SUSE-CU-2026:8033-1: Security update of bci/bci-sle15-kernel-module-devel

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 12:23:30 UTC 2026


SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8033-1
Container Tags        : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.26 , bci/bci-sle15-kernel-module-devel:latest
Container Release     : 60.26
Severity              : important
Type                  : security
References            : 1204315 1243603 1251942 1252306 1253043 1256564 1257463 1257605
                        1257777 1260012 1260593 1261250 1261562 1262391 1262603 1262605
                        1262614 1262637 1262639 1262649 1262653 1262658 1262659 1262678
                        1262723 1262751 1262757 1262765 1262768 1262992 1263008 1263011
                        1263013 1263014 1263016 1263017 1263020 1263025 1263030 1263031
                        1263045 1263055 1263059 1263068 1263073 1263075 1263077 1263097
                        1263111 1263128 1263134 1263139 1263142 1263145 1263167 1263173
                        1263175 1263491 1263493 1263495 1263539 1263562 1263598 1263657
                        1263776 1263777 1263778 1263780 1263782 1263785 1263786 1263806
                        1263876 1263904 1263905 1263911 1263923 1263975 1263999 1264003
                        1264006 1264008 1264009 1264019 1264030 1264032 1264033 1264035
                        1264039 1264041 1264044 1264048 1264056 1264065 1264070 1264071
                        1264073 1264074 1264075 1264079 1264088 1264100 1264101 1264110
                        1264121 1264122 1264125 1264129 1264142 1264180 1264188 1264189
                        1264190 1264197 1264237 1264247 1264257 1264270 1264296 1264302
                        1264304 1264308 1264313 1264315 1264317 1264321 1264322 1264328
                        1264331 1264336 1264338 1264339 1264340 1264365 1264377 1264379
                        1264386 1264387 1264388 1264414 1264416 1264417 1264419 1264423
                        1264424 1264425 1264429 1264431 1264436 1264442 1264451 1264473
                        1264477 1264479 1264480 1264520 1264526 1264531 1264538 1264540
                        1264544 1264545 1264548 1264553 1264556 1264560 1264564 1264580
                        1264584 1264590 1264592 1264594 1264598 1264600 1264613 1264615
                        1264616 1264618 1264620 1264624 1264626 1264630 1264633 1264637
                        1264640 1264642 1264644 1264645 1264668 1264677 1264731 1264739
                        1264744 1264746 1264758 1264768 1264780 1264781 1264782 1264783
                        1264785 1264788 1264790 1264791 1264794 1264803 1264809 1264815
                        1264816 1264819 1264821 1264822 1264826 1264830 1264835 1264837
                        1264844 1264846 1264853 1264978 1264987 1264988 1264991 1264993
                        1264997 1265019 1265023 1265032 1265037 1265041 1265047 1265054
                        1265074 1265078 1265079 1265080 1265089 1265092 1265093 1265096
                        1265100 1265101 1265102 1265105 1265112 1265133 1265138 1265142
                        1265249 1265257 1265264 1265627 1266000 1266003 1266399 1266411
                        1266412 1266458 1266467 1266468 1266677 1266679 1266684 1266686
                        1266688 1266692 1266703 1266707 1266721 1266722 1266726 1266729
                        1266732 1266739 1266740 1266741 1266743 1266744 1266751 1266755
                        1266762 1266773 1266774 1266775 1266777 1266780 1266805 1266806
                        1266831 1266832 1266834 1266836 1266838 1266839 1266841 1266842
                        1266846 1266854 1266855 1266863 1266864 1266870 1266872 1266879
                        1266883 1266884 1266886 1266893 1266894 1266898 1266908 1266910
                        1266917 1266920 1266925 1266934 1266935 1266939 1266947 1267021
                        1267027 1267198 1267204 1267213 1267226 1267234 1267251 1267360
                        1267367 1267380 1267432 1267435 1267436 1267445 1267448 1267449
                        1267466 1267472 1267473 1267479 1267491 1267493 1267494 1267495
                        1267496 1267497 1267502 1267524 1267555 1267565 1267571 1267583
                        1267592 1267595 1267611 1267615 1267616 1267618 1267623 1267627
                        1267630 1267632 1267636 1267638 1267643 1267646 1267649 1267658
                        1267661 1267666 1267667 1267669 1267676 1267677 1267680 1267683
                        1267690 1267691 1267693 1267701 1267702 1267704 1267712 1267719
                        1267725 1267728 1267922 1267932 1267939 1267948 1267968 1267987
                        1267990 1267991 1267992 1267994 1268024 1268049 1268051 1268220
                        1268221 1268223 1268290 1268981 1268986 1268989 1269001 1269002
                        1269008 1269025 1269030 1269031 1269036 1269081 1269095 1269098
                        1269106 1269111 1269116 1269124 1269125 1269129 1269131 1269133
                        1269141 1269151 1269153 1269159 1269164 1269172 1269174 1269177
                        1269178 1269187 1269188 1269190 1269193 1269230 1269236 1269239
                        1269245 1269254 1269255 1269257 1269258 1269262 1269273 1269283
                        1269304 1269364 1269378 1269385 1269386 1269389 1269392 1269403
                        1269404 1269410 1269414 1269493 1269505 1269527 1269532 1269537
                        1269556 1269587 1269637 1269644 1269645 1269646 1269651 1269652
                        1269654 1269661 1269663 1269669 1269670 1269674 1269675 1269677
                        1269680 1269682 1269684 1269690 1269691 1269700 1269709 1269710
                        1269711 1269719 1269726 1269733 1269768 1269770 1269772 1269786
                        1269790 1269795 1269796 1269799 1269809 1269811 1269814 1269817
                        1269826 1269877 1269886 1269889 1269898 1269899 1269904 1269976
                        1269984 1269986 1269988 1269989 1269992 1269993 1269996 1269997
                        1269998 1270022 1270042 1270058 1270059 1270112 1270226 1270241
                        1270244 1270248 1270249 1270257 1270260 1270263 1270268 1270302
                        1270393 1270396 1271040 1271050 1271166 1271167 1271248 1271249
                        1271287 1271366 1271402 CVE-2023-20585 CVE-2025-71274 CVE-2025-71286
                        CVE-2025-71291 CVE-2025-71297 CVE-2025-71302 CVE-2025-71305 CVE-2025-71314
                        CVE-2026-11979 CVE-2026-23276 CVE-2026-31430 CVE-2026-31439 CVE-2026-31440
                        CVE-2026-31441 CVE-2026-31447 CVE-2026-31474 CVE-2026-31479 CVE-2026-31485
                        CVE-2026-31497 CVE-2026-31498 CVE-2026-31503 CVE-2026-31509 CVE-2026-31510
                        CVE-2026-31511 CVE-2026-31513 CVE-2026-31520 CVE-2026-31522 CVE-2026-31523
                        CVE-2026-31524 CVE-2026-31532 CVE-2026-31540 CVE-2026-31545 CVE-2026-31548
                        CVE-2026-31549 CVE-2026-31551 CVE-2026-31552 CVE-2026-31561 CVE-2026-31566
                        CVE-2026-31568 CVE-2026-31576 CVE-2026-31578 CVE-2026-31581 CVE-2026-31583
                        CVE-2026-31585 CVE-2026-31587 CVE-2026-31599 CVE-2026-31603 CVE-2026-31604
                        CVE-2026-31605 CVE-2026-31615 CVE-2026-31616 CVE-2026-31617 CVE-2026-31618
                        CVE-2026-31619 CVE-2026-31623 CVE-2026-31624 CVE-2026-31625 CVE-2026-31626
                        CVE-2026-31627 CVE-2026-31651 CVE-2026-31657 CVE-2026-31659 CVE-2026-31660
                        CVE-2026-31661 CVE-2026-31667 CVE-2026-31672 CVE-2026-31678 CVE-2026-31687
                        CVE-2026-31701 CVE-2026-31720 CVE-2026-31726 CVE-2026-31727 CVE-2026-31728
                        CVE-2026-31730 CVE-2026-31747 CVE-2026-31748 CVE-2026-31749 CVE-2026-31751
                        CVE-2026-31754 CVE-2026-31755 CVE-2026-31756 CVE-2026-31761 CVE-2026-31762
                        CVE-2026-31763 CVE-2026-31765 CVE-2026-31768 CVE-2026-31770 CVE-2026-31773
                        CVE-2026-31776 CVE-2026-31778 CVE-2026-31779 CVE-2026-31780 CVE-2026-31781
                        CVE-2026-43007 CVE-2026-43011 CVE-2026-43017 CVE-2026-43018 CVE-2026-43019
                        CVE-2026-43020 CVE-2026-43032 CVE-2026-43043 CVE-2026-43047 CVE-2026-43051
                        CVE-2026-43057 CVE-2026-43058 CVE-2026-43061 CVE-2026-43062 CVE-2026-43064
                        CVE-2026-43069 CVE-2026-43072 CVE-2026-43092 CVE-2026-43098 CVE-2026-43104
                        CVE-2026-43105 CVE-2026-43111 CVE-2026-43113 CVE-2026-43117 CVE-2026-43118
                        CVE-2026-43123 CVE-2026-43124 CVE-2026-43129 CVE-2026-43133 CVE-2026-43134
                        CVE-2026-43135 CVE-2026-43136 CVE-2026-43137 CVE-2026-43140 CVE-2026-43141
                        CVE-2026-43143 CVE-2026-43147 CVE-2026-43149 CVE-2026-43152 CVE-2026-43156
                        CVE-2026-43157 CVE-2026-43159 CVE-2026-43162 CVE-2026-43167 CVE-2026-43169
                        CVE-2026-43177 CVE-2026-43180 CVE-2026-43182 CVE-2026-43183 CVE-2026-43189
                        CVE-2026-43191 CVE-2026-43194 CVE-2026-43196 CVE-2026-43199 CVE-2026-43200
                        CVE-2026-43202 CVE-2026-43203 CVE-2026-43204 CVE-2026-43205 CVE-2026-43207
                        CVE-2026-43211 CVE-2026-43215 CVE-2026-43218 CVE-2026-43220 CVE-2026-43221
                        CVE-2026-43222 CVE-2026-43223 CVE-2026-43225 CVE-2026-43226 CVE-2026-43231
                        CVE-2026-43232 CVE-2026-43236 CVE-2026-43240 CVE-2026-43241 CVE-2026-43242
                        CVE-2026-43243 CVE-2026-43244 CVE-2026-43246 CVE-2026-43248 CVE-2026-43251
                        CVE-2026-43253 CVE-2026-43255 CVE-2026-43256 CVE-2026-43257 CVE-2026-43260
                        CVE-2026-43264 CVE-2026-43269 CVE-2026-43270 CVE-2026-43277 CVE-2026-43278
                        CVE-2026-43279 CVE-2026-43287 CVE-2026-43291 CVE-2026-43294 CVE-2026-43295
                        CVE-2026-43300 CVE-2026-43302 CVE-2026-43304 CVE-2026-43312 CVE-2026-43313
                        CVE-2026-43314 CVE-2026-43316 CVE-2026-43318 CVE-2026-43319 CVE-2026-43320
                        CVE-2026-43324 CVE-2026-43327 CVE-2026-43337 CVE-2026-43340 CVE-2026-43342
                        CVE-2026-43343 CVE-2026-43346 CVE-2026-43353 CVE-2026-43357 CVE-2026-43370
                        CVE-2026-43373 CVE-2026-43380 CVE-2026-43381 CVE-2026-43382 CVE-2026-43383
                        CVE-2026-43387 CVE-2026-43395 CVE-2026-43397 CVE-2026-43412 CVE-2026-43425
                        CVE-2026-43426 CVE-2026-43427 CVE-2026-43428 CVE-2026-43429 CVE-2026-43430
                        CVE-2026-43432 CVE-2026-43436 CVE-2026-43443 CVE-2026-43444 CVE-2026-43445
                        CVE-2026-43449 CVE-2026-43450 CVE-2026-43452 CVE-2026-43459 CVE-2026-43465
                        CVE-2026-43466 CVE-2026-43467 CVE-2026-43468 CVE-2026-43473 CVE-2026-43476
                        CVE-2026-43480 CVE-2026-43488 CVE-2026-43493 CVE-2026-43496 CVE-2026-43497
                        CVE-2026-45834 CVE-2026-45835 CVE-2026-45839 CVE-2026-45851 CVE-2026-45853
                        CVE-2026-45857 CVE-2026-45858 CVE-2026-45867 CVE-2026-45868 CVE-2026-45869
                        CVE-2026-45871 CVE-2026-45875 CVE-2026-45877 CVE-2026-45879 CVE-2026-45880
                        CVE-2026-45881 CVE-2026-45883 CVE-2026-45885 CVE-2026-45899 CVE-2026-45902
                        CVE-2026-45911 CVE-2026-45914 CVE-2026-45916 CVE-2026-45919 CVE-2026-45920
                        CVE-2026-45921 CVE-2026-45922 CVE-2026-45923 CVE-2026-45928 CVE-2026-45936
                        CVE-2026-45941 CVE-2026-45946 CVE-2026-45947 CVE-2026-45954 CVE-2026-45958
                        CVE-2026-45963 CVE-2026-45969 CVE-2026-45976 CVE-2026-45981 CVE-2026-45982
                        CVE-2026-45986 CVE-2026-45987 CVE-2026-45994 CVE-2026-45996 CVE-2026-45997
                        CVE-2026-46006 CVE-2026-46009 CVE-2026-46011 CVE-2026-46016 CVE-2026-46018
                        CVE-2026-46019 CVE-2026-46023 CVE-2026-46027 CVE-2026-46033 CVE-2026-46040
                        CVE-2026-46046 CVE-2026-46048 CVE-2026-46049 CVE-2026-46050 CVE-2026-46051
                        CVE-2026-46052 CVE-2026-46056 CVE-2026-46058 CVE-2026-46059 CVE-2026-46064
                        CVE-2026-46068 CVE-2026-46075 CVE-2026-46077 CVE-2026-46082 CVE-2026-46086
                        CVE-2026-46088 CVE-2026-46089 CVE-2026-46092 CVE-2026-46099 CVE-2026-46102
                        CVE-2026-46103 CVE-2026-46108 CVE-2026-46122 CVE-2026-46125 CVE-2026-46128
                        CVE-2026-46131 CVE-2026-46132 CVE-2026-46136 CVE-2026-46138 CVE-2026-46140
                        CVE-2026-46143 CVE-2026-46146 CVE-2026-46151 CVE-2026-46152 CVE-2026-46161
                        CVE-2026-46163 CVE-2026-46165 CVE-2026-46166 CVE-2026-46167 CVE-2026-46177
                        CVE-2026-46178 CVE-2026-46179 CVE-2026-46184 CVE-2026-46186 CVE-2026-46187
                        CVE-2026-46190 CVE-2026-46191 CVE-2026-46198 CVE-2026-46199 CVE-2026-46201
                        CVE-2026-46204 CVE-2026-46205 CVE-2026-46206 CVE-2026-46207 CVE-2026-46211
                        CVE-2026-46212 CVE-2026-46216 CVE-2026-46218 CVE-2026-46219 CVE-2026-46220
                        CVE-2026-46225 CVE-2026-46230 CVE-2026-46231 CVE-2026-46232 CVE-2026-46233
                        CVE-2026-46235 CVE-2026-46236 CVE-2026-46238 CVE-2026-46242 CVE-2026-46247
                        CVE-2026-46249 CVE-2026-46252 CVE-2026-46261 CVE-2026-46263 CVE-2026-46267
                        CVE-2026-46270 CVE-2026-46275 CVE-2026-46276 CVE-2026-46285 CVE-2026-46286
                        CVE-2026-46294 CVE-2026-46307 CVE-2026-46312 CVE-2026-46313 CVE-2026-46314
                        CVE-2026-46321 CVE-2026-46322 CVE-2026-46330 CVE-2026-52904 CVE-2026-52914
                        CVE-2026-52915 CVE-2026-52916 CVE-2026-52919 CVE-2026-52922 CVE-2026-52924
                        CVE-2026-52926 CVE-2026-52931 CVE-2026-52933 CVE-2026-52936 CVE-2026-52948
                        CVE-2026-52951 CVE-2026-52953 CVE-2026-52955 CVE-2026-52956 CVE-2026-52958
                        CVE-2026-52961 CVE-2026-52963 CVE-2026-52964 CVE-2026-52976 CVE-2026-52981
                        CVE-2026-52982 CVE-2026-52989 CVE-2026-52993 CVE-2026-52995 CVE-2026-53003
                        CVE-2026-53004 CVE-2026-53009 CVE-2026-53013 CVE-2026-53021 CVE-2026-53022
                        CVE-2026-53035 CVE-2026-53036 CVE-2026-53037 CVE-2026-53039 CVE-2026-53045
                        CVE-2026-53047 CVE-2026-53049 CVE-2026-53050 CVE-2026-53056 CVE-2026-53058
                        CVE-2026-53060 CVE-2026-53065 CVE-2026-53066 CVE-2026-53068 CVE-2026-53070
                        CVE-2026-53073 CVE-2026-53075 CVE-2026-53078 CVE-2026-53080 CVE-2026-53086
                        CVE-2026-53090 CVE-2026-53093 CVE-2026-53098 CVE-2026-53112 CVE-2026-53135
                        CVE-2026-53136 CVE-2026-53137 CVE-2026-53139 CVE-2026-53140 CVE-2026-53143
                        CVE-2026-53144 CVE-2026-53146 CVE-2026-53147 CVE-2026-53148 CVE-2026-53149
                        CVE-2026-53150 CVE-2026-53158 CVE-2026-53159 CVE-2026-53160 CVE-2026-53161
                        CVE-2026-53167 CVE-2026-53168 CVE-2026-53176 CVE-2026-53178 CVE-2026-53181
                        CVE-2026-53186 CVE-2026-53190 CVE-2026-53192 CVE-2026-53194 CVE-2026-53195
                        CVE-2026-53196 CVE-2026-53202 CVE-2026-53203 CVE-2026-53208 CVE-2026-53209
                        CVE-2026-53213 CVE-2026-53215 CVE-2026-53216 CVE-2026-53217 CVE-2026-53218
                        CVE-2026-53224 CVE-2026-53225 CVE-2026-53227 CVE-2026-53229 CVE-2026-53237
                        CVE-2026-53239 CVE-2026-53241 CVE-2026-53242 CVE-2026-53245 CVE-2026-53246
                        CVE-2026-53249 CVE-2026-53254 CVE-2026-53255 CVE-2026-53256 CVE-2026-53258
                        CVE-2026-53268 CVE-2026-53272 CVE-2026-53274 CVE-2026-53279 CVE-2026-53285
                        CVE-2026-53293 CVE-2026-53306 CVE-2026-53313 CVE-2026-53325 CVE-2026-53329
                        CVE-2026-53339 CVE-2026-53347 CVE-2026-53350 CVE-2026-53355 CVE-2026-53356
                        CVE-2026-53357 CVE-2026-53358 CVE-2026-53359 CVE-2026-53360 CVE-2026-53362
                        CVE-2026-53366 CVE-2026-54411 CVE-2026-56288 CVE-2026-56289 
-----------------------------------------------------------------

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released:    Fri Jul 17 13:39:27 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1269790,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3106-1
Released:    Fri Jul 17 16:02:05 2026
Summary:     Recommended update for kmod
Type:        recommended
Severity:    moderate
References:  
This update for kmod fixes the following issues:

- Use in-kernel decompression if available (jsc#PED-16303):
    * libkmod:
        + Add a separate function to load the file contents when it's needed.
          When it's not needed on the path of loading modules via finit_module(),
          there is no need to mmap the file.
        + Extract 2 functions to handle finit_module vs init_modules differences,
          with a fallback from the former to the latter.
        + Don't only set the type as direct, but also keep track of the compression being used.
        + When creating the context, read /sys/kernel/compression to check. 
          what's the compression type supported by the kernel.
        + Use kernel decompression when available
        + add fallback MODULE_INIT_COMPRESSED_FILE define

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released:    Tue Jul 21 09:04:39 2026
Summary:     Recommended update for shadow
Type:        recommended
Severity:    important
References:  1270393
This update for shadow fixes the following issues:

- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3161-1
Released:    Tue Jul 21 16:30:29 2026
Summary:     Security update for patch
Type:        security
Severity:    low
References:  1271166,1271167,CVE-2026-56288,CVE-2026-56289
This update for patch fixes the following issues

- CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167).
- CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released:    Tue Jul 21 16:50:54 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3166-1
Released:    Tue Jul 21 19:09:06 2026
Summary:     Security update for the Linux Kernel
Type:        security
Severity:    important
References:  1204315,1243603,1251942,1256564,1257605,1257777,1260012,1260593,1261250,1261562,1262391,1262603,1262605,1262614,1262637,1262639,1262649,1262653,1262658,1262659,1262678,1262723,1262751,1262757,1262765,1262768,1262992,1263008,1263011,1263013,1263014,1263016,1263017,1263020,1263025,1263030,1263031,1263045,1263055,1263059,1263068,1263073,1263075,1263077,1263097,1263111,1263128,1263134,1263139,1263142,1263145,1263167,1263173,1263175,1263491,1263493,1263495,1263539,1263562,1263598,1263657,1263776,1263777,1263778,1263780,1263782,1263785,1263786,1263806,1263876,1263904,1263905,1263911,1263923,1263975,1263999,1264003,1264006,1264008,1264009,1264019,1264030,1264032,1264033,1264035,1264039,1264041,1264044,1264048,1264056,1264065,1264070,1264071,1264073,1264074,1264075,1264079,1264088,1264100,1264101,1264110,1264121,1264122,1264125,1264129,1264142,1264180,1264188,1264189,1264190,1264197,1264237,1264247,1264257,1264270,1264296,1264302,1264304,1264308,1264313,1264315,1264317,1264321,1
 264322,1264328,1264331,1264336,1264338,1264339,1264340,1264365,1264377,1264379,1264386,1264387,1264388,1264414,1264416,1264417,1264419,1264423,1264424,1264425,1264429,1264431,1264436,1264442,1264451,1264473,1264477,1264479,1264480,1264520,1264526,1264531,1264538,1264540,1264544,1264545,1264548,1264553,1264556,1264560,1264564,1264580,1264584,1264590,1264592,1264594,1264598,1264600,1264613,1264615,1264616,1264618,1264620,1264624,1264626,1264630,1264633,1264637,1264640,1264642,1264644,1264645,1264668,1264677,1264731,1264739,1264744,1264746,1264758,1264768,1264780,1264781,1264782,1264783,1264785,1264788,1264790,1264791,1264794,1264803,1264809,1264815,1264816,1264819,1264821,1264822,1264826,1264830,1264835,1264837,1264844,1264846,1264853,1264978,1264987,1264988,1264991,1264993,1264997,1265019,1265023,1265032,1265037,1265041,1265047,1265054,1265074,1265078,1265079,1265080,1265089,1265092,1265093,1265096,1265100,1265101,1265102,1265105,1265112,1265133,1265138,1265142,1265249,1265257,126526
 4,1265627,1266000,1266003,1266399,1266411,1266412,1266458,1266467,1266468,1266677,1266679,1266684,1266686,1266688,1266692,1266703,1266707,1266721,1266722,1266726,1266729,1266732,1266739,1266740,1266741,1266743,1266744,1266751,1266755,1266762,1266773,1266774,1266775,1266777,1266780,1266805,1266806,1266831,1266832,1266834,1266836,1266838,1266839,1266841,1266842,1266846,1266854,1266855,1266863,1266864,1266870,1266872,1266879,1266883,1266884,1266886,1266893,1266894,1266898,1266908,1266910,1266917,1266920,1266925,1266934,1266935,1266939,1266947,1267021,1267027,1267198,1267204,1267213,1267226,1267234,1267251,1267360,1267367,1267380,1267432,1267435,1267436,1267445,1267448,1267449,1267466,1267472,1267473,1267479,1267491,1267493,1267494,1267495,1267496,1267497,1267502,1267524,1267555,1267565,1267571,1267583,1267592,1267595,1267611,1267615,1267616,1267618,1267623,1267627,1267630,1267632,1267636,1267638,1267643,1267646,1267649,1267658,1267661,1267666,1267667,1267669,1267676,1267677,1267680,126
 7683,1267690,1267691,1267693,1267701,1267702,1267704,1267712,1267719,1267725,1267728,1267922,1267932,1267939,1267948,1267968,1267987,1267990,1267991,1267992,1267994,1268024,1268049,1268051,1268220,1268221,1268223,1268981,1268986,1268989,1269001,1269002,1269008,1269025,1269030,1269031,1269036,1269081,1269095,1269098,1269106,1269111,1269116,1269124,1269125,1269129,1269131,1269133,1269141,1269151,1269153,1269159,1269164,1269172,1269174,1269177,1269178,1269187,1269188,1269190,1269193,1269230,1269236,1269239,1269245,1269254,1269255,1269257,1269258,1269262,1269273,1269283,1269304,1269364,1269378,1269385,1269386,1269389,1269392,1269403,1269404,1269410,1269414,1269493,1269505,1269527,1269532,1269537,1269556,1269587,1269637,1269644,1269645,1269646,1269651,1269652,1269654,1269661,1269663,1269669,1269670,1269674,1269675,1269677,1269680,1269682,1269684,1269690,1269691,1269700,1269709,1269710,1269711,1269719,1269726,1269733,1269768,1269770,1269772,1269786,1269795,1269796,1269799,1269809,1269811,
 1269814,1269817,1269826,1269877,1269886,1269889,1269898,1269899,1269904,1269976,1269984,1269986,1269988,1269989,1269992,1269993,1269996,1269997,1269998,1270022,1270042,1270058,1270059,1270112,1270226,1270241,1270244,1270248,1270249,1270257,1270260,1270263,1270268,1270302,1270396,1271040,1271050,1271248,1271249,1271287,1271366,1271402,CVE-2023-20585,CVE-2025-71274,CVE-2025-71286,CVE-2025-71291,CVE-2025-71297,CVE-2025-71302,CVE-2025-71305,CVE-2025-71314,CVE-2026-23276,CVE-2026-31430,CVE-2026-31439,CVE-2026-31440,CVE-2026-31441,CVE-2026-31447,CVE-2026-31474,CVE-2026-31479,CVE-2026-31485,CVE-2026-31497,CVE-2026-31498,CVE-2026-31503,CVE-2026-31509,CVE-2026-31510,CVE-2026-31511,CVE-2026-31513,CVE-2026-31520,CVE-2026-31522,CVE-2026-31523,CVE-2026-31524,CVE-2026-31532,CVE-2026-31540,CVE-2026-31545,CVE-2026-31548,CVE-2026-31549,CVE-2026-31551,CVE-2026-31552,CVE-2026-31561,CVE-2026-31566,CVE-2026-31568,CVE-2026-31576,CVE-2026-31578,CVE-2026-31581,CVE-2026-31583,CVE-2026-31585,CVE-2026-31587,C
 VE-2026-31599,CVE-2026-31603,CVE-2026-31604,CVE-2026-31605,CVE-2026-31615,CVE-2026-31616,CVE-2026-31617,CVE-2026-31618,CVE-2026-31619,CVE-2026-31623,CVE-2026-31624,CVE-2026-31625,CVE-2026-31626,CVE-2026-31627,CVE-2026-31651,CVE-2026-31657,CVE-2026-31659,CVE-2026-31660,CVE-2026-31661,CVE-2026-31667,CVE-2026-31672,CVE-2026-31678,CVE-2026-31687,CVE-2026-31701,CVE-2026-31720,CVE-2026-31726,CVE-2026-31727,CVE-2026-31728,CVE-2026-31730,CVE-2026-31747,CVE-2026-31748,CVE-2026-31749,CVE-2026-31751,CVE-2026-31754,CVE-2026-31755,CVE-2026-31756,CVE-2026-31761,CVE-2026-31762,CVE-2026-31763,CVE-2026-31765,CVE-2026-31768,CVE-2026-31770,CVE-2026-31773,CVE-2026-31776,CVE-2026-31778,CVE-2026-31779,CVE-2026-31780,CVE-2026-31781,CVE-2026-43007,CVE-2026-43011,CVE-2026-43017,CVE-2026-43018,CVE-2026-43019,CVE-2026-43020,CVE-2026-43032,CVE-2026-43043,CVE-2026-43047,CVE-2026-43051,CVE-2026-43057,CVE-2026-43058,CVE-2026-43061,CVE-2026-43062,CVE-2026-43064,CVE-2026-43069,CVE-2026-43072,CVE-2026-43092,CVE-2026
 -43098,CVE-2026-43104,CVE-2026-43105,CVE-2026-43111,CVE-2026-43113,CVE-2026-43117,CVE-2026-43118,CVE-2026-43123,CVE-2026-43124,CVE-2026-43129,CVE-2026-43133,CVE-2026-43134,CVE-2026-43135,CVE-2026-43136,CVE-2026-43137,CVE-2026-43140,CVE-2026-43141,CVE-2026-43143,CVE-2026-43147,CVE-2026-43149,CVE-2026-43152,CVE-2026-43156,CVE-2026-43157,CVE-2026-43159,CVE-2026-43162,CVE-2026-43167,CVE-2026-43169,CVE-2026-43177,CVE-2026-43180,CVE-2026-43182,CVE-2026-43183,CVE-2026-43189,CVE-2026-43191,CVE-2026-43194,CVE-2026-43196,CVE-2026-43199,CVE-2026-43200,CVE-2026-43202,CVE-2026-43203,CVE-2026-43204,CVE-2026-43205,CVE-2026-43207,CVE-2026-43211,CVE-2026-43215,CVE-2026-43218,CVE-2026-43220,CVE-2026-43221,CVE-2026-43222,CVE-2026-43223,CVE-2026-43225,CVE-2026-43226,CVE-2026-43231,CVE-2026-43232,CVE-2026-43236,CVE-2026-43240,CVE-2026-43241,CVE-2026-43242,CVE-2026-43243,CVE-2026-43244,CVE-2026-43246,CVE-2026-43248,CVE-2026-43251,CVE-2026-43253,CVE-2026-43255,CVE-2026-43256,CVE-2026-43257,CVE-2026-43260,
 CVE-2026-43264,CVE-2026-43269,CVE-2026-43270,CVE-2026-43277,CVE-2026-43278,CVE-2026-43279,CVE-2026-43287,CVE-2026-43291,CVE-2026-43294,CVE-2026-43295,CVE-2026-43300,CVE-2026-43302,CVE-2026-43304,CVE-2026-43312,CVE-2026-43313,CVE-2026-43314,CVE-2026-43316,CVE-2026-43318,CVE-2026-43319,CVE-2026-43320,CVE-2026-43324,CVE-2026-43327,CVE-2026-43337,CVE-2026-43340,CVE-2026-43342,CVE-2026-43343,CVE-2026-43346,CVE-2026-43353,CVE-2026-43357,CVE-2026-43370,CVE-2026-43373,CVE-2026-43380,CVE-2026-43381,CVE-2026-43382,CVE-2026-43383,CVE-2026-43387,CVE-2026-43395,CVE-2026-43397,CVE-2026-43412,CVE-2026-43425,CVE-2026-43426,CVE-2026-43427,CVE-2026-43428,CVE-2026-43429,CVE-2026-43430,CVE-2026-43432,CVE-2026-43436,CVE-2026-43443,CVE-2026-43444,CVE-2026-43445,CVE-2026-43449,CVE-2026-43450,CVE-2026-43452,CVE-2026-43459,CVE-2026-43465,CVE-2026-43466,CVE-2026-43467,CVE-2026-43468,CVE-2026-43473,CVE-2026-43476,CVE-2026-43480,CVE-2026-43488,CVE-2026-43493,CVE-2026-43496,CVE-2026-43497,CVE-2026-45834,CVE-202
 6-45835,CVE-2026-45839,CVE-2026-45851,CVE-2026-45853,CVE-2026-45857,CVE-2026-45858,CVE-2026-45867,CVE-2026-45868,CVE-2026-45869,CVE-2026-45871,CVE-2026-45875,CVE-2026-45877,CVE-2026-45879,CVE-2026-45880,CVE-2026-45881,CVE-2026-45883,CVE-2026-45885,CVE-2026-45899,CVE-2026-45902,CVE-2026-45911,CVE-2026-45914,CVE-2026-45916,CVE-2026-45919,CVE-2026-45920,CVE-2026-45921,CVE-2026-45922,CVE-2026-45923,CVE-2026-45928,CVE-2026-45936,CVE-2026-45941,CVE-2026-45946,CVE-2026-45947,CVE-2026-45954,CVE-2026-45958,CVE-2026-45963,CVE-2026-45969,CVE-2026-45976,CVE-2026-45981,CVE-2026-45982,CVE-2026-45986,CVE-2026-45987,CVE-2026-45994,CVE-2026-45996,CVE-2026-45997,CVE-2026-46006,CVE-2026-46009,CVE-2026-46011,CVE-2026-46016,CVE-2026-46018,CVE-2026-46019,CVE-2026-46023,CVE-2026-46027,CVE-2026-46033,CVE-2026-46040,CVE-2026-46046,CVE-2026-46048,CVE-2026-46049,CVE-2026-46050,CVE-2026-46051,CVE-2026-46052,CVE-2026-46056,CVE-2026-46058,CVE-2026-46059,CVE-2026-46064,CVE-2026-46068,CVE-2026-46075,CVE-2026-46077
 ,CVE-2026-46082,CVE-2026-46086,CVE-2026-46088,CVE-2026-46089,CVE-2026-46092,CVE-2026-46099,CVE-2026-46102,CVE-2026-46103,CVE-2026-46108,CVE-2026-46122,CVE-2026-46125,CVE-2026-46128,CVE-2026-46131,CVE-2026-46132,CVE-2026-46136,CVE-2026-46138,CVE-2026-46140,CVE-2026-46143,CVE-2026-46146,CVE-2026-46151,CVE-2026-46152,CVE-2026-46161,CVE-2026-46163,CVE-2026-46165,CVE-2026-46166,CVE-2026-46167,CVE-2026-46177,CVE-2026-46178,CVE-2026-46179,CVE-2026-46184,CVE-2026-46186,CVE-2026-46187,CVE-2026-46190,CVE-2026-46191,CVE-2026-46198,CVE-2026-46199,CVE-2026-46201,CVE-2026-46204,CVE-2026-46205,CVE-2026-46206,CVE-2026-46207,CVE-2026-46211,CVE-2026-46212,CVE-2026-46216,CVE-2026-46218,CVE-2026-46219,CVE-2026-46220,CVE-2026-46225,CVE-2026-46230,CVE-2026-46231,CVE-2026-46232,CVE-2026-46233,CVE-2026-46235,CVE-2026-46236,CVE-2026-46238,CVE-2026-46242,CVE-2026-46247,CVE-2026-46249,CVE-2026-46252,CVE-2026-46261,CVE-2026-46263,CVE-2026-46267,CVE-2026-46270,CVE-2026-46275,CVE-2026-46276,CVE-2026-46285,CVE-20
 26-46286,CVE-2026-46294,CVE-2026-46307,CVE-2026-46312,CVE-2026-46313,CVE-2026-46314,CVE-2026-46321,CVE-2026-46322,CVE-2026-46330,CVE-2026-52904,CVE-2026-52914,CVE-2026-52915,CVE-2026-52916,CVE-2026-52919,CVE-2026-52922,CVE-2026-52924,CVE-2026-52926,CVE-2026-52931,CVE-2026-52933,CVE-2026-52936,CVE-2026-52948,CVE-2026-52951,CVE-2026-52953,CVE-2026-52955,CVE-2026-52956,CVE-2026-52958,CVE-2026-52961,CVE-2026-52963,CVE-2026-52964,CVE-2026-52976,CVE-2026-52981,CVE-2026-52982,CVE-2026-52989,CVE-2026-52993,CVE-2026-52995,CVE-2026-53003,CVE-2026-53004,CVE-2026-53009,CVE-2026-53013,CVE-2026-53021,CVE-2026-53022,CVE-2026-53035,CVE-2026-53036,CVE-2026-53037,CVE-2026-53039,CVE-2026-53045,CVE-2026-53047,CVE-2026-53049,CVE-2026-53050,CVE-2026-53056,CVE-2026-53058,CVE-2026-53060,CVE-2026-53065,CVE-2026-53066,CVE-2026-53068,CVE-2026-53070,CVE-2026-53073,CVE-2026-53075,CVE-2026-53078,CVE-2026-53080,CVE-2026-53086,CVE-2026-53090,CVE-2026-53093,CVE-2026-53098,CVE-2026-53112,CVE-2026-53135,CVE-2026-5313
 6,CVE-2026-53137,CVE-2026-53139,CVE-2026-53140,CVE-2026-53143,CVE-2026-53144,CVE-2026-53146,CVE-2026-53147,CVE-2026-53148,CVE-2026-53149,CVE-2026-53150,CVE-2026-53158,CVE-2026-53159,CVE-2026-53160,CVE-2026-53161,CVE-2026-53167,CVE-2026-53168,CVE-2026-53176,CVE-2026-53178,CVE-2026-53181,CVE-2026-53186,CVE-2026-53190,CVE-2026-53192,CVE-2026-53194,CVE-2026-53195,CVE-2026-53196,CVE-2026-53202,CVE-2026-53203,CVE-2026-53208,CVE-2026-53209,CVE-2026-53213,CVE-2026-53215,CVE-2026-53216,CVE-2026-53217,CVE-2026-53218,CVE-2026-53224,CVE-2026-53225,CVE-2026-53227,CVE-2026-53229,CVE-2026-53237,CVE-2026-53239,CVE-2026-53241,CVE-2026-53242,CVE-2026-53245,CVE-2026-53246,CVE-2026-53249,CVE-2026-53254,CVE-2026-53255,CVE-2026-53256,CVE-2026-53258,CVE-2026-53268,CVE-2026-53272,CVE-2026-53274,CVE-2026-53279,CVE-2026-53285,CVE-2026-53293,CVE-2026-53306,CVE-2026-53313,CVE-2026-53325,CVE-2026-53329,CVE-2026-53339,CVE-2026-53347,CVE-2026-53350,CVE-2026-53355,CVE-2026-53356,CVE-2026-53357,CVE-2026-53358,CVE-2
 026-53359,CVE-2026-53360,CVE-2026-53362,CVE-2026-53366
The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues

The following security issues were fixed:

- CVE-2023-20585: iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19 (bsc#1243603).
- CVE-2025-71302: drm/panthor: fix for dma-fence safe access rules (bsc#1264837).
- CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765).
- CVE-2026-31503: udp: Fix wildcard bind conflict check when using hash2 (bsc#1263077).
- CVE-2026-43019: Bluetooth: hci_conn: fix potential UAF in set_cig_params_sync (bsc#1264003).
- CVE-2026-43057: net: mpls: error out if inner headers are not set (bsc#1264056).
- CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270).
- CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545).
- CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624).
- CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580).
- CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 (bsc#1264548).
- CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304).
- CVE-2026-43199: net/mlx5e: Fix 'scheduling while atomic' in IPsec MAC address query (bsc#1264556).
- CVE-2026-43204: ASoC: qcom: q6asm: handle the responses after closing (bsc#1264531).
- CVE-2026-43205: dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328).
- CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544).
- CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386).
- CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321).
- CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302).
- CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1260593 bsc#1264419).
- CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429).
- CVE-2026-43294: drm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels (bsc#1264853).
- CVE-2026-43304: libceph: define and enforce CEPH_MAX_KEY_LEN (bsc#1264993).
- CVE-2026-43320: drm/amd/display: Fix dsc eDP issue (bsc#1264987).
- CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112).
- CVE-2026-43353: i3c: mipi-i3c-hci: Fix race in DMA ring dequeue (bsc#1265089).
- CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079).
- CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744).
- CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041).
- CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023).
- CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794).
- CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142).
- CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997).
- CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790).
- CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw->wq (bsc#1264978).
- CVE-2026-43473: scsi: mpi3mr: Add NULL checks when resetting request and reply queues (bsc#1264731).
- CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000).
- CVE-2026-45839: bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() (bsc#1266399).
- CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458).
- CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773).
- CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883).
- CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893).
- CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805).
- CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204).
- CVE-2026-45987: KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (bsc#1267213).
- CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432).
- CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740).
- CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449).
- CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744).
- CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472).
- CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726).
- CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686).
- CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360).
- CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).
- CVE-2026-46059: KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (bsc#1267495).
- CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497).
- CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592).
- CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524).
- CVE-2026-46089: zram: do not forget to endio for partial discard requests (bsc#1267445).
- CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722).
- CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502).
- CVE-2026-46132: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo (bsc#1267616).
- CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838).
- CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493).
- CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690).
- CVE-2026-46207: vsock/virtio: fix length and offset in tap skb for split packets (bsc#1267691).
- CVE-2026-46216: drm/xe/hdcp: Add NULL check for media_gt in (bsc#1267234).
- CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618).
- CVE-2026-46249: octeontx2-af: Fix PF driver crash with kexec kernel booting (bsc#1267683).
- CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992).
- CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024).
- CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994).
- CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001).
- CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).
- CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989).
- CVE-2026-52953: iommu/vt-d: Fix oops due to out of scope access (bsc#1269133).
- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
- CVE-2026-52961: ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size (bsc#1269129).
- CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254).
- CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
- CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124).
- CVE-2026-53003: pppoe: drop PFC frames (bsc#1269111).
- CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106).
- CVE-2026-53009: ice: fix double-free of tx_buf skb (bsc#1269098).
- CVE-2026-53013: macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF (bsc#1269095).
- CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151).
- CVE-2026-53035: bpf, sockmap: Fix af_unix iter deadlock (bsc#1269190).
- CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389).
- CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392).
- CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646).
- CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).
- CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164).
- CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690).
- CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700).
- CVE-2026-53086: net: bcmgenet: fix racing timeout handler (bsc#1269537).
- CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532).
- CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262).
- CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768).
- CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645).
- CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710).
- CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795).
- CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886).
- CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663).
- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
- CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680).
- CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587).
- CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989).
- CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273).
- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
- CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711).
- CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877).
- CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691).
- CVE-2026-53239: xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx() (bsc#1269677).
- CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675).
- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
- CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992).
- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
- CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230).
- CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257).
- CVE-2026-53272: erofs: fix use-after-free on sbi->sync_decompress (bsc#1269809).
- CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651).
- CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527).
- CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814).
- CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249).
- CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).
- CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270302).
- CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366).

The following non security issues were fixed:

- ALSA: hda: conexant: Remove mic bias threshold override (git-fixes).
- ALSA: hda: Fix cached processing coefficient verbs (git-fixes).
- ALSA: usb-audio: Skip DSD quirk for Musical Fidelity M6s DAC (git-fixes).
- ASoC: amd: ps: fix wrong ACP version string in pci_request_regions() (git-fixes).
- ASoC: cs42l43: Correct report for forced microphone jack (git-fixes).
- ASoC: meson: aiu: fifo-spdif: soft reset the S/PDIF datapath on start/stop (git-fixes).
- ASoC: tas2562: fix deprecated 'shut-down' GPIO always cleared after lookup (git-fixes).
- batman-adv: access unicast_ttvn skb->data only after skb realloc (git-fixes).
- batman-adv: bla: reacquire gw address after skb realloc (git-fixes).
- batman-adv: dat: acquire ARP hw source only after skb realloc (git-fixes).
- batman-adv: dat: ensure accessible eth_hdr proto field (git-fixes).
- batman-adv: gw: acquire ethernet header only after skb realloc (git-fixes).
- Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes).
- Bluetooth: bnep: pin L2CAP connection during netdev registration (git-fixes).
- Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup() (git-fixes).
- Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes).
- Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes).
- Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes).
- Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes).
- Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes).
- Bluetooth: L2CAP: validate option length before reading conf opt value (git-fixes).
- Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes).
- Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git-fixes).
- bnxt_en: Add a timeout parameter to bnxt_hwrm_port_ts_query() (bsc#1264180).
- bnxt_en: Add is_ts_pkt field to struct bnxt_sw_tx_bd (bsc#1264180).
- bnxt_en: Add new TX timestamp completion definitions (bsc#1264180).
- bnxt_en: Add TX timestamp completion logic (bsc#1264180).
- bnxt_en: Allow some TX packets to be unprocessed in NAPI (bsc#1264180).
- bnxt_en: fix module unload sequence (bsc#1264180).
- bnxt_en: Fix PTP firmware timeout parameter (bsc#1264180).
- bnxt_en: improve TX timestamping FIFO configuration (bsc#1264180).
- bnxt_en: Increase the max total outstanding PTP TX packets to 4 (bsc#1264180).
- bnxt_en: Let bnxt_stamp_tx_skb() return error code (bsc#1264180).
- bnxt_en: Refactor all PTP TX timestamp fields into a struct (bsc#1264180).
- bnxt_en: Remove an impossible condition check for PTP TX pending SKB (bsc#1264180).
- bnxt_en: Remove atomic operations on ptp->tx_avail (bsc#1264180).
- bnxt_en: Retry PTP TX timestamp from FW for 1 second (bsc#1264180).
- bnxt_en: silence clang build warning (bsc#1264180).
- bpf: Disambiguate SCALAR register state output in verifier logs (bsc#1271249).
- crypto: qat - Replace kzalloc() + copy_from_user() with memdup_user() (stable-fixes).
- crypto: qat - Return pointer directly in adf_ctl_alloc_resources (stable-fixes).
- drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference (git-fixes).
- drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips (git-fixes).
- drm/amd/pm: fix amdgpu_pm_info power display units (git-fixes).
- drm/amd/pm: fix smu13 power limit range calculation (git-fixes).
- drm/amdgpu: fix aperture mapping leak (git-fixes).
- drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() (git-fixes).
- drm/gfx10: Program DB_RING_CONTROL (git-fixes).
- drm/i915/bios: range check LFP Data Block panel_type2 (git-fixes).
- drm/i915/gem: Do not leak siblings[] on proto context error (git-fixes).
- drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU (git-fixes).
- drm/i915: Return NULL on error in active_instance (git-fixes).
- drm/imagination: Fix double call to drm_sched_entity_fini() (git-fixes).
- drm/imagination: fix error checking of pvr_vm_context_lookup() (git-fixes).
- drm/imagination: Fix returned size for DRM_IOCTL_PVR_DEV_QUERY (git-fixes).
- drm/imagination: Fix user array stride in pvr_set_uobj_array() (git-fixes).
- drm/panthor: Don't overrule pending immediate ticks in sched_resume_tick() (git-fixes).
- drm/panthor: Fix a leak when a group is evicted before the tiler OOM is serviced (git-fixes).
- drm/panthor: Fix potential invalid pointer deref in group_process_tiler_oom() (git-fixes).
- drm/panthor: Interrupt group start/resumption if group_bind_locked() fails (git-fixes).
- drm/v3d: Reject invalid indirect BO handle in indirect CSD setup (git-fixes).
- drm/virtio: bound EDID block reads to the response buffer (git-fixes).
- drm/xe/hw_engine: Fix double-free of managed BO in error path (git-fixes).
- drm/xe/pf: Don't attempt to process FAST_REQ or EVENT relays (git-fixes).
- drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() (git-fixes).
- drm/xe: Fix PTE index in xe_vm_populate_pgtable() for chunked binds (git-fixes).
- drm/xe: remove duplicate <kunit/test-bug.h> include (git-fixes).
- fbdev: efifb: fix memory leak in efifb_probe() (git-fixes).
- fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes).
- fbdev: fix use-after-free in store_modes() (stable-fixes).
- fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes).
- git_sort: Add workqueue maintainer tree.
- git_sort: Update nf-next branch.
- gpio-f7188x: Add support for NCT6126D version B (git-fixes).
- gpio: htc-egpio: use managed gpiochip registration (git-fixes).
- gpio: mvebu: fail probe if gpiochip registration fails (git-fixes).
- gpio: timberdale: Return -ENOMEM on dynamic memory allocation in probe (git-fixes).
- gpios: palmas: add .get_direction() op (git-fixes).
- HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes).
- HID: lg-g15: cancel pending work on remove to fix a use-after-free (git-fixes).
- HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes).
- hwmon: (asus_atk0110) Check package count before accessing element (git-fixes).
- hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes).
- hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes).
- hwmon: adm1275: Prevent reading uninitialized stack (git-fixes).
- i3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue (git-fixes).
- i3c: mipi-i3c-hci: Preserve RUN bit when aborting DMA ring (git-fixes).
- iio: accel: bmc150: clamp the device-reported FIFO frame count (git-fixes).
- iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error (git-fixes).
- iio: adc: lpc32xx: Initialize completion before requesting IRQ (git-fixes).
- iio: adc: spear: Initialize completion before requesting IRQ (git-fixes).
- iio: adc: ti-ads124s08: Return reset GPIO lookup errors (git-fixes).
- iio: event: Fix event FIFO reset race (git-fixes).
- iio: imu: bmi160: add IRQF_NO_THREAD to data-ready trigger IRQ (git-fixes).
- iio: imu: st_lsm6dsx: deselect shub page before reading whoami (git-fixes).
- iio: light: al3010: fix incorrect scale for the highest gain range (git-fixes).
- iio: light: gp2ap002: fix runtime PM leak on read error (git-fixes).
- iio: light: tsl2591: return actual error from probe IRQ failure (git-fixes).
- Input: maplemouse - fix NULL pointer dereference in open() (git-fixes).
- Input: mms114 - fix multi-touch slot corruption (git-fixes).
- io_uring/kbuf: fix missing BUF_MORE for incremental buffers at EOF (bsc#1261250).
- io_uring/kbuf: propagate BUF_MORE through early buffer commit path (bsc#1261250).
- io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git-fixes bsc#1261250 bsc#1271287).
- iommu/amd: serialize sequence allocation under concurrent TLB invalidations (git-fixes).
- ipvs: Move defense_work to system_dfl_long_wq (bsc#1257605).
- ixgbe: reduce number of reads when getting OROM data (bsc#1269637).
- KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050).
- KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050).
- KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050).
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes).
- mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042 bsc#1270396).
- mm: Do not allocate shrinker info with cgroup.memory=nokmem (bsc#1256564).
- net/handshake: do not send request when the socket is closed (bsc#1251942).
- net: mana: Sync page pool RX frags for CPU (git-fixes).
- net: mana: Validate the packet length reported by the NIC (git-fixes).
- net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes).
- net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes).
- net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes).
- net: wwan: iosm: bound device offsets in the MUX downlink decoder (git-fixes).
- page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562).
- pinctrl: meson: restore non-sleeping GPIO access (git-fixes).
- ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302).
- regulator: core: regulator_lock_two() should test for EDEADLK not EDEADLOCK (git-fixes).
- s390/ap: Externalize AP bus specific bitmap reading function (jsc#PED-15897).
- s390/pkey: Check length in pkey_pckmo handler implementation (bsc#1270268).
- s390/pkey: Check length in PKEY_VERIFYPROTK ioctl (bsc#1270263).
- s390/vfio-ap: Add sysfs attr, ap_config, to export mdev state (jsc#PED-15897).
- s390/vfio-ap: Add write support to sysfs attr ap_config (jsc#PED-15897).
- s390/vfio-ap: Driver feature advertisement (jsc#PED-15897).
- s390/vfio-ap: Ignore duplicate link requests in vfio_ap_mdev_link_queue (jsc#PED-15897).
- scripts/submit_branch: do submission right after upload.
- sctp: validate embedded address parameter length (git-fixes).
- selftests/alsa: Fix memory leak in find_controls error path (git-fixes).
- selftests/bpf: Add uprobe_multi to gen_tar target (bsc#1271248).
- selftests/bpf: Make align selftests more robust (bsc#1271249).
- serial: 8250_omap: clear rx_running on zero-length DMA completes (git-fixes).
- serial: msm: Disable DMA for kernel console UART (git-fixes).
- staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop (git-fixes).
- staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop (git-fixes).
- staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl() (git-fixes).
- staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop (git-fixes).
- staging: rtl8723bs: fix OOB write in HT_caps_handler() (git-fixes).
- staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() (git-fixes).
- tools: hv: Fix cross-compilation (git-fixes).
- tpm: Make the TPM character devices non-seekable (git-fixes).
- usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() (git-fixes).
- USB: chaoskey: Fix slab-use-after-free in chaoskey_release() (git-fixes).
- usb: dwc3: meson-g12a: fix refcount leak in dwc3_meson_g12a_resume() (git-fixes).
- usb: dwc3: run gadget disconnect from sleepable suspend context (git-fixes).
- usb: free iso schedules on failed submit (git-fixes).
- usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler (git-fixes).
- usb: gadget: f_printer: take kref only for successful open (git-fixes).
- USB: idmouse: fix use-after-free on disconnect race (git-fixes).
- USB: iowarrior: fix use-after-free on disconnect (git-fixes).
- USB: ldusb: fix use-after-free on disconnect race (git-fixes).
- USB: legousbtower: fix use-after-free on disconnect race (git-fixes).
- USB: misc: uss720: unregister parport on probe failure (git-fixes).
- usb: mtu3: unmap request DMA on queue failure (git-fixes).
- USB: serial: digi_acceleport: fix broken rx after throttle (git-fixes).
- USB: serial: digi_acceleport: fix hard lockup on disconnect (git-fixes).
- USB: serial: digi_acceleport: fix write buffer corruption (git-fixes).
- USB: serial: keyspan_pda: fix information leak (git-fixes).
- usb: sl811-hcd: disable controller wakeup on remove (git-fixes).
- USB: storage: include US_FL_NO_SAME in quirks mask (git-fixes).
- usb: typec: anx7411: use devm_pm_runtime_enable() (git-fixes).
- usb: typec: class: drop PD lookup reference (git-fixes).
- usb: typec: tcpm: Fix VDM type for Enter Mode commands (git-fixes).
- usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (git-fixes).
- usb: typec: ucsi: cancel pending work on system suspend (git-fixes).
- usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove (git-fixes).
- usb: typec: ucsi: Invert DisplayPort role assignment (git-fixes).
- usb: typec: ucsi: Pass full DP config payload in SET_NEW_CAM for DP alt mode (git-fixes).
- USB: ulpi: fix memory leak on registration failure (git-fixes).
- USB: usb-storage: ene_ub6250: restore media-ready check (git-fixes).
- usb: xhci: Fix sleep in atomic context in xhci_free_streams() (git-fixes).
- usbip: tools: support SuperSpeedPlus devices (git-fixes).
- usbip: vudc: fix NULL deref in vep_dequeue() (git-fixes).
- usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes).
- wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes).
- wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes).
- wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes).


The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.12.10-150700.4.14.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- kernel-macros-6.4.0-150700.53.73.1 updated
- libatomic1-15.3.0+git11272-150000.1.12.1 updated
- libgomp1-15.3.0+git11272-150000.1.12.1 updated
- libitm1-15.3.0+git11272-150000.1.12.1 updated
- liblsan0-15.3.0+git11272-150000.1.12.1 updated
- patch-2.7.6-150000.5.12.1 updated
- kernel-devel-6.4.0-150700.53.73.1 updated
- kmod-29-150600.13.6.1 updated
- kernel-default-devel-6.4.0-150700.53.73.2 updated
- kernel-syms-6.4.0-150700.53.73.1 updated
- container:registry.suse.com-bci-bci-base-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated


More information about the sle-container-updates mailing list