SUSE-SU-2026:3602-1: important: Security update for the Linux Kernel
SUSE-SU-2026:3605-1: important: Security update for openssh
SUSE-SU-2026:3602-1: important: Security update for the Linux Kernel
# Security update for the Linux Kernel
Announcement ID: SUSE-SU-2026:3602-1
Release Date: 2026-08-12T18:36:00Z
Rating: important
References:
* bsc#1185845
* bsc#1243603
* bsc#1253262
* bsc#1258718
* bsc#1260347
* bsc#1262573
* bsc#1262745
* bsc#1262771
* bsc#1263010
* bsc#1263068
* bsc#1263718
* bsc#1263788
* bsc#1264013
* bsc#1264053
* bsc#1264076
* bsc#1264089
* bsc#1264090
* bsc#1264558
* bsc#1264779
* bsc#1264795
* bsc#1265308
* bsc#1266238
* bsc#1266758
* bsc#1266850
* bsc#1266890
* bsc#1266913
* bsc#1267375
* bsc#1267384
* bsc#1267435
* bsc#1267584
* bsc#1267596
* bsc#1267656
* bsc#1267682
* bsc#1267715
* bsc#1267995
* bsc#1268029
* bsc#1268307
* bsc#1269181
* bsc#1269188
* bsc#1269289
* bsc#1269383
* bsc#1269512
* bsc#1269513
* bsc#1269577
* bsc#1269633
* bsc#1269773
* bsc#1269808
* bsc#1269981
* bsc#1269988
* bsc#1269997
* bsc#1270000
* bsc#1270230
* bsc#1271349
* bsc#1271368
* bsc#1271526
* bsc#1271825
* bsc#1271866
* bsc#1271899
* bsc#1271904
* bsc#1271908
* bsc#1271912
* bsc#1271964
* bsc#1272176
* bsc#1272180
* bsc#1272183
* bsc#1272207
* bsc#1272242
* bsc#1272263
* bsc#1272268
* bsc#1272282
* bsc#1272466
* bsc#1272468
* bsc#1272573
* bsc#1272607
* bsc#1272665
* bsc#1272678
* bsc#1272693
* bsc#1272694
* bsc#1272836
* bsc#1272855
* bsc#1272865
* bsc#1272904
* bsc#1272907
* bsc#1272918
* bsc#1273004
* bsc#1273035
* bsc#1273231
* bsc#1274072
Cross-References:
* CVE-2023-2058
* CVE-2025-54518
* CVE-2026-31431
* CVE-2026-31482
* CVE-2026-31483
* CVE-2026-31542
* CVE-2026-31598
* CVE-2026-31628
* CVE-2026-31759
* CVE-2026-43033
* CVE-2026-43046
* CVE-2026-43056
* CVE-2026-43276
* CVE-2026-43440
* CVE-2026-43475
* CVE-2026-45904
* CVE-2026-46056
* CVE-2026-46080
* CVE-2026-46084
* CVE-2026-46109
* CVE-2026-46117
* CVE-2026-46126
* CVE-2026-46144
* CVE-2026-46145
* CVE-2026-46174
* CVE-2026-46193
* CVE-2026-46243
* CVE-2026-46323
* CVE-2026-46324
* CVE-2026-46333
* CVE-2026-52967
* CVE-2026-52986
* CVE-2026-53050
* CVE-2026-53129
* CVE-2026-53131
* CVE-2026-53177
* CVE-2026-53224
* CVE-2026-53246
* CVE-2026-53250
* CVE-2026-53262
* CVE-2026-53267
* CVE-2026-53297
* CVE-2026-53324
* CVE-2026-53354
* CVE-2026-53375
* CVE-2026-53388
* CVE-2026-53391
* CVE-2026-53402
* CVE-2026-63794
* CVE-2026-63802
* CVE-2026-63806
* CVE-2026-63807
* CVE-2026-63824
* CVE-2026-63826
* CVE-2026-63829
* CVE-2026-63884
* CVE-2026-63893
* CVE-2026-63912
* CVE-2026-63917
* CVE-2026-63919
* CVE-2026-63921
* CVE-2026-63922
* CVE-2026-63924
* CVE-2026-63946
* CVE-2026-63952
* CVE-2026-63968
* CVE-2026-63971
* CVE-2026-63975
* CVE-2026-63984
* CVE-2026-63994
* CVE-2026-64106
* CVE-2026-64189
* CVE-2026-64530
* CVE-2026-64560
* CVE-2026-64561
* CVE-2026-64564
* CVE-2026-64600
CVSS scores:
* CVE-2023-2058 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
* CVE-2023-2058 ( NVD ): 2.4 CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
* CVE-2025-54518 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2025-54518 ( NVD ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31431 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31482 ( SUSE ): 2.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-31482 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
* CVE-2026-31482 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31483 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31483 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-31483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31542 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31542 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31542 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31598 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31598 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31628 ( SUSE ): 5.7
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
* CVE-2026-31628 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-31628 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-31759 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43033 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43033 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43046 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43056 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43440 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43440 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43475 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43475 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45904 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-45904 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45904 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46056 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46080 ( SUSE ): 6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46084 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46109 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46117 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46117 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46117 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46117 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46126 ( SUSE ): 4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-46126 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-46126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46145 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46145 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46174 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46174 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-46174 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-46193 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46193 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46243 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46324 ( SUSE ): 7.1
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46324 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46324 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
* CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
* CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-52967 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
* CVE-2026-52967 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-52986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-52986 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53050 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53050 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53129 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53129 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53131 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53131 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
* CVE-2026-53131 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
* CVE-2026-53177 ( SUSE ): 5.7
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53177 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53177 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53224 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53246 ( SUSE ): 8.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53250 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53250 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53262 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53262 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53267 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53267 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53297 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53324 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53354 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53354 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53354 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53375 ( SUSE ): 7.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53375 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
* CVE-2026-53375 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-53391 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-53402 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-53402 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-53402 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63794 ( SUSE ): 7.5
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63794 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63794 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63802 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63802 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63802 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63806 ( SUSE ): 5.9
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63806 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63806 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
* CVE-2026-63807 ( SUSE ): 5.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63807 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H
* CVE-2026-63807 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63824 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63824 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63824 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63826 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63826 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63829 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63829 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-63829 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63884 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63884 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63884 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63893 ( SUSE ): 5.9 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
* CVE-2026-63893 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-63912 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63912 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63912 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63917 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63917 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63919 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63919 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63919 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63921 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
* CVE-2026-63921 ( SUSE ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L
* CVE-2026-63921 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-63922 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63922 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63946 ( SUSE ): 7.7
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63946 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63946 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63952 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63952 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63952 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
* CVE-2026-63968 ( SUSE ): 8.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63968 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63968 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-63971 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63971 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63971 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( SUSE ): 8.7
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63975 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63975 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63984 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-63994 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-63994 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64106 ( SUSE ): 6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64106 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
* CVE-2026-64106 ( NVD ): 9.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
* CVE-2026-64189 ( SUSE ): 7.3
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64189 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64530 ( SUSE ): 8.8
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64560 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64560 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64561 ( SUSE ): 9.3
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64564 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-64600 ( SUSE ): 8.8
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
* CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
* CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
* openSUSE Leap 15.6
* SUSE Linux Enterprise High Availability Extension 15 SP6
* SUSE Linux Enterprise Live Patching 15-SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves 77 vulnerabilities and has 11 security fixes can now be
installed.
## Description:
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security
issues:
The following security issues were fixed:
* CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey
handlers (bsc#1267435).
* CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks
(bsc#1267656).
* CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook
objects (bsc#1267995).
* CVE-2026-52967: smb/client: fix possible infinite loop and oob read in
symlink_data() (bsc#1269181).
* CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul
(bsc#1269289).
* CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota
deactivation (bsc#1269188).
* CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache
(bsc#1269633).
* CVE-2026-53131: netfilter: require Ethernet MAC header before using
eth_hdr() (bsc#1269773).
* CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths
in cookie (bsc#1269997).
* CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO
processing (bsc#1269988).
* CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in
xsk_skb_metadata() (bsc#1269808).
* CVE-2026-53262: l2tp: pppol2tp: hold reference to session in
pppol2tp_ioctl() (bsc#1270000).
* CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval
(bsc#1269577).
* CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs
(bsc#1270230).
* CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches
(bsc#1271899).
* CVE-2026-53388: fuse: re-lock request before replacing page cache folio
(bsc#1271825).
* CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in
nfs4_decode_mp_ds_addr (bsc#1271904).
* CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of
(bsc#1271908).
* CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT
path (bsc#1271964).
* CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282).
* CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd
datamatch with get_unaligned() (bsc#1272268).
* CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking
max mapping level (bsc#1272263).
* CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2()
(bsc#1272180).
* CVE-2026-63826: fbdev: fix use-after-free in store_modes() (bsc#1272183).
* CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for
changelink (bsc#1272176).
* CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge
(bsc#1272573).
* CVE-2026-63893: thunderbolt: property: Reject u32 wrap in
tb_property_entry_valid() (bsc#1272607).
* CVE-2026-63912: xfrm: esp: restore combined single-frag length gate
(bsc#1272836).
* CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink()
(bsc#1272904).
* CVE-2026-63919: xfrm: input: hold netns during deferred transport
reinjection (bsc#1272907).
* CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate()
(bsc#1272918).
* CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO
option (bsc#1272855).
* CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665).
* CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE
(bsc#1272468).
* CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path()
(bsc#1272466).
* CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff
(bsc#1272678).
* CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
(bsc#1272694).
* CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
(bsc#1272865).
* CVE-2026-63994: tunnels: load network headers after skb_cow() in
iptunnel_pmtud_build_icmp() (bsc#1273035).
* CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range
num_eventid_bits (bsc#1272242).
* CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list
resize (bsc#1272207).
* CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec()
race (bsc#1273004).
* CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU
pages available (bsc#1273231).
* CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP
processing (bsc#1274072).
* CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK
(bsc#1271526).
The following non security issues were fixed:
* Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes).
* hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
* ice: don't check has_ready_bitmap in E810 functions (bsc#1269981).
* ice: factor out ice_ptp_rebuild_owner() (bsc#1269981).
* ice: fix PTP Call Trace during PTP release (bsc#1269981).
* ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981).
* ice: introduce PTP state machine (bsc#1269981).
* ice: pass reset type to PTP reset functions (bsc#1269981).
* ice: rename ice_ptp_tx_cfg_intr (bsc#1269981).
* ice: rename verify_cached to has_ready_bitmap (bsc#1269981).
* ice: stop destroying and reinitalizing Tx tracker during reset
(bsc#1269981).
* KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes).
* KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes).
* KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes).
* KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as
roots (git-fixes).
* KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls
(git-fixes).
* KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes).
* KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV
timer (git-fixes).
* KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-
fixes).
* KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes).
* mkspec-dtb: Skip missing DTBs.
* net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle
(bsc#1271866).
* net: mana: Add Interrupt Moderation support (bsc#1271368).
* net: mana: Return error code from mana_create_rxq() (git-fixes).
* net: mana: Validate the packet length reported by the NIC (git-fixes).
* pkspec-dtb: Fix dtb-al rename.
* posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
* posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del()
(bsc#1271912).
* posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
* posix-cpu-timers: Handle interval timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get()
(bsc#1271912).
* posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set()
(bsc#1271912).
* posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
* posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set()
(bsc#1271912).
* posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
* posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
* posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
* posix-timers: Add proper state tracking (bsc#1271912).
* posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
* posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
* posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
* posix-timers: Consolidate signal queueing (bsc#1271912).
* posix-timers: Consolidate timer setup (bsc#1271912).
* posix-timers: Cure si_sys_private race (bsc#1271912).
* posix-timers: Document common_clock_get() correctly (bsc#1271912).
* posix-timers: Expand timer_arm() callbacks with a boolean return value
(bsc#1271912).
* posix-timers: Polish coding style in a few places (bsc#1271912).
* posix-timers: Retrieve interval in common timer_settime() code
(bsc#1271912).
* RDMA/mana_ib: initialize err for empty send WR lists (git-fixes).
* sctp: validate embedded address parameter length (git-fixes).
* time: Switch to hrtimer_setup() (bsc#1271912).
## Special Instructions and Notes:
* Please reboot the system after installing this update.
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3602=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3602=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3602=1
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3602=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3602=1
## Package List:
* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.130.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.130.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-default-extra-debuginfo-6.4.0-150600.23.130.1
* cluster-md-kmp-default-6.4.0-150600.23.130.1
* kernel-default-optional-6.4.0-150600.23.130.1
* kernel-default-debuginfo-6.4.0-150600.23.130.1
* kselftests-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-obs-build-6.4.0-150600.23.130.1
* kernel-default-devel-6.4.0-150600.23.130.1
* kernel-default-optional-debuginfo-6.4.0-150600.23.130.1
* kernel-default-extra-6.4.0-150600.23.130.1
* kernel-syms-6.4.0-150600.23.130.1
* ocfs2-kmp-default-6.4.0-150600.23.130.1
* kernel-obs-build-debugsource-6.4.0-150600.23.130.1
* reiserfs-kmp-default-6.4.0-150600.23.130.1
* kernel-default-devel-debuginfo-6.4.0-150600.23.130.1
* kernel-default-debugsource-6.4.0-150600.23.130.1
* dlm-kmp-default-6.4.0-150600.23.130.1
* kernel-default-livepatch-6.4.0-150600.23.130.1
* kselftests-kmp-default-6.4.0-150600.23.130.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-obs-qa-6.4.0-150600.23.130.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* gfs2-kmp-default-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (aarch64)
* dtb-amd-6.4.0-150600.23.130.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.130.1
* dtb-renesas-6.4.0-150600.23.130.1
* kernel-64kb-optional-6.4.0-150600.23.130.1
* dtb-broadcom-6.4.0-150600.23.130.1
* gfs2-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* dtb-mediatek-6.4.0-150600.23.130.1
* dtb-qcom-6.4.0-150600.23.130.1
* kernel-64kb-debuginfo-6.4.0-150600.23.130.1
* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* dtb-altera-6.4.0-150600.23.130.1
* dtb-freescale-6.4.0-150600.23.130.1
* dtb-arm-6.4.0-150600.23.130.1
* kernel-64kb-extra-6.4.0-150600.23.130.1
* ocfs2-kmp-64kb-6.4.0-150600.23.130.1
* kernel-64kb-extra-debuginfo-6.4.0-150600.23.130.1
* dtb-cavium-6.4.0-150600.23.130.1
* dlm-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* cluster-md-kmp-64kb-6.4.0-150600.23.130.1
* kernel-64kb-optional-debuginfo-6.4.0-150600.23.130.1
* gfs2-kmp-64kb-6.4.0-150600.23.130.1
* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* kernel-64kb-debugsource-6.4.0-150600.23.130.1
* dtb-apple-6.4.0-150600.23.130.1
* dtb-marvell-6.4.0-150600.23.130.1
* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* dtb-sprd-6.4.0-150600.23.130.1
* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.130.1
* dtb-amazon-6.4.0-150600.23.130.1
* dtb-apm-6.4.0-150600.23.130.1
* dtb-rockchip-6.4.0-150600.23.130.1
* dtb-exynos-6.4.0-150600.23.130.1
* kernel-64kb-devel-6.4.0-150600.23.130.1
* dtb-amlogic-6.4.0-150600.23.130.1
* kselftests-kmp-64kb-6.4.0-150600.23.130.1
* reiserfs-kmp-64kb-6.4.0-150600.23.130.1
* dtb-nvidia-6.4.0-150600.23.130.1
* dtb-allwinner-6.4.0-150600.23.130.1
* dtb-hisilicon-6.4.0-150600.23.130.1
* dtb-lg-6.4.0-150600.23.130.1
* dtb-socionext-6.4.0-150600.23.130.1
* dtb-xilinx-6.4.0-150600.23.130.1
* dlm-kmp-64kb-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (x86_64)
* kernel-default-vdso-6.4.0-150600.23.130.1
* kernel-default-vdso-debuginfo-6.4.0-150600.23.130.1
* kernel-debug-vdso-debuginfo-6.4.0-150600.23.130.1
* kernel-debug-vdso-6.4.0-150600.23.130.1
* kernel-kvmsmall-vdso-6.4.0-150600.23.130.1
* kernel-kvmsmall-vdso-debuginfo-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (ppc64le x86_64)
* kernel-debug-devel-debuginfo-6.4.0-150600.23.130.1
* kernel-debug-debuginfo-6.4.0-150600.23.130.1
* kernel-debug-devel-6.4.0-150600.23.130.1
* kernel-debug-debugsource-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (s390x)
* kernel-zfcpdump-debugsource-6.4.0-150600.23.130.1
* kernel-zfcpdump-debuginfo-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (ppc64le s390x x86_64)
* kernel-livepatch-SLE15-SP6_Update_30-debugsource-1-150600.13.5.1
* kernel-livepatch-6_4_0-150600_23_130-default-1-150600.13.5.1
* kernel-default-livepatch-devel-6.4.0-150600.23.130.1
* kernel-livepatch-6_4_0-150600_23_130-default-debuginfo-1-150600.13.5.1
* openSUSE Leap 15.6 (aarch64 nosrc)
* kernel-64kb-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (aarch64 nosrc ppc64le s390x x86_64)
* kernel-default-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (aarch64 ppc64le x86_64)
* kernel-kvmsmall-debuginfo-6.4.0-150600.23.130.1
* kernel-kvmsmall-devel-6.4.0-150600.23.130.1
* kernel-kvmsmall-devel-debuginfo-6.4.0-150600.23.130.1
* kernel-default-base-6.4.0-150600.23.130.1.150600.12.60.3
* kernel-kvmsmall-debugsource-6.4.0-150600.23.130.1
* kernel-default-base-rebuild-6.4.0-150600.23.130.1.150600.12.60.3
* openSUSE Leap 15.6 (aarch64 nosrc ppc64le x86_64)
* kernel-kvmsmall-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (noarch)
* kernel-source-6.4.0-150600.23.130.1
* kernel-macros-6.4.0-150600.23.130.1
* kernel-docs-html-6.4.0-150600.23.130.1
* kernel-devel-6.4.0-150600.23.130.1
* kernel-source-vanilla-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (nosrc ppc64le x86_64)
* kernel-debug-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (nosrc s390x)
* kernel-zfcpdump-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.130.1
* openSUSE Leap 15.6 (nosrc)
* dtb-aarch64-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* kernel-default-devel-6.4.0-150600.23.130.1
* dlm-kmp-default-6.4.0-150600.23.130.1
* kernel-syms-6.4.0-150600.23.130.1
* cluster-md-kmp-default-6.4.0-150600.23.130.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.130.1
* ocfs2-kmp-default-6.4.0-150600.23.130.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-obs-build-debugsource-6.4.0-150600.23.130.1
* kernel-default-devel-debuginfo-6.4.0-150600.23.130.1
* reiserfs-kmp-default-6.4.0-150600.23.130.1
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.130.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-default-debuginfo-6.4.0-150600.23.130.1
* kernel-default-debugsource-6.4.0-150600.23.130.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-obs-build-6.4.0-150600.23.130.1
* gfs2-kmp-default-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc ppc64le s390x
x86_64)
* kernel-default-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (nosrc s390x)
* kernel-zfcpdump-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* kernel-devel-6.4.0-150600.23.130.1
* kernel-macros-6.4.0-150600.23.130.1
* kernel-source-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch nosrc)
* kernel-docs-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le x86_64)
* kernel-default-base-6.4.0-150600.23.130.1.150600.12.60.3
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 nosrc)
* kernel-64kb-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64)
* kernel-64kb-debugsource-6.4.0-150600.23.130.1
* kernel-64kb-debuginfo-6.4.0-150600.23.130.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.130.1
* kernel-64kb-devel-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (s390x)
* kernel-zfcpdump-debugsource-6.4.0-150600.23.130.1
* kernel-zfcpdump-debuginfo-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* kernel-devel-6.4.0-150600.23.130.1
* kernel-macros-6.4.0-150600.23.130.1
* kernel-source-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch nosrc)
* kernel-docs-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* kernel-default-devel-6.4.0-150600.23.130.1
* dlm-kmp-default-6.4.0-150600.23.130.1
* kernel-syms-6.4.0-150600.23.130.1
* cluster-md-kmp-default-6.4.0-150600.23.130.1
* dlm-kmp-default-debuginfo-6.4.0-150600.23.130.1
* ocfs2-kmp-default-6.4.0-150600.23.130.1
* gfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-obs-build-6.4.0-150600.23.130.1
* reiserfs-kmp-default-6.4.0-150600.23.130.1
* kernel-obs-build-debugsource-6.4.0-150600.23.130.1
* kernel-default-base-6.4.0-150600.23.130.1.150600.12.60.3
* cluster-md-kmp-default-debuginfo-6.4.0-150600.23.130.1
* kernel-default-devel-debuginfo-6.4.0-150600.23.130.1
* kernel-default-debuginfo-6.4.0-150600.23.130.1
* kernel-default-debugsource-6.4.0-150600.23.130.1
* reiserfs-kmp-default-debuginfo-6.4.0-150600.23.130.1
* ocfs2-kmp-default-debuginfo-6.4.0-150600.23.130.1
* gfs2-kmp-default-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le
x86_64)
* kernel-default-6.4.0-150600.23.130.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (nosrc)
* kernel-default-6.4.0-150600.23.130.1
* SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le
s390x x86_64)
* kernel-default-debugsource-6.4.0-150600.23.130.1
* kernel-default-debuginfo-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64)
* kernel-livepatch-6_4_0-150600_23_130-default-1-150600.13.5.1
* kernel-default-livepatch-6.4.0-150600.23.130.1
* kernel-livepatch-SLE15-SP6_Update_30-debugsource-1-150600.13.5.1
* kernel-default-livepatch-devel-6.4.0-150600.23.130.1
* kernel-default-debuginfo-6.4.0-150600.23.130.1
* kernel-livepatch-6_4_0-150600_23_130-default-debuginfo-1-150600.13.5.1
* kernel-default-debugsource-6.4.0-150600.23.130.1
* SUSE Linux Enterprise Live Patching 15-SP6 (nosrc)
* kernel-default-6.4.0-150600.23.130.1
## References:
* https://www.suse.com/security/cve/CVE-2023-2058.html
* https://www.suse.com/security/cve/CVE-2025-54518.html
* https://www.suse.com/security/cve/CVE-2026-31431.html
* https://www.suse.com/security/cve/CVE-2026-31482.html
* https://www.suse.com/security/cve/CVE-2026-31483.html
* https://www.suse.com/security/cve/CVE-2026-31542.html
* https://www.suse.com/security/cve/CVE-2026-31598.html
* https://www.suse.com/security/cve/CVE-2026-31628.html
* https://www.suse.com/security/cve/CVE-2026-31759.html
* https://www.suse.com/security/cve/CVE-2026-43033.html
* https://www.suse.com/security/cve/CVE-2026-43046.html
* https://www.suse.com/security/cve/CVE-2026-43056.html
* https://www.suse.com/security/cve/CVE-2026-43276.html
* https://www.suse.com/security/cve/CVE-2026-43440.html
* https://www.suse.com/security/cve/CVE-2026-43475.html
* https://www.suse.com/security/cve/CVE-2026-45904.html
* https://www.suse.com/security/cve/CVE-2026-46056.html
* https://www.suse.com/security/cve/CVE-2026-46080.html
* https://www.suse.com/security/cve/CVE-2026-46084.html
* https://www.suse.com/security/cve/CVE-2026-46109.html
* https://www.suse.com/security/cve/CVE-2026-46117.html
* https://www.suse.com/security/cve/CVE-2026-46126.html
* https://www.suse.com/security/cve/CVE-2026-46144.html
* https://www.suse.com/security/cve/CVE-2026-46145.html
* https://www.suse.com/security/cve/CVE-2026-46174.html
* https://www.suse.com/security/cve/CVE-2026-46193.html
* https://www.suse.com/security/cve/CVE-2026-46243.html
* https://www.suse.com/security/cve/CVE-2026-46323.html
* https://www.suse.com/security/cve/CVE-2026-46324.html
* https://www.suse.com/security/cve/CVE-2026-46333.html
* https://www.suse.com/security/cve/CVE-2026-52967.html
* https://www.suse.com/security/cve/CVE-2026-52986.html
* https://www.suse.com/security/cve/CVE-2026-53050.html
* https://www.suse.com/security/cve/CVE-2026-53129.html
* https://www.suse.com/security/cve/CVE-2026-53131.html
* https://www.suse.com/security/cve/CVE-2026-53177.html
* https://www.suse.com/security/cve/CVE-2026-53224.html
* https://www.suse.com/security/cve/CVE-2026-53246.html
* https://www.suse.com/security/cve/CVE-2026-53250.html
* https://www.suse.com/security/cve/CVE-2026-53262.html
* https://www.suse.com/security/cve/CVE-2026-53267.html
* https://www.suse.com/security/cve/CVE-2026-53297.html
* https://www.suse.com/security/cve/CVE-2026-53324.html
* https://www.suse.com/security/cve/CVE-2026-53354.html
* https://www.suse.com/security/cve/CVE-2026-53375.html
* https://www.suse.com/security/cve/CVE-2026-53388.html
* https://www.suse.com/security/cve/CVE-2026-53391.html
* https://www.suse.com/security/cve/CVE-2026-53402.html
* https://www.suse.com/security/cve/CVE-2026-63794.html
* https://www.suse.com/security/cve/CVE-2026-63802.html
* https://www.suse.com/security/cve/CVE-2026-63806.html
* https://www.suse.com/security/cve/CVE-2026-63807.html
* https://www.suse.com/security/cve/CVE-2026-63824.html
* https://www.suse.com/security/cve/CVE-2026-63826.html
* https://www.suse.com/security/cve/CVE-2026-63829.html
* https://www.suse.com/security/cve/CVE-2026-63884.html
* https://www.suse.com/security/cve/CVE-2026-63893.html
* https://www.suse.com/security/cve/CVE-2026-63912.html
* https://www.suse.com/security/cve/CVE-2026-63917.html
* https://www.suse.com/security/cve/CVE-2026-63919.html
* https://www.suse.com/security/cve/CVE-2026-63921.html
* https://www.suse.com/security/cve/CVE-2026-63922.html
* https://www.suse.com/security/cve/CVE-2026-63924.html
* https://www.suse.com/security/cve/CVE-2026-63946.html
* https://www.suse.com/security/cve/CVE-2026-63952.html
* https://www.suse.com/security/cve/CVE-2026-63968.html
* https://www.suse.com/security/cve/CVE-2026-63971.html
* https://www.suse.com/security/cve/CVE-2026-63975.html
* https://www.suse.com/security/cve/CVE-2026-63984.html
* https://www.suse.com/security/cve/CVE-2026-63994.html
* https://www.suse.com/security/cve/CVE-2026-64106.html
* https://www.suse.com/security/cve/CVE-2026-64189.html
* https://www.suse.com/security/cve/CVE-2026-64530.html
* https://www.suse.com/security/cve/CVE-2026-64560.html
* https://www.suse.com/security/cve/CVE-2026-64561.html
* https://www.suse.com/security/cve/CVE-2026-64564.html
* https://www.suse.com/security/cve/CVE-2026-64600.html
* https://bugzilla.suse.com/show_bug.cgi?id85845
* https://bugzilla.suse.com/show_bug.cgi?id43603
* https://bugzilla.suse.com/show_bug.cgi?id53262
* https://bugzilla.suse.com/show_bug.cgi?id58718
* https://bugzilla.suse.com/show_bug.cgi?id60347
* https://bugzilla.suse.com/show_bug.cgi?id62573
* https://bugzilla.suse.com/show_bug.cgi?id62745
* https://bugzilla.suse.com/show_bug.cgi?id62771
* https://bugzilla.suse.com/show_bug.cgi?id63010
* https://bugzilla.suse.com/show_bug.cgi?id63068
* https://bugzilla.suse.com/show_bug.cgi?id63718
* https://bugzilla.suse.com/show_bug.cgi?id63788
* https://bugzilla.suse.com/show_bug.cgi?id64013
* https://bugzilla.suse.com/show_bug.cgi?id64053
* https://bugzilla.suse.com/show_bug.cgi?id64076
* https://bugzilla.suse.com/show_bug.cgi?id64089
* https://bugzilla.suse.com/show_bug.cgi?id64090
* https://bugzilla.suse.com/show_bug.cgi?id64558
* https://bugzilla.suse.com/show_bug.cgi?id64779
* https://bugzilla.suse.com/show_bug.cgi?id64795
* https://bugzilla.suse.com/show_bug.cgi?id65308
* https://bugzilla.suse.com/show_bug.cgi?id66238
* https://bugzilla.suse.com/show_bug.cgi?id66758
* https://bugzilla.suse.com/show_bug.cgi?id66850
* https://bugzilla.suse.com/show_bug.cgi?id66890
* https://bugzilla.suse.com/show_bug.cgi?id66913
* https://bugzilla.suse.com/show_bug.cgi?id67375
* https://bugzilla.suse.com/show_bug.cgi?id67384
* https://bugzilla.suse.com/show_bug.cgi?id67435
* https://bugzilla.suse.com/show_bug.cgi?id67584
* https://bugzilla.suse.com/show_bug.cgi?id67596
* https://bugzilla.suse.com/show_bug.cgi?id67656
* https://bugzilla.suse.com/show_bug.cgi?id67682
* https://bugzilla.suse.com/show_bug.cgi?id67715
* https://bugzilla.suse.com/show_bug.cgi?id67995
* https://bugzilla.suse.com/show_bug.cgi?id68029
* https://bugzilla.suse.com/show_bug.cgi?id68307
* https://bugzilla.suse.com/show_bug.cgi?id69181
* https://bugzilla.suse.com/show_bug.cgi?id69188
* https://bugzilla.suse.com/show_bug.cgi?id69289
* https://bugzilla.suse.com/show_bug.cgi?id69383
* https://bugzilla.suse.com/show_bug.cgi?id69512
* https://bugzilla.suse.com/show_bug.cgi?id69513
* https://bugzilla.suse.com/show_bug.cgi?id69577
* https://bugzilla.suse.com/show_bug.cgi?id69633
* https://bugzilla.suse.com/show_bug.cgi?id69773
* https://bugzilla.suse.com/show_bug.cgi?id69808
* https://bugzilla.suse.com/show_bug.cgi?id69981
* https://bugzilla.suse.com/show_bug.cgi?id69988
* https://bugzilla.suse.com/show_bug.cgi?id69997
* https://bugzilla.suse.com/show_bug.cgi?id70000
* https://bugzilla.suse.com/show_bug.cgi?id70230
* https://bugzilla.suse.com/show_bug.cgi?id71349
* https://bugzilla.suse.com/show_bug.cgi?id71368
* https://bugzilla.suse.com/show_bug.cgi?id71526
* https://bugzilla.suse.com/show_bug.cgi?id71825
* https://bugzilla.suse.com/show_bug.cgi?id71866
* https://bugzilla.suse.com/show_bug.cgi?id71899
* https://bugzilla.suse.com/show_bug.cgi?id71904
* https://bugzilla.suse.com/show_bug.cgi?id71908
* https://bugzilla.suse.com/show_bug.cgi?id71912
* https://bugzilla.suse.com/show_bug.cgi?id71964
* https://bugzilla.suse.com/show_bug.cgi?id72176
* https://bugzilla.suse.com/show_bug.cgi?id72180
* https://bugzilla.suse.com/show_bug.cgi?id72183
* https://bugzilla.suse.com/show_bug.cgi?id72207
* https://bugzilla.suse.com/show_bug.cgi?id72242
* https://bugzilla.suse.com/show_bug.cgi?id72263
* https://bugzilla.suse.com/show_bug.cgi?id72268
* https://bugzilla.suse.com/show_bug.cgi?id72282
* https://bugzilla.suse.com/show_bug.cgi?id72466
* https://bugzilla.suse.com/show_bug.cgi?id72468
* https://bugzilla.suse.com/show_bug.cgi?id72573
* https://bugzilla.suse.com/show_bug.cgi?id72607
* https://bugzilla.suse.com/show_bug.cgi?id72665
* https://bugzilla.suse.com/show_bug.cgi?id72678
* https://bugzilla.suse.com/show_bug.cgi?id72693
* https://bugzilla.suse.com/show_bug.cgi?id72694
* https://bugzilla.suse.com/show_bug.cgi?id72836
* https://bugzilla.suse.com/show_bug.cgi?id72855
* https://bugzilla.suse.com/show_bug.cgi?id72865
* https://bugzilla.suse.com/show_bug.cgi?id72904
* https://bugzilla.suse.com/show_bug.cgi?id72907
* https://bugzilla.suse.com/show_bug.cgi?id72918
* https://bugzilla.suse.com/show_bug.cgi?id73004
* https://bugzilla.suse.com/show_bug.cgi?id73035
* https://bugzilla.suse.com/show_bug.cgi?id73231
* https://bugzilla.suse.com/show_bug.cgi?id74072
SUSE-SU-2026:3605-1: important: Security update for openssh
# Security update for openssh
Announcement ID: SUSE-SU-2026:3605-1
Release Date: 2026-08-13T06:35:45Z
Rating: important
References:
* bsc#1271044
* bsc#1271046
* bsc#1271048
* bsc#1271049
* bsc#1271052
* bsc#1271053
* bsc#1271054
* bsc#1271055
* jsc#PED-16473
Cross-References:
* CVE-2026-59995
* CVE-2026-59996
* CVE-2026-59997
* CVE-2026-59998
* CVE-2026-59999
* CVE-2026-60000
* CVE-2026-60001
* CVE-2026-60002
CVSS scores:
* CVE-2026-59995 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59995 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59995 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59995 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59996 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-59996 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59996 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59996 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
* CVE-2026-59997 ( SUSE ): 2.1
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59997 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59997 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59997 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
* CVE-2026-59998 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59998 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-59998 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-59998 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
* CVE-2026-59999 ( SUSE ): 6.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
* CVE-2026-59999 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-59999 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-59999 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
* CVE-2026-60000 ( SUSE ): 2.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2026-60000 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-60000 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-60000 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
* CVE-2026-60001 ( SUSE ): 6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
* CVE-2026-60001 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-60001 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
* CVE-2026-60002 ( SUSE ): 7.5
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
* CVE-2026-60002 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-60002 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
* CVE-2026-60002 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected Products:
* Basesystem Module 15-SP7
* Desktop Applications Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7
An update that solves eight vulnerabilities and contains one feature can now be
installed.
## Description:
This update for openssh fixes the following issues:
* Backported support for the mlkemx25519 key exchange from upstream
(jsc#PED-16473).
* CVE-2026-59995: sftp: location of downloaded files not properly constrained
when `sftp server:/path .` is used with an attacker-controlled server
(bsc#1271044).
* CVE-2026-59996: scp: file placed in the parent directory of an intended
target directory when copy occurs between two remote destinations
(bsc#1271046).
* CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated
after the 9th argument (bsc#1271048).
* CVE-2026-59998: sshd: undocumented security-relevant
`GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory is not
documented (bsc#1271049).
* CVE-2026-59999: sshd: `DisableForwarding=yes` does not override
`PermitTunnel=yes` (bsc#1271052).
* CVE-2026-60000: sshd: pre-authentication denial of service when
GSSAPIAuthentication is enabled (bsc#1271053).
* CVE-2026-60001: sshd: minimum authentication delay is not honored
(bsc#1271054).
* CVE-2026-60002: ssh: client-side use-after-free when a server changes its
host key during a key reexchange (bsc#1271055).
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3605=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3605=1
* Desktop Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3605=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3605=1
* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-3605=1
## Package List:
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* openssh-server-9.6p1-150600.6.49.1
* openssh-helpers-debuginfo-9.6p1-150600.6.49.1
* openssh-debugsource-9.6p1-150600.6.49.1
* openssh-debuginfo-9.6p1-150600.6.49.1
* openssh-common-9.6p1-150600.6.49.1
* openssh-fips-9.6p1-150600.6.49.1
* openssh-clients-debuginfo-9.6p1-150600.6.49.1
* openssh-helpers-9.6p1-150600.6.49.1
* openssh-clients-9.6p1-150600.6.49.1
* openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
* openssh-common-debuginfo-9.6p1-150600.6.49.1
* openssh-server-debuginfo-9.6p1-150600.6.49.1
* openssh-9.6p1-150600.6.49.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* openssh-server-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debuginfo-9.6p1-150600.6.49.1
* openssh-helpers-debuginfo-9.6p1-150600.6.49.1
* openssh-debugsource-9.6p1-150600.6.49.1
* openssh-debuginfo-9.6p1-150600.6.49.1
* openssh-common-9.6p1-150600.6.49.1
* openssh-fips-9.6p1-150600.6.49.1
* openssh-clients-debuginfo-9.6p1-150600.6.49.1
* openssh-clients-9.6p1-150600.6.49.1
* openssh-helpers-9.6p1-150600.6.49.1
* openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
* openssh-common-debuginfo-9.6p1-150600.6.49.1
* openssh-askpass-gnome-9.6p1-150600.6.49.1
* openssh-server-debuginfo-9.6p1-150600.6.49.1
* openssh-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debugsource-9.6p1-150600.6.49.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* openssh-cavs-9.6p1-150600.6.49.1
* openssh-server-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debuginfo-9.6p1-150600.6.49.1
* openssh-helpers-debuginfo-9.6p1-150600.6.49.1
* openssh-debugsource-9.6p1-150600.6.49.1
* openssh-debuginfo-9.6p1-150600.6.49.1
* openssh-cavs-debuginfo-9.6p1-150600.6.49.1
* openssh-common-9.6p1-150600.6.49.1
* openssh-fips-9.6p1-150600.6.49.1
* openssh-clients-debuginfo-9.6p1-150600.6.49.1
* openssh-clients-9.6p1-150600.6.49.1
* openssh-helpers-9.6p1-150600.6.49.1
* openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
* openssh-common-debuginfo-9.6p1-150600.6.49.1
* openssh-server-debuginfo-9.6p1-150600.6.49.1
* openssh-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debugsource-9.6p1-150600.6.49.1
* openssh-askpass-gnome-9.6p1-150600.6.49.1
* Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* openssh-askpass-gnome-debugsource-9.6p1-150600.6.49.1
* openssh-askpass-gnome-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debuginfo-9.6p1-150600.6.49.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* openssh-server-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debuginfo-9.6p1-150600.6.49.1
* openssh-helpers-debuginfo-9.6p1-150600.6.49.1
* openssh-debugsource-9.6p1-150600.6.49.1
* openssh-debuginfo-9.6p1-150600.6.49.1
* openssh-common-9.6p1-150600.6.49.1
* openssh-fips-9.6p1-150600.6.49.1
* openssh-clients-debuginfo-9.6p1-150600.6.49.1
* openssh-clients-9.6p1-150600.6.49.1
* openssh-helpers-9.6p1-150600.6.49.1
* openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1
* openssh-common-debuginfo-9.6p1-150600.6.49.1
* openssh-askpass-gnome-9.6p1-150600.6.49.1
* openssh-server-debuginfo-9.6p1-150600.6.49.1
* openssh-9.6p1-150600.6.49.1
* openssh-askpass-gnome-debugsource-9.6p1-150600.6.49.1
## References:
* https://www.suse.com/security/cve/CVE-2026-59995.html
* https://www.suse.com/security/cve/CVE-2026-59996.html
* https://www.suse.com/security/cve/CVE-2026-59997.html
* https://www.suse.com/security/cve/CVE-2026-59998.html
* https://www.suse.com/security/cve/CVE-2026-59999.html
* https://www.suse.com/security/cve/CVE-2026-60000.html
* https://www.suse.com/security/cve/CVE-2026-60001.html
* https://www.suse.com/security/cve/CVE-2026-60002.html
* https://bugzilla.suse.com/show_bug.cgi?id71044
* https://bugzilla.suse.com/show_bug.cgi?id71046
* https://bugzilla.suse.com/show_bug.cgi?id71048
* https://bugzilla.suse.com/show_bug.cgi?id71049
* https://bugzilla.suse.com/show_bug.cgi?id71052
* https://bugzilla.suse.com/show_bug.cgi?id71053
* https://bugzilla.suse.com/show_bug.cgi?id71054
* https://bugzilla.suse.com/show_bug.cgi?id71055
* https://jira.suse.com/browse/PED-16473