SUSE-IU-2026:7394-1: Security update of suse/sle-micro/rt-5.5
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Sep 25 07:09:22 UTC 2026
SUSE Image Update Advisory: suse/sle-micro/rt-5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:7394-1
Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.730 , suse/sle-micro/rt-5.5:latest
Image Release : 4.5.730
Severity : important
Type : security
References : 1235944 1261604 1263072 1264734 1267023 1268659 1269000 1269004
1269238 1269242 1269306 1269655 1269731 1269792 1271825 1271830
1272179 1272182 1272230 1272385 1272390 1272756 1272868 1272877
1273060 1273105 1273276 1273303 1273311 1273422 1273484 1273488
1273523 1273555 1273742 1273745 1273748 1273762 1273774 1273869
1273882 1273891 1273930 1273944 1273966 1273995 1274014 1274031
1274041 1274208 1274274 1274497 1274547 1274550 1274696 1274705
1274752 1274753 1274754 1274859 1274888 1274898 1274902 1274908
1274941 1275161 1275472 1275474 1275506 1275528 1275687 1275782
1275798 1275827 1275867 1275886 1275905 1276350 1276665 1276931
1277073 1277155 1277285 1277391 1277408 1277523 1277571 1277678
1277860 1278088 1278233 1278236 1279554 1279813 CVE-2024-57841
CVE-2026-23451 CVE-2026-31502 CVE-2026-43456 CVE-2026-45968 CVE-2026-52910
CVE-2026-52912 CVE-2026-52929 CVE-2026-52977 CVE-2026-53059 CVE-2026-53163
CVE-2026-53260 CVE-2026-53264 CVE-2026-53381 CVE-2026-53388 CVE-2026-63801
CVE-2026-63823 CVE-2026-63827 CVE-2026-63887 CVE-2026-63888 CVE-2026-63920
CVE-2026-63992 CVE-2026-64002 CVE-2026-64007 CVE-2026-64010 CVE-2026-64011
CVE-2026-64015 CVE-2026-64047 CVE-2026-64048 CVE-2026-64098 CVE-2026-64109
CVE-2026-64114 CVE-2026-64115 CVE-2026-64137 CVE-2026-64266 CVE-2026-64268
CVE-2026-64304 CVE-2026-64355 CVE-2026-64423 CVE-2026-64450 CVE-2026-64481
CVE-2026-64541 CVE-2026-64543 CVE-2026-64562 CVE-2026-64563 CVE-2026-64572
CVE-2026-64577 CVE-2026-64581 CVE-2026-64593 CVE-2026-68121 CVE-2026-68136
CVE-2026-68138 CVE-2026-68160 CVE-2026-68202 CVE-2026-68397 CVE-2026-68398
CVE-2026-68417 CVE-2026-68426 CVE-2026-68480 CVE-2026-72020 CVE-2026-72069
CVE-2026-72072 CVE-2026-72123 CVE-2026-72135 CVE-2026-72251 CVE-2026-72262
CVE-2026-72288 CVE-2026-72289 CVE-2026-72389 CVE-2026-74345 CVE-2026-74377
CVE-2026-74378 CVE-2026-74390 CVE-2026-74394 CVE-2026-74454 CVE-2026-74488
CVE-2026-74496 CVE-2026-74518 CVE-2026-74537 CVE-2026-74581 CVE-2026-74582
CVE-2026-74669 CVE-2026-74695 CVE-2026-80722
-----------------------------------------------------------------
The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4347-1
Released: Thu Sep 24 16:36:19 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1235944,1261604,1263072,1264734,1267023,1268659,1269000,1269004,1269238,1269242,1269306,1269655,1269731,1269792,1271825,1271830,1272179,1272182,1272230,1272385,1272390,1272756,1272868,1272877,1273060,1273105,1273276,1273303,1273311,1273422,1273484,1273488,1273523,1273555,1273742,1273745,1273748,1273762,1273774,1273869,1273882,1273891,1273930,1273944,1273966,1273995,1274014,1274031,1274041,1274208,1274274,1274497,1274547,1274550,1274696,1274705,1274752,1274753,1274754,1274859,1274888,1274898,1274902,1274908,1274941,1275161,1275472,1275474,1275506,1275528,1275687,1275782,1275798,1275827,1275867,1275886,1275905,1276350,1276665,1276931,1277073,1277155,1277285,1277391,1277408,1277523,1277571,1277678,1277860,1278088,1278233,1278236,1279554,1279813,CVE-2024-57841,CVE-2026-23451,CVE-2026-31502,CVE-2026-43456,CVE-2026-45968,CVE-2026-52910,CVE-2026-52912,CVE-2026-52929,CVE-2026-52977,CVE-2026-53059,CVE-2026-53163,CVE-2026-53260,CVE-2026-53264,CVE-2026-53381,CVE-2026-53388,CVE-2026
-63801,CVE-2026-63823,CVE-2026-63827,CVE-2026-63887,CVE-2026-63888,CVE-2026-63920,CVE-2026-63992,CVE-2026-64002,CVE-2026-64007,CVE-2026-64010,CVE-2026-64011,CVE-2026-64015,CVE-2026-64047,CVE-2026-64048,CVE-2026-64098,CVE-2026-64109,CVE-2026-64114,CVE-2026-64115,CVE-2026-64137,CVE-2026-64266,CVE-2026-64268,CVE-2026-64304,CVE-2026-64355,CVE-2026-64423,CVE-2026-64450,CVE-2026-64481,CVE-2026-64541,CVE-2026-64543,CVE-2026-64562,CVE-2026-64563,CVE-2026-64572,CVE-2026-64577,CVE-2026-64581,CVE-2026-64593,CVE-2026-68121,CVE-2026-68136,CVE-2026-68138,CVE-2026-68160,CVE-2026-68202,CVE-2026-68397,CVE-2026-68398,CVE-2026-68417,CVE-2026-68426,CVE-2026-68480,CVE-2026-72020,CVE-2026-72069,CVE-2026-72072,CVE-2026-72123,CVE-2026-72135,CVE-2026-72251,CVE-2026-72262,CVE-2026-72288,CVE-2026-72289,CVE-2026-72389,CVE-2026-74345,CVE-2026-74377,CVE-2026-74378,CVE-2026-74390,CVE-2026-74394,CVE-2026-74454,CVE-2026-74488,CVE-2026-74496,CVE-2026-74518,CVE-2026-74537,CVE-2026-74581,CVE-2026-74582,CVE-2026-74669,
CVE-2026-74695,CVE-2026-80722
The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues:
The following security issues were fixed:
- CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731).
- CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).
- CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
- CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).
- CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023).
- CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
- CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).
- CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004).
- CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242).
- CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).
- CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
- CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).
- CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830).
- CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230).
- CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182).
- CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179).
- CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).
- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).
- CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868).
- CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).
- CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).
- CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).
- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).
- CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).
- CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060).
- CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484).
- CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488).
- CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).
- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).
- CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).
- CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276).
- CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).
- CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422).
- CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).
- CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523).
- CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547).
- CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).
- CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311).
- CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).
- CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995).
- CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014).
- CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031).
- CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).
- CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497).
- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
- CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474).
- CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941).
- CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472).
- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
- CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).
- CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).
- CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696).
- CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705).
- CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).
- CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).
- CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528).
- CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155).
- CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523).
- CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).
- CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).
- CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678).
- CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886).
- CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905).
- CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
- CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285).
- CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).
- CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).
- CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088).
- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408).
- CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).
- CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).
- CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).
- CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798).
- CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).
- CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782).
- CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784).
- CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).
- CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931).
- CVE-2026-80722: wifi: mac80211: validate individual TWT params before driver setup (bsc#1277860).
The following non security issues were fixed:
- mkspec-dtb: Move DTS prefix into package list.
- mkspec-dtb: Move provides-obsoletes to package list.
- mkspec-dtb: Put per-architecture package lists into a hash.
- mkspec-dtb: re-indent.
- net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes).
- net: mana: Add handler for sriov configure (bsc#1272756).
- net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792).
- net: mana: Route ring-buffer access through offset-based helpers (git-fixes).
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).
- PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes).
- powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752
ltc#221290).
- RDMA/mana_ib: drain QP references after partial table insertion (git-fixes).
- RDMA/mana_ib: unify QP lookup table (git-fixes).
- RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes).
- RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes).
- RDMA/siw: Introduce siw_free_cm_id (git-fixes).
- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes).
- scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes).
- smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).
- smb: client: require net admin for CIFS SWN netlink (bsc#1273966).
The following package changes have been done:
- kernel-rt-5.14.21-150500.13.161.1 updated
More information about the sle-container-updates
mailing list