR on nfs3proccreate if d_alias is a dir (bsc#1265128).
  • CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240).
  • CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).
  • CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009).
  • CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400).
  • CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395).
  • CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudpfillmetadata_dst() (bsc#1266394).
  • CVE-2026-45852: RDMA/rxe: Fix double free in rxesrqfrom_init (bsc#1266711).
  • CVE-2026-45856: RDMA/uverbs: Validate wqesize before using it in ibuverbspostsend (bsc#1266720).
  • CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767).
  • CVE-2026-45886: bpf: Fix bpfxdpstore_bytes proto for read-only arg (bsc#1266810).
  • CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889).
  • CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827).
  • CVE-2026-45970: bonding: alb: fix UAF in rlbarprecv during bond up/down (bsc#1267205).
  • CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697).
  • CVE-2026-45984: gfs2: Add metapath_dibh helper (bsc#1267214).
  • CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222).
  • CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).
  • CVE-2026-46024: libceph: Prevent potential null-ptr-deref in cephhandleauth_reply() (bsc#1267218).
  • CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payloadsize() in rxercv (bsc#1266901).
  • CVE-2026-46079: rbd: fix null-ptr-deref when deviceadddisk() fails (bsc#1266452).
  • CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696).
  • CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531).
  • CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927).
  • CVE-2026-46110: net: stmmac: rename STMMACGETENTRY() -> STMMACNEXTENTRY() (bsc#1266759).
  • CVE-2026-46111: Bluetooth: hciconn: fix potential UAF in createbig_sync (bsc#1267626).
  • CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969).
  • CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972).
  • CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726).
  • CVE-2026-46159: btrfs: fix btrfsioctlspaceinfo() slotcount TOCTOU which can lead to info-leak (bsc#1267652).
  • CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5ibdevressrq_init() (bsc#1266816).
  • CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4srqevent() (bsc#1266826).
  • CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drmgemfbinitwith_funcs() (bsc#1267663).

The following non-security bugs were fixed:

  • ALSA: PCM: Fix wait queue list corruption in sndpcmdrain() on linked streams (git-fixes).
  • ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes).
  • ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes).
  • ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes).
  • ALSA: sc6000: Use standard print API (stable-fixes).
  • ALSA: ua101: Reject too-short USB descriptors (git-fixes).
  • ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes).
  • ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes).
  • ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes).
  • ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes).
  • ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes).
  • ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes).
  • ASoC: cs35l56: Fix flushing of IRQ work in cs35l56sdwremove() (git-fixes).
  • ASoC: qcom: q6asm-dai: close stream only when running (git-fixes).
  • ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes).
  • ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes).
  • Bluetooth: 6lowpan: check skbclone() return value in sendmcast_pkt() (git-fixes).
  • Bluetooth: HIDP: fix missing length checks in hidpinputreport() (git-fixes).
  • Bluetooth: ISO: drop ISOEND frames received without prior ISOSTART (git-fixes).
  • Bluetooth: ISO: fix UAF in isorecvframe (git-fixes).
  • Bluetooth: ISO: serialize isosockclear_timer with socket lock (git-fixes).
  • Bluetooth: L2CAP: Fix possible crash on l2capecredconn_rsp (git-fixes).
  • Bluetooth: L2CAP: fix chan ref leak in l2capchantimeout() on !conn (git-fixes).
  • Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes).
  • Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes).
  • Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes).
  • Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes).
  • Bluetooth: RFCOMM: hold listener socket in rfcommconnectind() (git-fixes).
  • Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes).
  • Bluetooth: bnep: Fix UAF read of dev->name (git-fixes).
  • Bluetooth: bnep: reject short frames before parsing (git-fixes).
  • Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes).
  • Bluetooth: fix UAF in l2capsockcleanuplisten() vs l2capconn_del() (git-fixes).
  • Bluetooth: hcisync: Set HCICMDDRAINWORKQUEUE during device close (git-fixes).
  • Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes).
  • Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes).
  • Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes).
  • HID: quirks: really enable the intended work around for appledisplay (git-fixes).
  • HID: uclogic: Fix regression of input name assignment (git-fixes).
  • HID: wacom: Fix OOB write in wacomhidsetdevicemode() (git-fixes).
  • Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes).
  • Input: atmelmxtts - fix boundary check in mxtpreparecfg_mem (git-fixes).
  • Input: ims-pcu - fix usbfreecoherent() size in imspcubuffers_free() (git-fixes).
  • Input: usbtouchscreen - clamp NEXIO datalen/xlen to URB buffer size (git-fixes).
  • Input: xpad - fix out-of-bounds access for Share button (git-fixes).
  • KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes).
  • KVM: X86: Fix arrayindexnospec protection in __pvsendipi (git-fixes).
  • KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git-fixes).
  • KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes).
  • RDMA/efa: Check stored completion CTX command ID with received one (git-fixes)
  • RDMA/efa: Extend admin timeout error print (git-fixes)
  • RDMA/efa: Fix possible deadlock (git-fixes)
  • RDMA/efa: Improve admin completion context state machine (git-fixes)
  • RDMA/manaib: Report maxmsgsz in manaibqueryport (git-fixes).
  • USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes).
  • USB: serial: belkin_sa: validate interrupt status length (git-fixes).
  • USB: serial: cypress_m8: validate interrupt packet headers (git-fixes).
  • USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes).
  • USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes).
  • USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes).
  • USB: serial: omninet: fix memory corruption with small endpoint (git-fixes).
  • USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes).
  • USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes).
  • arm64: tlb: Allow XZR argument to TLBI ops (git-fixes)
  • arm64: tlb: Optimize ARM64WORKAROUNDREPEAT_TLBI (git-fixes)
  • auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes).
  • batman-adv: bla: fix reportwork leak on backbonegw purge (git-fixes).
  • batman-adv: clear current gateway during teardown (git-fixes).
  • batman-adv: dat: handle forward allocation error (git-fixes).
  • batman-adv: fix batadvskbis_frag() kernel-doc (git-fixes).
  • batman-adv: fix fragment reassembly length accounting (git-fixes).
  • batman-adv: fix tp_meter counter underflow during shutdown (git-fixes).
  • batman-adv: frag: disallow unicast fragment in fragment (git-fixes).
  • batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes).
  • batman-adv: tt: fix negative lastchangesetlen (git-fixes).
  • batman-adv: tt: fix negative ttbufflen (git-fixes).
  • bcache: fix uninitialized closure object (git-fixes).
  • comedi: comeditest: Fix limiting of convertarg in waveformaicmdtest() (git-fixes).
  • comedi: comeditest: fix check for valid scanbeginsrc in waveformai_cmdtest() (git-fixes).
  • device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes).
  • drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes).
  • drm/amd/display: Clamp HDMI HDCP2 rxidlist read to buffer size (git-fixes).
  • drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes).
  • drm/amd/display: Fix integer overflow in biosgetimage() (stable-fixes).
  • drm/amd/display: Reject gpiobitshift >= 32 in biosparsergetgpiopininfo() (git-fixes).
  • drm/amd/display: Use kreallocarray() in dalvector_reserve() (git-fixes).
  • drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes).
  • drm/amd/display: Validate payload length and linkindex in dcprocessdmubauxtransferasync (stable-fixes).
  • drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes).
  • drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git-fixes).
  • drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes).
  • drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes).
  • drm/amdgpu: fix spelling typos (stable-fixes).
  • drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes).
  • drm/amdkfd: fix NULL dereference in getqueueids() (git-fixes).
  • drm/bridge: chipone-icn6211: use devmdrmbridge_add in i2c probe (git-fixes).
  • drm/bridge: it66121: acquire reset GPIO in probe (git-fixes).
  • drm/bridge: megachips: remove bridge when irq request fails (git-fixes).
  • drm/hyperv: validate VMBus packet size in receive callback (git-fixes).
  • drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes).
  • drm/i915: Extract inteldbufmdclkcdclkratio_update() (stable-fixes).
  • drm/i915: Fix potential UAF in TTM object purge (git-fixes).
  • drm/i915: Loop over all active pipes in intelmbusdbox_update (stable-fixes).
  • drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes).
  • drm/msm/dsi: do not dump registers past the mapped region (git-fixes).
  • drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes).
  • drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes).
  • drm/virtio: use uninterruptible resv lock for plane updates (git-fixes).
  • efi: Allocate runtime workqueue before ACPI init (git-fixes).
  • firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes).
  • firmware: armffa: Skip freepages on RX buffer alloc failure (git-fixes).
  • hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes).
  • hwmon: (pmbus/adm1266) cap PDIO scan in getmultiple at ADM1266PDIO_NR (git-fixes).
  • hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes).
  • hwmon: (pmbus/adm1266) include PEC byte in pmbusblockxfer read buffer (git-fixes).
  • hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes).
  • hwmon: (pmbus/adm1266) register the gpiochip after pmbusdo_probe() (git-fixes).
  • hwmon: (pmbus/adm1266) register the nvmem device after pmbusdoprobe() (git-fixes).
  • hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes).
  • hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes).
  • hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes).
  • hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2CSMBUSBLOCK_MAX (git-fixes).
  • iio: adc: viperboard: Fix error handling in vprbrdiioread_raw (git-fixes).
  • iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes).
  • iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes).
  • iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes).
  • iio: dac: ad5686: fix input raw value check (git-fixes).
  • iio: dac: max5821: fix return value check in powerdown sync (git-fixes).
  • iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes).
  • iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes).
  • iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes).
  • iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes).
  • iio: sspsensors: cancel delayed workrefresh on remove (git-fixes).
  • iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes).
  • mmc: core: Fix host controller programming for fixed driver type (git-fixes).
  • mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes).
  • mmc: litexmmc: Use DIVROUND_UP for more accurate clock calculation (git-fixes).
  • mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes).
  • mmc: sdhci: add signal voltage switch in sdhciresumehost (git-fixes).
  • net: gro: do not merge zcopy skbs (git-fixes).
  • net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes).
  • net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414).
  • net: mana: Fix TOCTOU double-fetch of hwcmsgid from DMA buffer (bsc#1265928).
  • net: mana: Skip redundant detach on already-detached port (git-fixes).
  • net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765).
  • net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765).
  • net: mana: hardening: Reject zero maxnumqueues from GDMAQUERYMAX_RESOURCES (git-fixes).
  • net: mana: validate rxreqidx to prevent out-of-bounds array access (bsc#1266402).
  • net: wwan: iosm: fix potential memory leaks in ipcimeminit() (git-fixes).
  • parport: Fix race between port and client registration (git-fixes).
  • phy: marvell: mvebu-a3700-utmi: fix incorrect USB2PHYCTRL register access (git-fixes).
  • platform/x86: advswbutton: Check ACPIHANDLE() against NULL (git-fixes).
  • platform/x86: hpaccel: Check ACPICOMPANION() against NULL (git-fixes).
  • platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes).
  • platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes).
  • r8152: fix incorrect register write to USBUPHYXTAL (git-fixes).
  • rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538).
  • rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538).
  • rpm: Add BuildRequires for Rust enablement (bsc#1258538).
  • s390/barrier: Make arrayindexmask_nospec() _alwaysinline (bsc#1263068).
  • s390/entry: Scrub r12 register on kernel entry (bsc#1263068).
  • s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068).
  • sched/rt: Skip currently executing CPU in rtonextcpu() (bsc#1262649).
  • security/keys: fix missed RCU read section on lookup (stable-fixes).
  • serial: fsllpuart: fix rx buffer and DMA map leaks in startrx_dma (git-fixes).
  • serial: qcom-geni: fix UARTRXPAR_EN bit position (git-fixes).
  • smb: client: correctly handle ErrorContextData as a flexible array (git-fixes)
  • smb: client: reject userspace cifs.spnego descriptions (bsc#1266238).
  • spi: mtk-snfi: Fix resource leak in mtksnandreadpagecache() (git-fixes).
  • spi: sprd: fix error pointer deref after DMA setup failure (git-fixes).
  • spi: st-ssc4: switch to use modern name (stable-fixes).
  • spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes).
  • string: add memiszero() helper to check if memory area is all zeros (stable-fixes).
  • thunderbolt: property: Reject dirlen < 4 to prevent sizet underflow (git-fixes).
  • thunderbolt: property: Reject u32 wrap in tbpropertyentry_valid() (git-fixes).
  • tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634).
  • tty: serial: pchuart: add check for dmaalloc_coherent() (git-fixes).
  • usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes).
  • usb: chipidea: core: convert ciroleswitch to local variable (git-fixes).
  • usb: dwc2: Fix use after free in debug code (git-fixes).
  • usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes).
  • usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes).
  • usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes).
  • usb: gadget: fhid: fix device reference leak in hidgalloc() (git-fixes).
  • usb: gadget: net2280: Fix double free in probe error path (git-fixes).
  • usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes).
  • usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes).
  • usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes).
  • wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes).
  • wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes).
  • wifi: ath11k: fix error path leak in ath11ktmcmdwmiftm() (git-fixes).
  • wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes).
  • wifi: ath11k: fix error path leaks in some WMI calls (git-fixes).
  • wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes).
  • wifi: ath11k: fix use after free in ath11kdprxmsducoalesce() (git-fixes).
  • wifi: cfg80211: advance loop vars in cfg80211mergeprofile() (git-fixes).
  • wifi: mac80211: consume only present negotiated TTLM maps (git-fixes).
  • wifi: mac80211: limit injected antenna index in ieee80211parsetx_radiotap (git-fixes).
  • wifi: nl80211: reject oversized EMA RNR lists (git-fixes).
References

Affected packages

SUSE:Linux Micro 6.0 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-47.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-base": "6.4.0-47.1.21.24",
            "kernel-kvmsmall": "6.4.0-47.1",
            "kernel-default-livepatch": "6.4.0-47.1",
            "kernel-default": "6.4.0-47.1",
            "kernel-devel": "6.4.0-47.1",
            "kernel-macros": "6.4.0-47.1",
            "kernel-source": "6.4.0-47.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22108-1.json"

SUSE:Linux Micro 6.0 / kernel-default-base

Package

Name
kernel-default-base
Purl
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-47.1.21.24

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-base": "6.4.0-47.1.21.24",
            "kernel-kvmsmall": "6.4.0-47.1",
            "kernel-default-livepatch": "6.4.0-47.1",
            "kernel-default": "6.4.0-47.1",
            "kernel-devel": "6.4.0-47.1",
            "kernel-macros": "6.4.0-47.1",
            "kernel-source": "6.4.0-47.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22108-1.json"

SUSE:Linux Micro 6.0 / kernel-kvmsmall

Package

Name
kernel-kvmsmall
Purl
pkg:rpm/suse/kernel-kvmsmall&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-47.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-base": "6.4.0-47.1.21.24",
            "kernel-kvmsmall": "6.4.0-47.1",
            "kernel-default-livepatch": "6.4.0-47.1",
            "kernel-default": "6.4.0-47.1",
            "kernel-devel": "6.4.0-47.1",
            "kernel-macros": "6.4.0-47.1",
            "kernel-source": "6.4.0-47.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22108-1.json"

SUSE:Linux Micro 6.0 / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-47.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-base": "6.4.0-47.1.21.24",
            "kernel-kvmsmall": "6.4.0-47.1",
            "kernel-default-livepatch": "6.4.0-47.1",
            "kernel-default": "6.4.0-47.1",
            "kernel-devel": "6.4.0-47.1",
            "kernel-macros": "6.4.0-47.1",
            "kernel-source": "6.4.0-47.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22108-1.json"