SUSE-SU-2026:2914-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20262914-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:2914-1
Upstream
Related
Published
2026-07-13T14:56:37Z
Modified
2026-07-14T09:15:06.867396001Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2023-53995: net: ipv4: fix one memleak in __inetdelifa() (bsc#1255616).
  • CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891).
  • CVE-2026-23451: bonding: prevent potential infinite loop in bondheaderparse() (bsc#1261604).
  • CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655).
  • CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2capconndel() (bsc#1262674).
  • CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
  • CVE-2026-31592: KVM: SEV: Protect all of sevmemencregisterregion() with kvm->lock (bsc#1263123).
  • CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573).
  • CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560).
  • CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).
  • CVE-2026-31773: Bluetooth: SMP: derive legacy responder STK authentication from MITM state (bsc#1264039).
  • CVE-2026-31781: drm/ioc32: stop speculation on the drmcompatioctl path (bsc#1264033).
  • CVE-2026-43035: net: sched: clsapi: fix tcchainfillnode to initialize tcm_info to zero to prevent an info-leak (bsc#1263996).
  • CVE-2026-43036: net: use skbheaderpointer() for TCPv4 GSO frag_off check (bsc#1263993).
  • CVE-2026-43043: crypto: af-alg - fix NULL pointer dereference in scatterwalk (bsc#1264088).
  • CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request (bsc#1264073).
  • CVE-2026-43051: HID: wacom: fix out-of-bounds read in wacomintuosbt_irq (bsc#1264065).
  • CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236).
  • CVE-2026-43089: xfrmuser: fix info leak in buildmapping() (bsc#1264261).
  • CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254).
  • CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifssanitizeprepath (bsc#1264437).
  • CVE-2026-43117: btrfs: tracepoints: get correct superblock from dentry in event btrfssyncfile() (bsc#1264414).
  • CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6getsaddr() (bsc#1264294).
  • CVE-2026-43233: netfilter: nfconntrackh323: fix OOB read in decode_choice() (bsc#1264337).
  • CVE-2026-43279: ALSA: usb-audio: Add sanity check for OOB writes at silencing (bsc#1264618).
  • CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113).
  • CVE-2026-43456: bonding: fix type confusion in bondsetupby_slave() (bsc#1264734).
  • CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748).
  • CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpireadrawfromsgl() (bsc#1265629).
  • CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).
  • CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899).
  • CVE-2026-45948: ext4: fix memory leak in ext4extshift_extents() (bsc#1266929).
  • CVE-2026-45960: hfsplus: return error when node already exists in hfsbnodecreate (bsc#1266971).
  • CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430).
  • CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458).
  • CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiexadaptercleanup() (bsc#1267437).
  • CVE-2026-46082: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (bsc#1267473).
  • CVE-2026-46124: isofs: validate block number from NFS file handle in isofsexportiget (bsc#1266847).
  • CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928).
  • CVE-2026-46253: pstore/ram: fix buffer overflow in persistentramsave_old() (bsc#1267635).
  • CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637).
  • CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).
  • CVE-2026-46275: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (bsc#1267968).
  • CVE-2026-46299: hfsplus: fix held lock freed on hfsplusfillsuper() (bsc#1267920).
  • CVE-2026-46320: tap: free page on error paths in tapgetuser_xdp() (bsc#1267993).
  • CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037).
  • CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421).
  • CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
  • CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).
  • CVE-2026-52954: libceph: handle rbtree insertion error in decodechooseargs() (bsc#1269137).
  • CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
  • CVE-2026-52957: libceph: Fix potential null-ptr-deref in decodechooseargs() (bsc#1269103).
  • CVE-2026-52962: ceph: fix a buffer leak in _cephsetxattr() (bsc#1269135).
  • CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).
  • CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397).
  • CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).
  • CVE-2026-53075: ppp: require CAPNETADMIN in target netns for unattached ioctls (bsc#1269690).
  • CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size (bsc#1269786).
  • CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator (bsc#1269386).
  • CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow (bsc#1269904).
  • CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bneprxframe() extension handling (bsc#1269574).
  • CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506).
  • CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).

The following non security issues were fixed:

  • btrfs: tracepoints: fix sleep while in atomic context in btrfssyncfile() (git-fixes).
  • libceph: add non-asserting rbtree insertion helper (bsc#1269137).
References

Affected packages

SUSE:Linux Enterprise Live Patching 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-kgraft": "4.12.14-122.320.1",
            "kernel-default-kgraft-devel": "4.12.14-122.320.1",
            "kgraft-patch-4_12_14-122_320-default": "1-8.3.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
kgraft-patch-SLE12-SP5_Update_85

Package

Name
kgraft-patch-SLE12-SP5_Update_85
Purl
pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_85&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-kgraft": "4.12.14-122.320.1",
            "kgraft-patch-4_12_14-122_320-default": "1-8.3.1",
            "kernel-default-kgraft-devel": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
SUSE:Linux Enterprise Server 12 SP5-LTSS
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.320.1",
            "kernel-default": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "kernel-default-man": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.320.1",
            "kernel-default": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "kernel-default-man": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "kernel-default-man": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-default": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-default": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.320.1",
            "kernel-macros": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.320.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.320.1",
            "kernel-source": "4.12.14-122.320.1",
            "kernel-syms": "4.12.14-122.320.1",
            "kernel-default-base": "4.12.14-122.320.1",
            "dlm-kmp-default": "4.12.14-122.320.1",
            "kernel-devel": "4.12.14-122.320.1",
            "ocfs2-kmp-default": "4.12.14-122.320.1",
            "gfs2-kmp-default": "4.12.14-122.320.1",
            "kernel-default-devel": "4.12.14-122.320.1",
            "cluster-md-kmp-default": "4.12.14-122.320.1",
            "kernel-macros": "4.12.14-122.320.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2914-1.json"