SUSE-SU-2026:22436-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202622436-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22436-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:22436-1
Upstream
  • CVE-2025-10263
Related
Published
2026-06-30T23:09:03Z
Modified
2026-07-03T18:24:21.038473869Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
  • CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3registerwork (bsc#1256668).
  • CVE-2026-31414: netfilter: nfconntrackexpect: use expect->helper (bsc#1262085).
  • CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392).
  • CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).
  • CVE-2026-31469: virtionet: Fix UAF on dstops when IFFXMITDSTRELEASE is cleared and napitx is false
  • CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748).
  • CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798).
  • CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2capconndel() (bsc#1262674).
  • CVE-2026-31500: Bluetooth: btintel: serialize btintelhwerror() with hcireqsync_lock (bsc#1262993).
  • CVE-2026-31555: futex: Clear stale exiting pointer in futexlockpi() retry path (bsc#1263178).
  • CVE-2026-31592: KVM: SEV: Protect all of sevmemencregisterregion() with kvm->lock (bsc#1263123).
  • CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578).
  • CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137).
  • CVE-2026-31674: netfilter: ip6trt: reject oversized addrnr in rtmt6_check() (bsc#1263568).
  • CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).
  • CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744).
  • CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).
  • CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).
  • CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).
  • CVE-2026-31752: bridge: brndsend: validate ND option lengths (bsc#1264045).
  • CVE-2026-31759: usb: ulpi: fix double free in ulpiregisterinterface() error path (bsc#1264076).
  • CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).
  • CVE-2026-43023: Bluetooth: SCO: fix race conditions in scosockconnect() (bsc#1264137).
  • CVE-2026-43024: netfilter: nftables: reject immediate NFQUEUE verdict (bsc#1263930).
  • CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).
  • CVE-2026-43035: net: sched: clsapi: fix tcchainfillnode to initialize tcm_info to zero to prevent an info-leak (bsc#1263996).
  • CVE-2026-43036: net: use skbheaderpointer() for TCPv4 GSO frag_off check (bsc#1263993).
  • CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080).
  • CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084).
  • CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263).
  • CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
  • CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266).
  • CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in _ioam6filltracedata() (bsc#1264239).
  • CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifssanitizeprepath (bsc#1264437).
  • CVE-2026-43119: Bluetooth: hcisync: annotate data-races around hdev->reqstatus (bsc#1264561).
  • CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).
  • CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549).
  • CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).
  • CVE-2026-43198: tcp: fix potential race in tcpv6synrecvsock() (bsc#1264610).
  • CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444).
  • CVE-2026-43339: ipv6: prevent possible UaF in addrconfpermanentaddr() (bsc#1264763).
  • CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103).
  • CVE-2026-43405: libceph: Use u32 for non-negative values in cephmonmapdecode() (bsc#1264741).
  • CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143).
  • CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628).
  • CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).
  • CVE-2026-45841: netfilter: nfnetlinkosf: fix divide-by-zero in OSFWSS_MODULO (bsc#1266390).
  • CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705).
  • CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).
  • CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895).
  • CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916).
  • CVE-2026-45961: gfs2: fix memory leaks in gfs2fillsuper error path (bsc#1266933).
  • CVE-2026-45964: SUNRPC: fix gssauth kref leak in gssalloc_msg error path (bsc#1266698).
  • CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208).
  • CVE-2026-45974: btrfs: fix invalid leaf access in btrfsquotaenable() if ref key not found (bsc#1266922).
  • CVE-2026-46005: xfs: fix a resource leak in xfsallocbuftarg() (bsc#1267431).
  • CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
  • CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878).
  • CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628).
  • CVE-2026-46120: ip6gre: Use cached t->net in ip6erspanchangelink() (bsc#1267640).
  • CVE-2026-46123: Bluetooth: virtiobt: clamp rx length before skbput (bsc#1267621).
  • CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
  • CVE-2026-46160: btrfs: fix missing lastunlinktrans update when removing a directory (bsc#1267624).
  • CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6rcvencap() (bsc#1266903).
  • CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).
  • CVE-2026-46227: sctp: revalidate list cursor after sctpsendmsgtoasoc() in SCTPSENDALL (bsc#1267697).
  • CVE-2026-46244: netfilter: nftinner: Fix IPv6 innerthoff desync (bsc#1267654).
  • CVE-2026-46259: procfs: fix missing RCU protection when reading realparent in dotask_stat() (bsc#1267685).
  • CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651).

The following non-security bugs were fixed:

  • ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes).
  • ACPI: IPMI: Fix message kref handling on dead device (git-fixes).
  • ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes).
  • ALSA: aloop: Drop superfluous break (git-fixes).
  • ALSA: cmipci: check sndctlnew1() return value (git-fixes).
  • ALSA: core: Fix unintuitive behavior of sndpowerrefandwait() (git-fixes).
  • ALSA: es1938: check sndctlnew1() return value (git-fixes).
  • ALSA: gus: check sndctlnew1() return value (git-fixes).
  • ALSA: ice1712: check sndctlnew1() return value (git-fixes).
  • ALSA: seq: Clear variable event pointer on read (git-fixes).
  • ALSA: seq: Fix partial userptr event expansion (git-fixes).
  • ALSA: seq: midi: Serialize output teardown with event_input (git-fixes).
  • ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes).
  • ALSA: usb-audio: Propagate errors in scarlettctlenum_put() (git-fixes).
  • ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes).
  • ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes).
  • ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes).
  • ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes).
  • ALSA: ymfpci: check sndctlnew1() return value (git-fixes).
  • ASoC: SOF: ipc3-control: Fix TOCTOU in bytesput and bytesget (git-fixes).
  • ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes).
  • ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes).
  • ASoC: SOF: ipc3-control: Validate size in sndsofupdate_control (git-fixes).
  • ASoC: SOF: ipc4-control: Fix TOCTOU in sofipc4bytes_put (git-fixes).
  • ASoC: SOF: topology: validate vendor array size before parsing (git-fixes).
  • ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes).
  • ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes).
  • ASoC: cs35l56: Cleanup if component_probe fails (git-fixes).
  • ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes).
  • ASoC: cs35l56: Fix missing calls to wmadsp2remove() (git-fixes).
  • ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes).
  • ASoC: meson: aiu: Validate written enum values (git-fixes).
  • ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes).
  • ASoC: topology: Check PCM and DAI name strings before use (git-fixes).
  • ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes).
  • Bluetooth: btmtksdio: fix infinite loop in btmtksdiotxrxwork() (git-fixes).
  • Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes).
  • Bluetooth: btusb: fix use-after-free on registration failure (git-fixes).
  • Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes).
  • Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes).
  • Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes).
  • Bluetooth: hci: validate codec capability element length (git-fixes).
  • Bluetooth: vhci: validate devcoredump state before side effects (git-fixes).
  • Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes).
  • KVM: SEV: Ignore MMIO requests of length '0' (git-fixes).
  • KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes).
  • KVM: SVM: Allow KVMSETNESTED_STATE to clear GIF when SVME==0 (git-fixes).
  • KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes).
  • KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes).
  • KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes).
  • KVM: arm64: Discard PC update state on vcpu reset (git-fixes).
  • KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes).
  • KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes).
  • KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes).
  • KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes).
  • KVM: arm64: vgic-its: Reject restored DTE with out-of-range numeventidbits (git-fixes).
  • KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).
  • KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes).
  • KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes).
  • KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes).
  • KVM: nSVM: Set exitcodehi to -1 when synthesizing SVMEXITERR (failed VMRUN) (git-fixes).
  • KVM: x86/mmu: Fix UBSAN warning when reading nxhugepages parameter (git-fixes).
  • PM: sleep: Use complete() in devicepmsleep_init() (git-fixes).
  • USB: serial: ioti: fix heap overflow in buildi2cfwhdr() (git-fixes).
  • USB: serial: ioti: fix heap overflow in getmanuf_info() (git-fixes).
  • USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes).
  • X.509: Fix validation of ASN.1 certificate header (git-fixes).
  • add bugnumber to existing mana_ib change (bsc#1267682)
  • agp/amd64: Fix broken error propagation in agpamd64probe() (git-fixes).
  • batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes).
  • batman-adv: tpmeter: add only finished tpvars to lists (git-fixes).
  • batman-adv: tpmeter: avoid divide-by-zero for deccwnd (git-fixes).
  • batman-adv: tp_meter: avoid window underflow (git-fixes).
  • batman-adv: tp_meter: fix fast recovery precondition (git-fixes).
  • batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes).
  • batman-adv: tpmeter: initialize deccwnd explicitly (git-fixes).
  • batman-adv: tpmeter: initialize dupacks explicitly (git-fixes).
  • batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes).
  • bnxt_en: Fix NULL pointer dereference (bsc#1268307).
  • crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes).
  • crypto: amlogic - avoid double cleanup in mesoncryptoprobe() (git-fixes).
  • crypto: asymmetrickeys - fix OOB read in pefiledigestpecontents (git-fixes).
  • crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes).
  • crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: ccp - Fix snpfilterreservedmemregions() off-by-one (git-fixes).
  • crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes).
  • crypto: drbg - Fix drbgmaxaddtl() on 64-bit kernels (git-fixes).
  • crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes).
  • crypto: drbg - Fix the fips_enabled priority boost (git-fixes).
  • crypto: ecc - Fix carry overflow in vli multiplication (git-fixes).
  • crypto: ecrdsa - fix unknown OID check in ecrdsaparamcurve (git-fixes).
  • crypto: hisilicon/qm - disable error report before flr (git-fixes).
  • crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: pcrypt - restore callback for non-parallel fallback (git-fixes).
  • crypto: qat - protect service table iterations with service_lock (git-fixes).
  • crypto: qat - validate RSA CRT component lengths (git-fixes).
  • crypto: rng - Free default RNG on module exit (git-fixes).
  • driver core: reject devices with unregistered buses (git-fixes).
  • driver core: use READONCE() for dev->driver in devhassyncstate() (git-fixes).
  • drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes).
  • drm/amdgpu: fix integer overflow in amdgpugemalign_pitch() (git-fixes).
  • drm/amdgpu: set subblockindex for mca ras sub-blocks (git-fixes).
  • drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes).
  • drm/bridge: cdns-dsi: Replace deprecated UNIVERSALDEVPM_OPS() (git-fixes).
  • drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes).
  • drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes).
  • drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes).
  • drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes).
  • drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes).
  • drm/hyperv: use VMBUSRINGSIZE() (git-fixes).
  • drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes).
  • drm/msm/dp: Fix the ISR_* enum values (git-fixes).
  • drm/msm/dp: fix HPD state status bit shift value (git-fixes).
  • drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes).
  • drm/radeon: fix integer overflow in radeonalignpitch() (git-fixes).
  • drm/radeon: fix memory leak in radeonringrestore() on lock failure (git-fixes).
  • drm/rockchip: cdn-dp: add missing check in cdndpconfig_video() (git-fixes).
  • drm/tegra: Fix iommumapsgtable() return value check (git-fixes).
  • drm/tegra: dc: Fix device node reference leak in tegradchas_output() (git-fixes).
  • drm/tidss: Drop extra drmmodeconfig_reset() call (git-fixes).
  • drm/tidss: Fix missing drmbridgeadd() call (git-fixes).
  • drm/vc4: fix krealloc() memory leak (git-fixes).
  • drm/virtio: Fix driver removal with disabled KMS (git-fixes).
  • drm/virtio: fix dmafence refcount leak on error in virtiogpudmafence_wait() (git-fixes).
  • ethtool: provide customized dim profile management (bsc#1261256).
  • fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes).
  • fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes).
  • fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes).
  • fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes).
  • fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes).
  • fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes).
  • fbdev: radeon: fix potential memory leak in radeonfbpciregister() (git-fixes).
  • fbdev: s3fb: fix potential memory leak in s3pciprobe() (git-fixes).
  • fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes).
  • fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes).
  • fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes).
  • fbdev: tridentfb: fix potential memory leak in tridentpciprobe() (git-fixes).
  • fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes).
  • fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes).
  • firmware: armscmi: Fix OOB in scmipowernameget() (git-fixes).
  • firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes).
  • firmwareloader: Fix recursive lock in devicecachefwimages() (git-fixes).
  • firmwareloader: fix device reference leak in firmwareupload_register() (git-fixes).
  • gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes).
  • gpu: host1x: Allow entries in BO caches to be freed (git-fixes).
  • gpu: host1x: Fix iommumapsgtable() return value check (git-fixes).
  • hv: utils: handle and propagate errors in kvp_register (git-fixes).
  • hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes).
  • hwrng: jh7110 - fix refcount leak in starfivetrngread() (git-fixes).
  • hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes).
  • hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).
  • i2c: core: fix irq domain leak on adapter registration failure (git-fixes).
  • i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes).
  • i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes).
  • i2c: tegra: Fix NOIRQ suspend/resume (git-fixes).
  • linux/dim: move useful macros to .h file (bsc#1261256).
  • misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes).
  • misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes).
  • misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes).
  • misc: fastrpc: fix use-after-free race in fastrpcmapcreate (git-fixes).
  • net: ethtool: add ethtool COALESCERXCQE_FRAMES/NSECS (bsc#1261256).
  • net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256).
  • net: mana: Add support for RX CQE Coalescing (bsc#1261256).
  • of: cpu: add check in _offindnmatchcpuproperty() (git-fixes).
  • slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes).
  • soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes).
  • soc: ti: k3-ringacc: Fix access mode for k3ringaccringpoptail_io/proxy (git-fixes).
  • spi: at91-usart: drop dead runtime pm support (git-fixes).
  • spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes).
  • spi: fsl-lpspi: replace dmaengineterminateall() with dmaengineterminatesync() (git-fixes).
  • spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes).
  • spi: meson-spifc: fix runtime PM leak on remove (git-fixes).
  • spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes).
  • thermal: hwmon: Fix critical temperature attribute removal (git-fixes).
  • thunderbolt: Bound root directory content to block size (git-fixes).
  • thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes).
  • thunderbolt: Limit XDomain response copy to actual frame size (git-fixes).
  • thunderbolt: Reject zero-length property entries in validator (git-fixes).
  • thunderbolt: Validate XDomain request packet size before type cast (git-fixes).
  • watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes).
  • watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes).
  • watchdog: sprdwdt: Remove redundant sprdwdt_disable() on register failure (git-fixes).
  • watchdog: unregister PM notifier on watchdog unregister (git-fixes).
  • wifi: ath11k: fix warning when unbinding (git-fixes).
  • wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes).
  • wifi: cfg80211: fix grammar in MLO group key error message (git-fixes).
  • wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes).
  • wifi: mt76: fix argument to ieee80211isfirst_frag() (git-fixes).
  • wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes).
  • wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes).
  • wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes).
  • wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes).
  • wifi: rtw88: increase TX report timeout to fix race condition (git-fixes).
  • wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes).
  • wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes).
  • wifi: wcn36xx: fix OOB read from firmware count in PRINTREGINFO indication (git-fixes).
  • wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes).
  • wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes).
References

Affected packages

SUSE:Linux Micro 6.0 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-48.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-48.1",
            "kernel-default": "6.4.0-48.1",
            "kernel-devel": "6.4.0-48.1",
            "kernel-kvmsmall": "6.4.0-48.1",
            "kernel-default-livepatch": "6.4.0-48.1",
            "kernel-default-base": "6.4.0-48.1.21.25",
            "kernel-macros": "6.4.0-48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22436-1.json"

SUSE:Linux Micro 6.0 / kernel-default-base

Package

Name
kernel-default-base
Purl
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-48.1.21.25

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-48.1",
            "kernel-default": "6.4.0-48.1",
            "kernel-devel": "6.4.0-48.1",
            "kernel-default-base": "6.4.0-48.1.21.25",
            "kernel-default-livepatch": "6.4.0-48.1",
            "kernel-kvmsmall": "6.4.0-48.1",
            "kernel-macros": "6.4.0-48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22436-1.json"

SUSE:Linux Micro 6.0 / kernel-kvmsmall

Package

Name
kernel-kvmsmall
Purl
pkg:rpm/suse/kernel-kvmsmall&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-48.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-48.1",
            "kernel-default": "6.4.0-48.1",
            "kernel-devel": "6.4.0-48.1",
            "kernel-kvmsmall": "6.4.0-48.1",
            "kernel-default-livepatch": "6.4.0-48.1",
            "kernel-default-base": "6.4.0-48.1.21.25",
            "kernel-macros": "6.4.0-48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22436-1.json"

SUSE:Linux Micro 6.0 / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Micro%206.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-48.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-48.1",
            "kernel-default": "6.4.0-48.1",
            "kernel-devel": "6.4.0-48.1",
            "kernel-kvmsmall": "6.4.0-48.1",
            "kernel-default-livepatch": "6.4.0-48.1",
            "kernel-default-base": "6.4.0-48.1.21.25",
            "kernel-macros": "6.4.0-48.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22436-1.json"