ESSA-2026:0165: Moderate: SUSE Liberty Linux 9 Important: kernel security, bug fix, and enhancement update

Update Advisories for SUSE Liberty Linux suse-liberty-linux-updates at lists.suse.com
Tue Sep 15 15:07:51 UTC 2026


# Important: kernel security, bug fix, and enhancement update

Announcement ID: ESSA-2026:0165
Rating: Moderate

Cross-References:

  * CVE-2025-68183
  * CVE-2026-31408
  * CVE-2026-43074
  * CVE-2026-43279
  * CVE-2026-45984
  * CVE-2026-46135
  * CVE-2026-46152
  * CVE-2026-46189
  * CVE-2026-46316



CVSS scores:

  * CVE-2025-68183 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
  * CVE-2025-68183 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-31408 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-31408 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-46135 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  * CVE-2026-46135 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-46152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-46189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-46316 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products:

  * SUSE Liberty Linux 9


An update that solves 9 vulnerabilities can now be installed.

## Description:

The kernel packages contain the Linux kernel, the core of any Linux operating system.
  Security Fix(es): kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183) 
 kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408) 
 kernel: eventpoll: defer struct eventpoll free to RCU grace period (CVE-2026-43074) 
 kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279) 
 kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984) 
 kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152) 
 kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189) 
 kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135) 
 kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242) 
 kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316) 
 kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359) 
Bug Fix(es) and Enhancement(s): Possible THP Stalls on Multi-NUMA Systems for HANA on RHEL [rhel-9.6.z] (JIRA:RHEL-164774) 
 crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS mode [rhel-9.6.z] (JIRA:RHEL-182539) 
 

## Package List:

  * SUSE Liberty Linux 9:
    * kernel 5.14.0-570.129.2.el9_6
    * kernel-abi-stablelists 5.14.0-570.129.2.el9_6
    * kernel-core 5.14.0-570.129.2.el9_6
    * kernel-cross-headers 5.14.0-570.129.2.el9_6
    * kernel-debug 5.14.0-570.129.2.el9_6
    * kernel-debug-core 5.14.0-570.129.2.el9_6
    * kernel-debug-devel 5.14.0-570.129.2.el9_6
    * kernel-debug-devel-matched 5.14.0-570.129.2.el9_6
    * kernel-debug-modules 5.14.0-570.129.2.el9_6
    * kernel-debug-modules-core 5.14.0-570.129.2.el9_6
    * kernel-debug-modules-extra 5.14.0-570.129.2.el9_6
    * kernel-debug-uki-virt 5.14.0-570.129.2.el9_6
    * kernel-devel 5.14.0-570.129.2.el9_6
    * kernel-devel-matched 5.14.0-570.129.2.el9_6
    * kernel-doc 5.14.0-570.129.2.el9_6
    * kernel-headers 5.14.0-570.129.2.el9_6
    * kernel-modules 5.14.0-570.129.2.el9_6
    * kernel-modules-core 5.14.0-570.129.2.el9_6
    * kernel-modules-extra 5.14.0-570.129.2.el9_6
    * kernel-rt 5.14.0-570.129.2.el9_6
    * kernel-rt-core 5.14.0-570.129.2.el9_6
    * kernel-rt-debug 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-core 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-devel 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-kvm 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-modules 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-modules-core 5.14.0-570.129.2.el9_6
    * kernel-rt-debug-modules-extra 5.14.0-570.129.2.el9_6
    * kernel-rt-devel 5.14.0-570.129.2.el9_6
    * kernel-rt-kvm 5.14.0-570.129.2.el9_6
    * kernel-rt-modules 5.14.0-570.129.2.el9_6
    * kernel-rt-modules-core 5.14.0-570.129.2.el9_6
    * kernel-rt-modules-extra 5.14.0-570.129.2.el9_6
    * kernel-tools 5.14.0-570.129.2.el9_6
    * kernel-tools-libs 5.14.0-570.129.2.el9_6
    * kernel-tools-libs-devel 5.14.0-570.129.2.el9_6
    * kernel-uki-virt 5.14.0-570.129.2.el9_6
    * kernel-uki-virt-addons 5.14.0-570.129.2.el9_6
    * libperf 5.14.0-570.129.2.el9_6
    * perf 5.14.0-570.129.2.el9_6
    * python3-perf 5.14.0-570.129.2.el9_6
    * rtla 5.14.0-570.129.2.el9_6
    * rv 5.14.0-570.129.2.el9_6

## References:

  * https://www.suse.com/security/cve/CVE-2025-68183.html
  * https://www.suse.com/security/cve/CVE-2026-31408.html
  * https://www.suse.com/security/cve/CVE-2026-43074.html
  * https://www.suse.com/security/cve/CVE-2026-43279.html
  * https://www.suse.com/security/cve/CVE-2026-45984.html
  * https://www.suse.com/security/cve/CVE-2026-46135.html
  * https://www.suse.com/security/cve/CVE-2026-46152.html
  * https://www.suse.com/security/cve/CVE-2026-46189.html
  * https://www.suse.com/security/cve/CVE-2026-46316.html


More information about the suse-liberty-linux-updates mailing list