SUSE-SU-2026:2450-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262450-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2450-1
Upstream
  • CVE-2025-10263
  • CVE-2026-3150
Related
Published
2026-06-18T13:36:00Z
Modified
2026-06-19T08:15:05.662454930Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2025-10263: arm64: Add workaround for Cortex-A76 erratum 1286807 (bsc#1266290).
  • CVE-2025-40253: s390/ctcm: Fix double-kfree (bsc#1255084).
  • CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3registerwork (bsc#1256668).
  • CVE-2026-3150: bcache: fix cacheddev.sbbio use-after-free and crash (bsc#1263169).
  • CVE-2026-23271: perf: Fix _perfeventoverflow() vs perfremovefromcontext() race (bsc#1260018).
  • CVE-2026-23279: wifi: mac80211: fix NULL pointer dereference in meshrxcsa_frame() (bsc#1260468).
  • CVE-2026-23303: smb: client: Don't log plaintext credentials in cifssetcifscreds (bsc#1260502).
  • CVE-2026-23367: wifi: radiotap: reject radiotap with unknown bits (bsc#1260731).
  • CVE-2026-23396: wifi: mac80211: fix NULL deref in meshmatcheslocal() (bsc#1260729).
  • CVE-2026-23444: wifi: mac80211: always free skb on ieee80211txprepare_skb() failure (bsc#1266307).
  • CVE-2026-23448: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check (bsc#1261750).
  • CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700).
  • CVE-2026-31415: ipv6: avoid overflows in ip6datagramsend_ctl() (bsc#1262099).
  • CVE-2026-31421: net/sched: cls_fw: fix NULL pointer dereference on shared blocks (bsc#1262061).
  • CVE-2026-31447: ext4: reject mount if bigalloc with sfirstdata_block != 0 (bsc#1262614).
  • CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).
  • CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfcdiscovertargets_done() (bsc#1262656).
  • CVE-2026-31469: virtionet: Fix UAF on dstops when IFFXMITDSTRELEASE is cleared and napitx is false (bsc#1267816).
  • CVE-2026-31498: Bluetooth: L2CAP: Fix ERTM re-init and zero pdu_len infinite loop (bsc#1262751).
  • CVE-2026-31500: Bluetooth: btintel: serialize btintelhwerror() with hcireqsync_lock (bsc#1262993).
  • CVE-2026-31515: afkey: validate families in pfkeysend_migrate() (bsc#1262752).
  • CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755).
  • CVE-2026-31532: can: afcan: export cansock_destruct() (bsc#1262757).
  • CVE-2026-31540: drm/i915/gt: Check setdefaultsubmission() before deferencing (bsc#1263011).
  • CVE-2026-31546: net: bonding: fix NULL deref in bonddebugrlbhashshow (bsc#1263006).
  • CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165).
  • CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVMMEMORYENCRYPTREGREGION (bsc#1263152).
  • CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2groupextend (bsc#1263319).
  • CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790).
  • CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578).
  • CVE-2026-31668: seg6: separate dst_cache for input and output paths in seg6 lwtunnel (bsc#1263140).
  • CVE-2026-31671: xfrmuser: fix info leak in buildreport() (bsc#1263115).
  • CVE-2026-31673: afunix: read UNIXDIAGVFS data under unixstate_lock (bsc#1263143).
  • CVE-2026-31674: netfilter: ip6trt: reject oversized addrnr in rtmt6_check() (bsc#1263568).
  • CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562).
  • CVE-2026-31759: usb: ulpi: fix double free in ulpiregisterinterface() error path (bsc#1264076).
  • CVE-2026-31778: ALSA: caiaq: fix stack out-of-bounds read in init_card (bsc#1263923).
  • CVE-2026-43020: Bluetooth: MGMT: validate LTK enc_size on load (bsc#1264006).
  • CVE-2026-43024: netfilter: nftables: reject immediate NFQUEUE verdict (bsc#1263930).
  • CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTAEXPECTNAT absent (bsc#1263932).
  • CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).
  • CVE-2026-43037: ip6tunnel: clear skb2->cb in ip4ip6err() (bsc#1263995).
  • CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6errgenicmpv6unreach() (bsc#1264097).
  • CVE-2026-43040: net: ipv6: ndisc: fix ndiscrauseropt to initialize nduseropt_padX fields to zero to prevent an info- leak (bsc#1264091).
  • CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211tdlsoper (bsc#1263945).
  • CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
  • CVE-2026-43140: HID: magicmouse: Do not crash on missing msc->input (bsc#1264630).
  • CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).
  • CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).
  • CVE-2026-43198: tcp: fix potential race in tcpv6synrecvsock() (bsc#1264610).
  • CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfdeventpage_set() (bsc#1264551).
  • CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409).
  • CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716).
  • CVE-2026-43339: ipv6: prevent possible UaF in addrconfpermanentaddr() (bsc#1264763).
  • CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719).
  • CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722).
  • CVE-2026-43407: libceph: Fix potential out-of-bounds access in cephhandleauth_reply() (bsc#1265020).
  • CVE-2026-43413: scsi: hisisas: Fix NULL pointer exception during userscan() (bsc#1264671).
  • CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669).
  • CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).
  • CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960).
  • CVE-2026-45835: Bluetooth: L2CAP: Fix null-ptr-deref in l2capsocknewconnectioncb() (bsc#1266411).
  • CVE-2026-45841: netfilter: nfnetlinkosf: fix divide-by-zero in OSFWSS_MODULO (bsc#1266390).
  • CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400).
  • CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395).
  • CVE-2026-45852: RDMA/rxe: Fix double free in rxesrqfrom_init (bsc#1266711).
  • CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).
  • CVE-2026-45970: bonding: alb: fix UAF in rlbarprecv during bond up/down (bsc#1267205).
  • CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697).
  • CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).
  • CVE-2026-46024: libceph: Prevent potential null-ptr-deref in cephhandleauth_reply() (bsc#1267218).
  • CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payloadsize() in rxercv (bsc#1266901).
  • CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531).
  • CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969).
  • CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrmstatedelete (bsc#1267369).
  • CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
  • CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726).
  • CVE-2026-46159: btrfs: fix btrfsioctlspaceinfo() slotcount TOCTOU which can lead to info-leak (bsc#1267652).
  • CVE-2026-46160: btrfs: fix missing lastunlinktrans update when removing a directory (bsc#1267624).
  • CVE-2026-46169: hfsplus: fix uninit-value by validating catalog record size (bsc#1267713).
  • CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4srqevent() (bsc#1266826).
  • CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238).
  • CVE-2026-46259: procfs: fix missing RCU protection when reading realparent in dotask_stat() (bsc#1267685).
  • CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651).

The following non security issues were fixed:

  • arm64: tlb: Allow XZR argument to TLBI ops (git-fixes).
  • arm64: tlb: Optimize ARM64WORKAROUNDREPEAT_TLBI (git-fixes).
  • bcache: fix uninitialized closure object (git-fixes).
  • check-for-config-changes: Exclude CCMSEXTENSIONS.
  • check-for-config-changes: Exclude HAVECFIICALLNORMALIZEINTEGERS{,_RUSTC}.
  • kvm/svm: PKU not currently supported (bsc#1263887).
  • KVM: x86: Handle PKU CPUID adjustment in VMX code (bsc#1263887).
  • mkspec: Add signature to source list only when it exists.
  • net/sched: cls_fw: fix NULL dereference of 'old' filters before change() (git-fixes).
References

Affected packages

SUSE:Linux Enterprise Live Patching 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kgraft-patch-4_12_14-122_317-default": "1-8.7.1",
            "kernel-default-kgraft": "4.12.14-122.317.1",
            "kernel-default-kgraft-devel": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
kgraft-patch-SLE12-SP5_Update_84

Package

Name
kgraft-patch-SLE12-SP5_Update_84
Purl
pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_84&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-8.7.1

Ecosystem specific

{
    "binaries": [
        {
            "kgraft-patch-4_12_14-122_317-default": "1-8.7.1",
            "kernel-default-kgraft": "4.12.14-122.317.1",
            "kernel-default-kgraft-devel": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
SUSE:Linux Enterprise Server 12 SP5-LTSS
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.317.1",
            "kernel-source": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "kernel-default-man": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-default": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.317.1",
            "kernel-macros": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "kernel-default-man": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-source": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "4.12.14-122.317.1",
            "kernel-macros": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "kernel-default-man": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-default": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "4.12.14-122.317.1",
            "kernel-default": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-macros": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.317.1",
            "kernel-source": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-macros": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.317.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.317.1",
            "kernel-source": "4.12.14-122.317.1",
            "kernel-syms": "4.12.14-122.317.1",
            "kernel-default-base": "4.12.14-122.317.1",
            "ocfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-devel": "4.12.14-122.317.1",
            "dlm-kmp-default": "4.12.14-122.317.1",
            "gfs2-kmp-default": "4.12.14-122.317.1",
            "kernel-default-devel": "4.12.14-122.317.1",
            "cluster-md-kmp-default": "4.12.14-122.317.1",
            "kernel-default": "4.12.14-122.317.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2450-1.json"