ESSA-2026:0155: Moderate: SUSE Liberty Linux 9 Important: kernel security, bug fix, and enhancement update
Update Advisories for SUSE Liberty Linux
suse-liberty-linux-updates at lists.suse.com
Fri Aug 28 15:07:40 UTC 2026
# Important: kernel security, bug fix, and enhancement update
Announcement ID: ESSA-2026:0155
Rating: Moderate
Cross-References:
* CVE-2025-40064
* CVE-2026-23136
* CVE-2026-43116
* CVE-2026-43158
* CVE-2026-43303
* CVE-2026-45898
* CVE-2026-46125
* CVE-2026-46166
* CVE-2026-46243
* CVE-2026-46323
* CVE-2026-46331
CVSS scores:
* CVE-2025-40064 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-23136 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-23136 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
* CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45898 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-45898 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46323 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* SUSE Liberty Linux 9
An update that solves 11 vulnerabilities can now be installed.
## Description:
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: smc: Fix use-after-free in __pnet_find_base_ndev() (CVE-2025-40064)
kernel: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (CVE-2025-40168)
kernel: Linux kernel: Denial of Service in libceph OSD client due to unreset sparse-read state (CVE-2026-23136)
kernel: netfilter: ctnetlink: ensure safe access to master conntrack (CVE-2026-43116)
kernel: xfs: fix freemap adjustments when adding xattrs to leaf blocks (CVE-2026-43158)
kernel: mm/page_alloc: clear page->private in free_pages_prepare() (CVE-2026-43303)
kernel: net/sched: act_pedit: extend the writable skb range per key (CVE-2026-46331)
kernel: Linux kernel: Use-After-Free in net/gro due to improper handling of zerocopy skbs (CVE-2026-46323)
kernel: Linux kernel: smb: client: reject userspace cifs.spnego descriptions (CVE-2026-46243)
kernel: RDMA/iwcm: Fix workqueue list corruption by removing work_list (CVE-2026-45898)
kernel: wifi: mac80211: remove station if connection prep fails (CVE-2026-46125)
kernel: wifi: mac80211: use safe list iteration in radar detect work (CVE-2026-46166)
Bug Fix(es) and Enhancement(s): [RHEL-9] Performance impact of CVE-2025-38085 [rhel-9.6.z] (JIRA:RHEL-161145)
libceph: CEPH_CRYPTO_AES256KRB5 (--key-type aes256k) support [rhel-9.6.z] (JIRA:RHEL-168926)
[ice] 3 of 4 ports "Failed to set LAN Tx queue context, error: -22" [rhel-9.6.z] (JIRA:RHEL-175439)
Kernel panic while shutting down ice driver due to use-after-free [rhel-9.6.z] (JIRA:RHEL-177524)
rbd: eliminate a race in lock_dwork draining on unmap [rhel-9.6.z] (JIRA:RHEL-183129)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
## Package List:
* SUSE Liberty Linux 9:
* kernel 5.14.0-570.128.2.el9_6
* kernel-abi-stablelists 5.14.0-570.128.2.el9_6
* kernel-core 5.14.0-570.128.2.el9_6
* kernel-debug 5.14.0-570.128.2.el9_6
* kernel-debug-core 5.14.0-570.128.2.el9_6
* kernel-debug-devel 5.14.0-570.128.2.el9_6
* kernel-debug-devel-matched 5.14.0-570.128.2.el9_6
* kernel-debug-modules 5.14.0-570.128.2.el9_6
* kernel-debug-modules-core 5.14.0-570.128.2.el9_6
* kernel-debug-modules-extra 5.14.0-570.128.2.el9_6
* kernel-debug-uki-virt 5.14.0-570.128.2.el9_6
* kernel-devel 5.14.0-570.128.2.el9_6
* kernel-devel-matched 5.14.0-570.128.2.el9_6
* kernel-doc 5.14.0-570.128.2.el9_6
* kernel-headers 5.14.0-570.128.2.el9_6
* kernel-modules 5.14.0-570.128.2.el9_6
* kernel-modules-core 5.14.0-570.128.2.el9_6
* kernel-modules-extra 5.14.0-570.128.2.el9_6
* kernel-rt 5.14.0-570.128.2.el9_6
* kernel-rt-core 5.14.0-570.128.2.el9_6
* kernel-rt-debug 5.14.0-570.128.2.el9_6
* kernel-rt-debug-core 5.14.0-570.128.2.el9_6
* kernel-rt-debug-devel 5.14.0-570.128.2.el9_6
* kernel-rt-debug-kvm 5.14.0-570.128.2.el9_6
* kernel-rt-debug-modules 5.14.0-570.128.2.el9_6
* kernel-rt-debug-modules-core 5.14.0-570.128.2.el9_6
* kernel-rt-debug-modules-extra 5.14.0-570.128.2.el9_6
* kernel-rt-devel 5.14.0-570.128.2.el9_6
* kernel-rt-kvm 5.14.0-570.128.2.el9_6
* kernel-rt-modules 5.14.0-570.128.2.el9_6
* kernel-rt-modules-core 5.14.0-570.128.2.el9_6
* kernel-rt-modules-extra 5.14.0-570.128.2.el9_6
* kernel-tools 5.14.0-570.128.2.el9_6
* kernel-tools-libs 5.14.0-570.128.2.el9_6
* kernel-uki-virt 5.14.0-570.128.2.el9_6
* kernel-uki-virt-addons 5.14.0-570.128.2.el9_6
* perf 5.14.0-570.128.2.el9_6
* python3-perf 5.14.0-570.128.2.el9_6
* rtla 5.14.0-570.128.2.el9_6
* rv 5.14.0-570.128.2.el9_6
## References:
* https://www.suse.com/security/cve/CVE-2025-40064.html
* https://www.suse.com/security/cve/CVE-2026-23136.html
* https://www.suse.com/security/cve/CVE-2026-43116.html
* https://www.suse.com/security/cve/CVE-2026-43158.html
* https://www.suse.com/security/cve/CVE-2026-43303.html
* https://www.suse.com/security/cve/CVE-2026-45898.html
* https://www.suse.com/security/cve/CVE-2026-46125.html
* https://www.suse.com/security/cve/CVE-2026-46166.html
* https://www.suse.com/security/cve/CVE-2026-46243.html
* https://www.suse.com/security/cve/CVE-2026-46323.html
* https://www.suse.com/security/cve/CVE-2026-46331.html
More information about the suse-liberty-linux-updates
mailing list