SUSE-SU-2026:2722-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262722-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2722-1
Upstream
  • CVE-2025-10263
Related
Published
2026-07-01T13:35:33Z
Modified
2026-07-02T09:15:04.899939463Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
  • CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3registerwork (bsc#1256668).
  • CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).
  • CVE-2026-31414: netfilter: nfconntrackexpect: use expect->helper (bsc#1262085).
  • CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392).
  • CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).
  • CVE-2026-31469: virtionet: Fix UAF on dstops when IFFXMITDSTRELEASE is cleared and napitx is false
  • CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748).
  • CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798).
  • CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2capconndel() (bsc#1262674).
  • CVE-2026-31500: Bluetooth: btintel: serialize btintelhwerror() with hcireqsync_lock (bsc#1262993).
  • CVE-2026-31555: futex: Clear stale exiting pointer in futexlockpi() retry path (bsc#1263178).
  • CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057).
  • CVE-2026-31592: KVM: SEV: Protect all of sevmemencregisterregion() with kvm->lock (bsc#1263123).
  • CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124).
  • CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578).
  • CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137).
  • CVE-2026-31674: netfilter: ip6trt: reject oversized addrnr in rtmt6_check() (bsc#1263568).
  • CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).
  • CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744).
  • CVE-2026-31752: bridge: brndsend: validate ND option lengths (bsc#1264045).
  • CVE-2026-31759: usb: ulpi: fix double free in ulpiregisterinterface() error path (bsc#1264076).
  • CVE-2026-43023: Bluetooth: SCO: fix race conditions in scosockconnect() (bsc#1264137).
  • CVE-2026-43024: netfilter: nftables: reject immediate NFQUEUE verdict (bsc#1263930).
  • CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).
  • CVE-2026-43035: net: sched: clsapi: fix tcchainfillnode to initialize tcm_info to zero to prevent an info-leak (bsc#1263996).
  • CVE-2026-43036: net: use skbheaderpointer() for TCPv4 GSO frag_off check (bsc#1263993).
  • CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080).
  • CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
  • CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266).
  • CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in _ioam6filltracedata() (bsc#1264239).
  • CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifssanitizeprepath (bsc#1264437).
  • CVE-2026-43119: Bluetooth: hcisync: annotate data-races around hdev->reqstatus (bsc#1264561).
  • CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).
  • CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549).
  • CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).
  • CVE-2026-43198: tcp: fix potential race in tcpv6synrecvsock() (bsc#1264610).
  • CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444).
  • CVE-2026-43339: ipv6: prevent possible UaF in addrconfpermanentaddr() (bsc#1264763).
  • CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103).
  • CVE-2026-43405: libceph: Use u32 for non-negative values in cephmonmapdecode() (bsc#1264741).
  • CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143).
  • CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628).
  • CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).
  • CVE-2026-45841: netfilter: nfnetlinkosf: fix divide-by-zero in OSFWSS_MODULO (bsc#1266390).
  • CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705).
  • CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).
  • CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895).
  • CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916).
  • CVE-2026-45961: gfs2: fix memory leaks in gfs2fillsuper error path (bsc#1266933).
  • CVE-2026-45964: SUNRPC: fix gssauth kref leak in gssalloc_msg error path (bsc#1266698).
  • CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208).
  • CVE-2026-45974: btrfs: fix invalid leaf access in btrfsquotaenable() if ref key not found (bsc#1266922).
  • CVE-2026-46005: xfs: fix a resource leak in xfsallocbuftarg() (bsc#1267431).
  • CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
  • CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878).
  • CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628).
  • CVE-2026-46123: Bluetooth: virtiobt: clamp rx length before skbput (bsc#1267621).
  • CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
  • CVE-2026-46160: btrfs: fix missing lastunlinktrans update when removing a directory (bsc#1267624).
  • CVE-2026-46162: ice: fix double free in icesfeth_activate() error path (bsc#1266840).
  • CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6rcvencap() (bsc#1266903).
  • CVE-2026-46244: netfilter: nftinner: Fix IPv6 innerthoff desync (bsc#1267654).
  • CVE-2026-46259: procfs: fix missing RCU protection when reading realparent in dotask_stat() (bsc#1267685).
  • CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651).

The following non-security bugs were fixed:

  • ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes).
  • ACPI: IPMI: Fix message kref handling on dead device (git-fixes).
  • ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes).
  • ALSA: aloop: Drop superfluous break (git-fixes).
  • ALSA: cmipci: check sndctlnew1() return value (git-fixes).
  • ALSA: core: Fix unintuitive behavior of sndpowerrefandwait() (git-fixes).
  • ALSA: es1938: check sndctlnew1() return value (git-fixes).
  • ALSA: gus: check sndctlnew1() return value (git-fixes).
  • ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes).
  • ALSA: ice1712: check sndctlnew1() return value (git-fixes).
  • ALSA: seq: Clear variable event pointer on read (git-fixes).
  • ALSA: seq: Fix kernel heap address leak in bounceerrorevent() (git-fixes).
  • ALSA: seq: Fix partial userptr event expansion (git-fixes).
  • ALSA: seq: midi: Serialize output teardown with event_input (git-fixes).
  • ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes).
  • ALSA: usb-audio: Propagate errors in scarlettctlenum_put() (git-fixes).
  • ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes).
  • ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes).
  • ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes).
  • ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes).
  • ALSA: ymfpci: check sndctlnew1() return value (git-fixes).
  • ASoC: SOF: ipc3-control: Fix TOCTOU in bytesput and bytesget (git-fixes).
  • ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes).
  • ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes).
  • ASoC: SOF: ipc3-control: Validate size in sndsofupdate_control (git-fixes).
  • ASoC: SOF: ipc4-control: Fix TOCTOU in sofipc4bytes_put (git-fixes).
  • ASoC: SOF: topology: validate vendor array size before parsing (git-fixes).
  • ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes).
  • ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes).
  • ASoC: cs35l56: Cleanup if component_probe fails (git-fixes).
  • ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes).
  • ASoC: cs35l56: Fix missing calls to wmadsp2remove() (git-fixes).
  • ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes).
  • ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes).
  • ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes).
  • ASoC: meson: aiu: Validate written enum values (git-fixes).
  • ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes).
  • ASoC: topology: Check PCM and DAI name strings before use (git-fixes).
  • ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes).
  • Bluetooth: btmtk: fix URB leak in allocmtkintr_urb error path (git-fixes).
  • Bluetooth: btmtksdio: fix infinite loop in btmtksdiotxrxwork() (git-fixes).
  • Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes).
  • Bluetooth: btusb: fix use-after-free on registration failure (git-fixes).
  • Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes).
  • Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes).
  • Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes).
  • Bluetooth: hci: validate codec capability element length (git-fixes).
  • Bluetooth: hciqca: fix NULL pointer dereference in qcadmp_hdr() for non-serdev device (git-fixes).
  • Bluetooth: vhci: validate devcoredump state before side effects (git-fixes).
  • KVM: SEV: Ignore MMIO requests of length '0' (git-fixes).
  • KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes).
  • KVM: SVM: Allow KVMSETNESTED_STATE to clear GIF when SVME==0 (git-fixes).
  • KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes).
  • KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes).
  • KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes).
  • KVM: arm64: Discard PC update state on vcpu reset (git-fixes).
  • KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes).
  • KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes).
  • KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes).
  • KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes).
  • KVM: arm64: vgic-its: Reject restored DTE with out-of-range numeventidbits (git-fixes).
  • KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).
  • KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes).
  • KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes).
  • KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes).
  • KVM: x86/mmu: Fix UBSAN warning when reading nxhugepages parameter (git-fixes).
  • PM: sleep: Use complete() in devicepmsleep_init() (git-fixes).
  • USB: serial: ioti: fix heap overflow in buildi2cfwhdr() (git-fixes).
  • USB: serial: ioti: fix heap overflow in getmanuf_info() (git-fixes).
  • USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes).
  • X.509: Fix validation of ASN.1 certificate header (git-fixes).
  • accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes).
  • agp/amd64: Fix broken error propagation in agpamd64probe() (git-fixes).
  • batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes).
  • batman-adv: tpmeter: add only finished tpvars to lists (git-fixes).
  • batman-adv: tpmeter: avoid divide-by-zero for deccwnd (git-fixes).
  • batman-adv: tp_meter: avoid window underflow (git-fixes).
  • batman-adv: tp_meter: fix fast recovery precondition (git-fixes).
  • batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes).
  • batman-adv: tpmeter: initialize deccwnd explicitly (git-fixes).
  • batman-adv: tpmeter: initialize dupacks explicitly (git-fixes).
  • batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes).
  • crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes).
  • crypto: amlogic - avoid double cleanup in mesoncryptoprobe() (git-fixes).
  • crypto: asymmetrickeys - fix OOB read in pefiledigestpecontents (git-fixes).
  • crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes).
  • crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: ccp - Fix snpfilterreservedmemregions() off-by-one (git-fixes).
  • crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes).
  • crypto: drbg - Fix drbgmaxaddtl() on 64-bit kernels (git-fixes).
  • crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes).
  • crypto: drbg - Fix the fips_enabled priority boost (git-fixes).
  • crypto: ecc - Fix carry overflow in vli multiplication (git-fixes).
  • crypto: ecrdsa - fix unknown OID check in ecrdsaparamcurve (git-fixes).
  • crypto: hisilicon/qm - disable error report before flr (git-fixes).
  • crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes).
  • crypto: pcrypt - restore callback for non-parallel fallback (git-fixes).
  • crypto: qat - protect service table iterations with service_lock (git-fixes).
  • crypto: qat - validate RSA CRT component lengths (git-fixes).
  • crypto: rng - Free default RNG on module exit (git-fixes).
  • driver core: reject devices with unregistered buses (git-fixes).
  • driver core: use READONCE() for dev->driver in devhassyncstate() (git-fixes).
  • drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes).
  • drm/amd/pm: remove trailing semicolon from AMDGPUPMPOLICY_ATTR macro (git-fixes).
  • drm/amdgpu: fix integer overflow in amdgpugemalign_pitch() (git-fixes).
  • drm/amdgpu: set subblockindex for mca ras sub-blocks (git-fixes).
  • drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes).
  • drm/amdkfd: always resumeall after suspendall (git-fixes).
  • drm/bridge: cdns-dsi: Replace deprecated UNIVERSALDEVPM_OPS() (git-fixes).
  • drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes).
  • drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes).
  • drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes).
  • drm/gpuvm: Do not prepare NULL objects (git-fixes).
  • drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes).
  • drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes).
  • drm/hyperv: use VMBUSRINGSIZE() (git-fixes).
  • drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes).
  • drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes).
  • drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes).
  • drm/msm/dp: Fix the ISR_* enum values (git-fixes).
  • drm/msm/dp: fix HPD state status bit shift value (git-fixes).
  • drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes).
  • drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes).
  • drm/radeon: fix integer overflow in radeonalignpitch() (git-fixes).
  • drm/radeon: fix memory leak in radeonringrestore() on lock failure (git-fixes).
  • drm/rockchip: cdn-dp: add missing check in cdndpconfig_video() (git-fixes).
  • drm/syncobj: Fix memory leak in drmsyncobjfind_fence() (git-fixes).
  • drm/tegra: Fix iommumapsgtable() return value check (git-fixes).
  • drm/tegra: dc: Fix device node reference leak in tegradchas_output() (git-fixes).
  • drm/tidss: Drop extra drmmodeconfig_reset() call (git-fixes).
  • drm/tidss: Fix missing drmbridgeadd() call (git-fixes).
  • drm/vc4: fix krealloc() memory leak (git-fixes).
  • drm/virtio: Fix driver removal with disabled KMS (git-fixes).
  • drm/virtio: fix dmafence refcount leak on error in virtiogpudmafence_wait() (git-fixes).
  • drm/xe: fix refcount leak in xerangefence_insert() (git-fixes).
  • drm: renesas: rzg2lmipidsi: Increase reset deassertion delay (git-fixes).
  • fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes).
  • fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes).
  • fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes).
  • fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes).
  • fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes).
  • fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes).
  • fbdev: radeon: fix potential memory leak in radeonfbpciregister() (git-fixes).
  • fbdev: s3fb: fix potential memory leak in s3pciprobe() (git-fixes).
  • fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes).
  • fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes).
  • fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes).
  • fbdev: tridentfb: fix potential memory leak in tridentpciprobe() (git-fixes).
  • fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes).
  • fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes).
  • firmware: armscmi: Fix OOB in scmipowernameget() (git-fixes).
  • firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes).
  • firmwareloader: Fix recursive lock in devicecachefwimages() (git-fixes).
  • firmwareloader: fix device reference leak in firmwareupload_register() (git-fixes).
  • gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes).
  • gpu: host1x: Allow entries in BO caches to be freed (git-fixes).
  • gpu: host1x: Fix iommumapsgtable() return value check (git-fixes).
  • hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes).
  • hwrng: jh7110 - fix refcount leak in starfivetrngread() (git-fixes).
  • hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes).
  • i2c: core: fix irq domain leak on adapter registration failure (git-fixes).
  • i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes).
  • i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes).
  • i2c: tegra: Fix NOIRQ suspend/resume (git-fixes).
  • ice: ptp: do not WARN when controlling PF is unavailable (bsc#1267251).
  • misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes).
  • misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes).
  • misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes).
  • misc: fastrpc: fix use-after-free race in fastrpcmapcreate (git-fixes).
  • of: cpu: add check in _offindnmatchcpuproperty() (git-fixes).
  • scripts/submit_branch: add SLE15-SP7 submission script
  • serial: 8250: dispatch SysRq character in serial8250handleirq() (git-fixes).
  • serial: 8250dw: dispatch SysRq character in dw8250handle_irq() (git-fixes).
  • slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes).
  • soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes).
  • soc: ti: k3-ringacc: Fix access mode for k3ringaccringpoptail_io/proxy (git-fixes).
  • spi: at91-usart: drop dead runtime pm support (git-fixes).
  • spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes).
  • spi: fsl-lpspi: replace dmaengineterminateall() with dmaengineterminatesync() (git-fixes).
  • spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes).
  • spi: meson-spifc: fix runtime PM leak on remove (git-fixes).
  • spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes).
  • thermal: hwmon: Fix critical temperature attribute removal (git-fixes).
  • thunderbolt: Bound root directory content to block size (git-fixes).
  • thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes).
  • thunderbolt: Limit XDomain response copy to actual frame size (git-fixes).
  • thunderbolt: Reject zero-length property entries in validator (git-fixes).
  • thunderbolt: Validate XDomain request packet size before type cast (git-fixes).
  • watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes).
  • watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes).
  • watchdog: sprdwdt: Remove redundant sprdwdt_disable() on register failure (git-fixes).
  • watchdog: unregister PM notifier on watchdog unregister (git-fixes).
  • wifi: ath11k: fix warning when unbinding (git-fixes).
  • wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes).
  • wifi: cfg80211: fix grammar in MLO group key error message (git-fixes).
  • wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes).
  • wifi: mt76: fix argument to ieee80211isfirst_frag() (git-fixes).
  • wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes).
  • wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes).
  • wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes).
  • wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes).
  • wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes).
  • wifi: rtw88: increase TX report timeout to fix race condition (git-fixes).
  • wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes).
  • wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes).
  • wifi: wcn36xx: fix OOB read from firmware count in PRINTREGINFO indication (git-fixes).
  • wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes).
  • wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes).
References

Affected packages

SUSE:Linux Enterprise High Availability Extension 15 SP7
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "dlm-kmp-default": "6.4.0-150700.53.63.1",
            "ocfs2-kmp-default": "6.4.0-150700.53.63.1",
            "gfs2-kmp-default": "6.4.0-150700.53.63.1",
            "cluster-md-kmp-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Live Patching 15 SP7
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-livepatch-devel": "6.4.0-150700.53.63.1",
            "kernel-default-livepatch": "6.4.0-150700.53.63.1",
            "kernel-livepatch-6_4_0-150700_53_63-default": "1-150700.15.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-livepatch-SLE15-SP7_Update_17

Package

Name
kernel-livepatch-SLE15-SP7_Update_17
Purl
pkg:rpm/suse/kernel-livepatch-SLE15-SP7_Update_17&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-150700.15.3.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-livepatch-devel": "6.4.0-150700.53.63.1",
            "kernel-default-livepatch": "6.4.0-150700.53.63.1",
            "kernel-livepatch-6_4_0-150700_53_63-default": "1-150700.15.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Module for Basesystem 15 SP7
kernel-64kb

Package

Name
kernel-64kb
Purl
pkg:rpm/suse/kernel-64kb&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "6.4.0-150700.53.63.1",
            "kernel-64kb-devel": "6.4.0-150700.53.63.1",
            "kernel-default-base": "6.4.0-150700.53.63.1.150700.17.37.1",
            "kernel-devel": "6.4.0-150700.53.63.1",
            "kernel-zfcpdump": "6.4.0-150700.53.63.1",
            "kernel-64kb": "6.4.0-150700.53.63.1",
            "kernel-default-devel": "6.4.0-150700.53.63.1",
            "kernel-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "6.4.0-150700.53.63.1",
            "kernel-64kb-devel": "6.4.0-150700.53.63.1",
            "kernel-default-base": "6.4.0-150700.53.63.1.150700.17.37.1",
            "kernel-devel": "6.4.0-150700.53.63.1",
            "kernel-zfcpdump": "6.4.0-150700.53.63.1",
            "kernel-default-devel": "6.4.0-150700.53.63.1",
            "kernel-64kb": "6.4.0-150700.53.63.1",
            "kernel-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-default-base

Package

Name
kernel-default-base
Purl
pkg:rpm/suse/kernel-default-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1.150700.17.37.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "6.4.0-150700.53.63.1",
            "kernel-64kb-devel": "6.4.0-150700.53.63.1",
            "kernel-default-base": "6.4.0-150700.53.63.1.150700.17.37.1",
            "kernel-devel": "6.4.0-150700.53.63.1",
            "kernel-zfcpdump": "6.4.0-150700.53.63.1",
            "kernel-64kb": "6.4.0-150700.53.63.1",
            "kernel-default-devel": "6.4.0-150700.53.63.1",
            "kernel-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "6.4.0-150700.53.63.1",
            "kernel-64kb-devel": "6.4.0-150700.53.63.1",
            "kernel-default-base": "6.4.0-150700.53.63.1.150700.17.37.1",
            "kernel-devel": "6.4.0-150700.53.63.1",
            "kernel-zfcpdump": "6.4.0-150700.53.63.1",
            "kernel-64kb": "6.4.0-150700.53.63.1",
            "kernel-default-devel": "6.4.0-150700.53.63.1",
            "kernel-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-zfcpdump

Package

Name
kernel-zfcpdump
Purl
pkg:rpm/suse/kernel-zfcpdump&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "6.4.0-150700.53.63.1",
            "kernel-64kb-devel": "6.4.0-150700.53.63.1",
            "kernel-default-base": "6.4.0-150700.53.63.1.150700.17.37.1",
            "kernel-devel": "6.4.0-150700.53.63.1",
            "kernel-zfcpdump": "6.4.0-150700.53.63.1",
            "kernel-64kb": "6.4.0-150700.53.63.1",
            "kernel-default-devel": "6.4.0-150700.53.63.1",
            "kernel-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Module for Development Tools 15 SP7
kernel-docs

Package

Name
kernel-docs
Purl
pkg:rpm/suse/kernel-docs&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-150700.53.63.1",
            "kernel-syms": "6.4.0-150700.53.63.1",
            "kernel-docs": "6.4.0-150700.53.63.1",
            "kernel-obs-build": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-obs-build

Package

Name
kernel-obs-build
Purl
pkg:rpm/suse/kernel-obs-build&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-150700.53.63.1",
            "kernel-syms": "6.4.0-150700.53.63.1",
            "kernel-docs": "6.4.0-150700.53.63.1",
            "kernel-obs-build": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-150700.53.63.1",
            "kernel-syms": "6.4.0-150700.53.63.1",
            "kernel-docs": "6.4.0-150700.53.63.1",
            "kernel-obs-build": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-source": "6.4.0-150700.53.63.1",
            "kernel-syms": "6.4.0-150700.53.63.1",
            "kernel-docs": "6.4.0-150700.53.63.1",
            "kernel-obs-build": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Module for Legacy 15 SP7
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "reiserfs-kmp-default": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Module for Public Cloud 15 SP7
kernel-azure

Package

Name
kernel-azure
Purl
pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-azure": "6.4.0-150700.53.63.1",
            "kernel-azure-devel": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"
SUSE:Linux Enterprise Workstation Extension 15 SP7
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.4.0-150700.53.63.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-extra": "6.4.0-150700.53.63.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2722-1.json"