SUSE-SU-2026:3594-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263594-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:3594-1
Upstream
  • CVE-2023-2058
  • CVE-2025-54518
Related
Published
2026-08-12T11:31:24Z
Modified
2026-08-13T09:30:08.213513999Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues:

The following security issues were fixed:

  • CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618).
  • CVE-2026-31510: Bluetooth: L2CAP: Fix null-ptr-deref on l2capsockready_cb (bsc#1262603).
  • CVE-2026-31624: HID: core: clamp report_size in s32ton() to avoid undefined shift (bsc#1263657).
  • CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4mbfindbygoal() (bsc#1264255).
  • CVE-2026-43069: Bluetooth: hci_ll: Fix firmware leak on error path (bsc#1264190).
  • CVE-2026-43123: fbcon: check return value of con2fbacquirenewinfo() (bsc#1264598).
  • CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545).
  • CVE-2026-43156: net: usb: pegasus: enable basic endpoint checking (bsc#1265092).
  • CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537).
  • CVE-2026-43180: net: usb: kaweth: remove TX queue manipulation in kawethsetrx_mode (bsc#1265093).
  • CVE-2026-43211: PCI: Fix pcislottrylock() error handling (bsc#1264387).
  • CVE-2026-43216: net: Drop the lock in skbmaytx_timestamp() (bsc#1264319).
  • CVE-2026-43226: net/rds: No shortcut out of RDSCONNERROR (bsc#1264544).
  • CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539).
  • CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321).
  • CVE-2026-43253: iommu/amd: move waitonsem() out of spinlock (bsc#1264419).
  • CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418).
  • CVE-2026-43268: hfsplus: pretend special inodes as regular files (bsc#1265083).
  • CVE-2026-43273: ceph: supply snapshot context in cephzeropartial_object() (bsc#1264446).
  • CVE-2026-43281: mailbox: Prevent out-of-bounds access in fwmboxindex_xlate() (bsc#1264534).
  • CVE-2026-43287: drm: Account property blob allocations to memcg (bsc#1265037).
  • CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in runonedelayed_ref() (bsc#1264712).
  • CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827).
  • CVE-2026-43313: ACPI: processor: Fix NULL-pointer dereference in acpiprocessorerrata_piix4() (bsc#1264821).
  • CVE-2026-43370: drm/amdgpu: Fix use-after-free race in VM acquire (bsc#1264782).
  • CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079).
  • CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744).
  • CVE-2026-43425: usb: image: mdc800: kill download URB on timeout (bsc#1265133).
  • CVE-2026-43427: usb: class: cdc-wdm: fix reordering issue in read code path (bsc#1264746).
  • CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041).
  • CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvmedbbufset (bsc#1265023).
  • CVE-2026-43450: netfilter: nfnetlinkcthelper: fix OOB read in nfnlcthelperdumptable() (bsc#1264794).
  • CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009).
  • CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142).
  • CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790).
  • CVE-2026-43493: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (bsc#1265627).
  • CVE-2026-43496: net/sched: schred: Replace direct dequeue call with peek and qdiscdequeue_peeked (bsc#1266000).
  • CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458).
  • CVE-2026-45858: ext4: subdivide EXT4EXTDATA_VALID1 (bsc#1266773).
  • CVE-2026-45871: tpm: st33zp24: Fix missing cleanup on get_burstcount() error (bsc#1266755).
  • CVE-2026-45877: HID: intel-ish-hid: fix NULL-ptr-deref in ishtpbusremoveallclients (bsc#1266468).
  • CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883).
  • CVE-2026-45905: xfrm: fix iprtbug race in icmproutelookup reverse path (bsc#1266685).
  • CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896).
  • CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900).
  • CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893).
  • CVE-2026-45923: net: usb: catc: enable basic endpoint checking (bsc#1266894).
  • CVE-2026-45981: s390/cio: Fix device lifecycle handling in cssallocsubchannel() (bsc#1267204).
  • CVE-2026-45985: ext4: don't set EXT4GETBLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700).
  • CVE-2026-45994: ibmasm: fix OOB reads in commandfilewrite due to missing size checks (bsc#1267432).
  • CVE-2026-45997: scsi: sd: fix missing putdisk() when deviceadd(&disk_dev) fails (bsc#1266740).
  • CVE-2026-46018: ALSA: usb-audio: stop parsing UAC2 rates at MAXNRRATES (bsc#1266751).
  • CVE-2026-46023: dm mirror: fix integer overflow in createdirtylog() (bsc#1267449).
  • CVE-2026-46027: net/smc: avoid early lgr access in smcclcwait_msg (bsc#1266744).
  • CVE-2026-46033: crypto: authencesn - reject short ahash digests during instance creation (bsc#1266692).
  • CVE-2026-46040: inotify: fix watch count leak when fsnotifyaddinodemarklocked() fails (bsc#1267472).
  • CVE-2026-46049: ALSA: ctxfi: Add fallback to default RSR for S/PDIF (bsc#1267448).
  • CVE-2026-46051: md/raid5: fix soft lockup in retryalignedread() (bsc#1267360).
  • CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).
  • CVE-2026-46064: ibmasm: fix heap over-read in ibmasmsendi2o_message() (bsc#1267497).
  • CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842crypto{alloc,free}_ctx (bsc#1267592).
  • CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524).
  • CVE-2026-46088: ALSA: control: Validate buflen before strnlen() in sndctleleminitenumnames() (bsc#1267226).
  • CVE-2026-46102: net: strparser: fix skbhead leak in strpabort_strp() (bsc#1267502).
  • CVE-2026-46146: ALSA: usb-audio: Avoid potential endless loop in convertchmapv3() (bsc#1267571).
  • CVE-2026-46149: scsi: target: configfs: Bound snprintf() return in tgptgpmembersshow() (bsc#1267648).
  • CVE-2026-46161: md/raid10: fix divide-by-zero in setupgeo() with zero farcopies (bsc#1266838).
  • CVE-2026-46167: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (bsc#1266832).
  • CVE-2026-46177: ipmi: Add limits to event and receive message requests (bsc#1267725).
  • CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4ibcreate_srq() (bsc#1267493).
  • CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (bsc#1266813).
  • CVE-2026-46184: sound: ua101: fix division by zero at probe (bsc#1266864).
  • CVE-2026-46189: RDMA/vmwpvrdma: Fix double free on pvrdmaalloc_ucontext() error path (bsc#1266918).
  • CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690).
  • CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
  • CVE-2026-46220: drm/amdgpu/sdma4: replace BUGON with WARNON in fence emission (bsc#1267704).
  • CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678).
  • CVE-2026-46252: regulator: core: fix locking in regulatorresolvesupply() error path (bsc#1267676).
  • CVE-2026-46294: dm: fix a buffer overflow in ioctl processing (bsc#1267939).
  • CVE-2026-46307: wifi: ath5k: do not access array OOB (bsc#1267987).
  • CVE-2026-46321: tun: free page on short-frame rejection in tunxdpone() (bsc#1268024).
  • CVE-2026-46322: tun: free page on buildskb failure in tunxdp_one() (bsc#1267994).
  • CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
  • CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001).
  • CVE-2026-52927: netfilter: ebtables: fix OOB read in compatmtwfrom_user (bsc#1269027).
  • CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003).
  • CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967).
  • CVE-2026-52948: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (bsc#1269116).
  • CVE-2026-52956: libceph: Fix potential out-of-bounds access in __cephxdecrypt() (bsc#1269172).
  • CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
  • CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254).
  • CVE-2026-52982: net: usb: rtl8150: fix use-after-free in rtl8150startxmit() (bsc#1269258).
  • CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272).
  • CVE-2026-52986: netfilter: nfconntracksip: don't use simple_strtoul (bsc#1269289).
  • CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124).
  • CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118).
  • CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112).
  • CVE-2026-53004: sctp: fix OOB write to userspace in sctpgetsockoptpeerauthchunks (bsc#1269106).
  • CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104).
  • CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
  • CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151).
  • CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389).
  • CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392).
  • CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164).
  • CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658).
  • CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659).
  • CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132).
  • CVE-2026-53093: wifi: brcmfmac: Fix error pointer dereference (bsc#1269414).
  • CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633).
  • CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
  • CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819).
  • CVE-2026-53146: thunderbolt: Limit XDomain response copy to actual frame size (bsc#1269826).
  • CVE-2026-53147: thunderbolt: Validate XDomain request packet size before type cast (bsc#1269709).
  • CVE-2026-53149: thunderbolt: Bound root directory content to block size (bsc#1269733).
  • CVE-2026-53167: fuse: limit FUSENOTIFYRETRIEVE to uptodate folios (bsc#1269768).
  • CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISERHEADERSLEN (bsc#1269710).
  • CVE-2026-53181: vsock/vmci: fix skackbacklog leak on failed handshake (bsc#1269886).
  • CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663).
  • CVE-2026-53196: USB: serial: ioti: fix heap overflow in getmanuf_info() (bsc#1269986).
  • CVE-2026-53208: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (bsc#1269899).
  • CVE-2026-53213: drm/vc4: fix krealloc() memory leak (bsc#1269283).
  • CVE-2026-53218: netfilter: nftexthdr: fix register tracking for FPRESENT flag (bsc#1269273).
  • CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
  • CVE-2026-53225: sctp: fix uninit-value in _sctprcvasconflookup() (bsc#1269711).
  • CVE-2026-53227: net: openvswitch: fix possible kfreeskb of ERRPTR (bsc#1269877).
  • CVE-2026-53236: tcp: restrict SOATTACHFILTER to priv users (bsc#1269994).
  • CVE-2026-53242: ALSA: PCM: Fix wait queue list corruption in sndpcmdrain() on linked streams (bsc#1269236).
  • CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrppduparse_vecattr (bsc#1269675).
  • CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
  • CVE-2026-53249: ipv4: restrict IPOPTSSRR and IPOPTLSRR options (bsc#1269992).
  • CVE-2026-53252: adaption to srcu change of hcidev in hcisysfs (bsc#1269307).
  • CVE-2026-53254: Bluetooth: RFCOMM: validate skb length in MCC handlers (bsc#1269996).
  • CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks (bsc#1269378).
  • CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcommconnectind() (bsc#1269993).
  • CVE-2026-53262: l2tp: remove pppol2tpsessionclose() (bsc#1270000).
  • CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
  • CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257).
  • CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240).
  • CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713).
  • CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810).
  • CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814).
  • CVE-2026-53325: agp/amd64: Fix broken error propagation in agpamd64probe() (bsc#1269726).
  • CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230).
  • CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249).
  • CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818).
  • CVE-2026-53374: drm/amdgpu: zero-initialize GART table on allocation (bsc#1271827).
  • CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
  • CVE-2026-53376: drm/amdkfd: Add upper bound check for numofnodes (bsc#1271831).
  • CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
  • CVE-2026-53391: NFSv4/pNFS: reject zero-length raddr in nfs4decodempds_addr (bsc#1271904).
  • CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826).
  • CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869).
  • CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832).
  • CVE-2026-63794: KVM: SVM: Fix page overflow in sevdbgcrypt() for ENCRYPT path (bsc#1271964).
  • CVE-2026-63806: KVM: Replace guest-triggerable BUGON() in ioeventfd datamatch with getunaligned() (bsc#1272268).
  • CVE-2026-63826: fbdev: fix use-after-free in store_modes() (bsc#1272183).
  • CVE-2026-63829: net: ipgre: require CAPNET_ADMIN in the device netns for changelink (bsc#1272176).
  • CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tbpropertyentry_valid() (bsc#1272607).
  • CVE-2026-63899: USB: serial: mxuport: fix memory corruption with small endpoint (bsc#1272494).
  • CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501).
  • CVE-2026-63915: nfc: hci: fix out-of-bounds read in HCP header parsing (bsc#1272897).
  • CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855).
  • CVE-2026-63927: usb: dwc2: Fix use after free in debug code (bsc#1272892).
  • CVE-2026-63928: USB: serial: omninet: fix memory corruption with small endpoint (bsc#1272891).
  • CVE-2026-63958: usb: typec: ucsi: validate connector number in ucsiconnectorchange() (bsc#1272467).
  • CVE-2026-64298: NFSv4: include MAYWRITE in open permission mask for OTRUNC (bsc#1273550).
  • CVE-2026-64330: usb: typec: tcpm: Validate SVID index in svdmconsumemodes() (bsc#1272681).
  • CVE-2026-64465: usb: xhci: Fix sleep in atomic context in xhcifreestreams() (bsc#1272843).
  • CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
  • CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).

The following non security issues were fixed:

  • ACPI: processor: Fix previous acpiprocessorerrata_piix4() fix (bsc#1264821).
  • dm cache policy smq: check allocation under invalidate lock (git-fixes).
  • dm cache: fix missing return in invalidate_committed's error path (git-fixes).
  • HID: Intel-ish-hid: Ishtp: Fix sensor reads after ACPI S3 suspend (bsc#1266468).
  • KVM: nVMX: use vmexitcontrols_init() to write exit controls for vmcs02 (bsc#1249414).
  • kvm: vmx: Fix entry number check for addatomicswitch_msr() (git-fixes).
  • mkspec-dtb: Skip missing DTBs.
  • pkspec-dtb: Fix dtb-al rename.
  • sctp: validate embedded address parameter length (git-fixes).
  • tee: fix possible error pointer ctx dereferencing (git-fixes).
References

Affected packages

SUSE:Linux Enterprise Live Patching 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default-kgraft": "4.12.14-122.323.1",
            "kgraft-patch-4_12_14-122_323-default": "1-8.3.1",
            "kernel-default-kgraft-devel": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
kgraft-patch-SLE12-SP5_Update_86

Package

Name
kgraft-patch-SLE12-SP5_Update_86
Purl
pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_86&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-8.3.1

Ecosystem specific

{
    "binaries": [
        {
            "kgraft-patch-4_12_14-122_323-default": "1-8.3.1",
            "kernel-default-kgraft": "4.12.14-122.323.1",
            "kernel-default-kgraft-devel": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
SUSE:Linux Enterprise Server 12 SP5-LTSS
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.323.1",
            "kernel-macros": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "kernel-default-man": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.323.1",
            "kernel-default": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "kernel-default-man": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "kernel-default-man": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-default": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5
kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-macros": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-macros": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"
kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-122.323.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-default": "4.12.14-122.323.1",
            "kernel-macros": "4.12.14-122.323.1",
            "kernel-syms": "4.12.14-122.323.1",
            "kernel-default-base": "4.12.14-122.323.1",
            "dlm-kmp-default": "4.12.14-122.323.1",
            "kernel-devel": "4.12.14-122.323.1",
            "ocfs2-kmp-default": "4.12.14-122.323.1",
            "gfs2-kmp-default": "4.12.14-122.323.1",
            "kernel-default-devel": "4.12.14-122.323.1",
            "cluster-md-kmp-default": "4.12.14-122.323.1",
            "kernel-source": "4.12.14-122.323.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3594-1.json"