ESSA-2026:0165: Moderate: SUSE Liberty Linux 9 Important: kernel security, bug fix, and enhancement update
Update Advisories for SUSE Liberty Linux
suse-liberty-linux-updates at lists.suse.com
Tue Sep 15 15:07:51 UTC 2026
# Important: kernel security, bug fix, and enhancement update
Announcement ID: ESSA-2026:0165
Rating: Moderate
Cross-References:
* CVE-2025-68183
* CVE-2026-31408
* CVE-2026-43074
* CVE-2026-43279
* CVE-2026-45984
* CVE-2026-46135
* CVE-2026-46152
* CVE-2026-46189
* CVE-2026-46316
CVSS scores:
* CVE-2025-68183 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
* CVE-2025-68183 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-31408 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-31408 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46135 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-46135 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-46152 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2026-46316 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products:
* SUSE Liberty Linux 9
An update that solves 9 vulnerabilities can now be installed.
## Description:
The kernel packages contain the Linux kernel, the core of any Linux operating system.
Security Fix(es): kernel: ima: don't clear IMA_DIGSIG flag when setting or removing non-IMA xattr (CVE-2025-68183)
kernel: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (CVE-2026-31408)
kernel: eventpoll: defer struct eventpoll free to RCU grace period (CVE-2026-43074)
kernel: ALSA: usb-audio: Add sanity check for OOB writes at silencing (CVE-2026-43279)
kernel: gfs2: Fix use-after-free in iomap inline data write path (CVE-2026-45984)
kernel: wifi: mac80211: drop stray 'static' from fast-RX rx_result (CVE-2026-46152)
kernel: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (CVE-2026-46189)
kernel: nvmet-tcp: fix race between ICReq handling and queue teardown (CVE-2026-46135)
kernel: eventpoll: fix ep_remove struct eventpoll / struct file UAF (CVE-2026-46242)
kernel: KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry (CVE-2026-46316)
kernel: KVM: x86: Fix shadow paging use-after-free due to unexpected role (CVE-2026-53359)
Bug Fix(es) and Enhancement(s): Possible THP Stalls on Multi-NUMA Systems for HANA on RHEL [rhel-9.6.z] (JIRA:RHEL-164774)
crypto: testmgr - allow authenc(hmac(sha{256,384}),cts(cbc(aes))) in FIPS mode [rhel-9.6.z] (JIRA:RHEL-182539)
## Package List:
* SUSE Liberty Linux 9:
* kernel 5.14.0-570.129.2.el9_6
* kernel-abi-stablelists 5.14.0-570.129.2.el9_6
* kernel-core 5.14.0-570.129.2.el9_6
* kernel-cross-headers 5.14.0-570.129.2.el9_6
* kernel-debug 5.14.0-570.129.2.el9_6
* kernel-debug-core 5.14.0-570.129.2.el9_6
* kernel-debug-devel 5.14.0-570.129.2.el9_6
* kernel-debug-devel-matched 5.14.0-570.129.2.el9_6
* kernel-debug-modules 5.14.0-570.129.2.el9_6
* kernel-debug-modules-core 5.14.0-570.129.2.el9_6
* kernel-debug-modules-extra 5.14.0-570.129.2.el9_6
* kernel-debug-uki-virt 5.14.0-570.129.2.el9_6
* kernel-devel 5.14.0-570.129.2.el9_6
* kernel-devel-matched 5.14.0-570.129.2.el9_6
* kernel-doc 5.14.0-570.129.2.el9_6
* kernel-headers 5.14.0-570.129.2.el9_6
* kernel-modules 5.14.0-570.129.2.el9_6
* kernel-modules-core 5.14.0-570.129.2.el9_6
* kernel-modules-extra 5.14.0-570.129.2.el9_6
* kernel-rt 5.14.0-570.129.2.el9_6
* kernel-rt-core 5.14.0-570.129.2.el9_6
* kernel-rt-debug 5.14.0-570.129.2.el9_6
* kernel-rt-debug-core 5.14.0-570.129.2.el9_6
* kernel-rt-debug-devel 5.14.0-570.129.2.el9_6
* kernel-rt-debug-kvm 5.14.0-570.129.2.el9_6
* kernel-rt-debug-modules 5.14.0-570.129.2.el9_6
* kernel-rt-debug-modules-core 5.14.0-570.129.2.el9_6
* kernel-rt-debug-modules-extra 5.14.0-570.129.2.el9_6
* kernel-rt-devel 5.14.0-570.129.2.el9_6
* kernel-rt-kvm 5.14.0-570.129.2.el9_6
* kernel-rt-modules 5.14.0-570.129.2.el9_6
* kernel-rt-modules-core 5.14.0-570.129.2.el9_6
* kernel-rt-modules-extra 5.14.0-570.129.2.el9_6
* kernel-tools 5.14.0-570.129.2.el9_6
* kernel-tools-libs 5.14.0-570.129.2.el9_6
* kernel-tools-libs-devel 5.14.0-570.129.2.el9_6
* kernel-uki-virt 5.14.0-570.129.2.el9_6
* kernel-uki-virt-addons 5.14.0-570.129.2.el9_6
* libperf 5.14.0-570.129.2.el9_6
* perf 5.14.0-570.129.2.el9_6
* python3-perf 5.14.0-570.129.2.el9_6
* rtla 5.14.0-570.129.2.el9_6
* rv 5.14.0-570.129.2.el9_6
## References:
* https://www.suse.com/security/cve/CVE-2025-68183.html
* https://www.suse.com/security/cve/CVE-2026-31408.html
* https://www.suse.com/security/cve/CVE-2026-43074.html
* https://www.suse.com/security/cve/CVE-2026-43279.html
* https://www.suse.com/security/cve/CVE-2026-45984.html
* https://www.suse.com/security/cve/CVE-2026-46135.html
* https://www.suse.com/security/cve/CVE-2026-46152.html
* https://www.suse.com/security/cve/CVE-2026-46189.html
* https://www.suse.com/security/cve/CVE-2026-46316.html
More information about the suse-liberty-linux-updates
mailing list