{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "Security update for the Linux Kernel",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "\nThe SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues:\n\nThe following security issues were fixed:\n\n- CVE-2023-53109: net: tunnels: annotate lockless accesses to dev->needed_headroom (bsc#1242405 bsc#1275784).\n- CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944).\n- CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731).\n- CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).\n- CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).\n- CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).\n- CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008).\n- CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023).\n- CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).\n- CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).\n- CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004).\n- CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242).\n- CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).\n- CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).\n- CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).\n- CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830).\n- CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230).\n- CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182).\n- CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179).\n- CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).\n- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).\n- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).\n- CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868).\n- CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).\n- CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).\n- CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).\n- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).\n- CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).\n- CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060).\n- CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484).\n- CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488).\n- CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).\n- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).\n- CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).\n- CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276).\n- CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).\n- CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422).\n- CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).\n- CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523).\n- CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547).\n- CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).\n- CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311).\n- CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251).\n- CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).\n- CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995).\n- CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014).\n- CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).\n- CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497).\n- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).\n- CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474).\n- CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941).\n- CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304).\n- CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307).\n- CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470).\n- CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472).\n- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).\n- CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).\n- CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).\n- CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696).\n- CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705).\n- CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).\n- CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).\n- CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528).\n- CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535).\n- CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540).\n- CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523).\n- CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).\n- CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553).\n- CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).\n- CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886).\n- CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905).\n- CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985).\n- CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006).\n- CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).\n- CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285).\n- CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).\n- CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).\n- CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253).\n- CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088).\n- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408).\n- CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395).\n- CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).\n- CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).\n- CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).\n- CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798).\n- CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).\n- CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696).\n- CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784).\n- CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901).\n- CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813).\n- CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).\n- CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931).\n- CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908).\n- CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294).\n- CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561).\n- CVE-2026-80716: ALSA: pcm: wake linked drain waiters on unlink (bsc#1277837).\n- CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487).\n- CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422).\n\nThe following non security issues were fixed:\n\n- mkspec-dtb: Move DTS prefix into package list.\n- mkspec-dtb: Move provides-obsoletes to package list.\n- mkspec-dtb: Put per-architecture package lists into a hash.\n- mkspec-dtb: re-indent.\n- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).\n- perf: Reject exited events as group leaders (git-fixes).\n- powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752\n  ltc#221290).\n- RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes).\n- RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes).\n- RDMA/siw: Introduce siw_free_cm_id (git-fixes).\n- RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes).\n- smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).\n- smb: client: require net admin for CIFS SWN netlink (bsc#1273966).\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "SUSE-2026-4279,SUSE-SLE-Micro-5.3-2026-4279,SUSE-SLE-Micro-5.4-2026-4279",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2026_4279-1.json"
      },
      {
        "category": "self",
        "summary": "URL for SUSE-SU-2026:4279-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264279-1/"
      },
      {
        "category": "self",
        "summary": "E-Mail link for SUSE-SU-2026:4279-1",
        "url": "https://www.suse.com/support/update/announcement/2026/suse-su-20264279-1/"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1235944",
        "url": "https://bugzilla.suse.com/1235944"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1242405",
        "url": "https://bugzilla.suse.com/1242405"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1261604",
        "url": "https://bugzilla.suse.com/1261604"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1263072",
        "url": "https://bugzilla.suse.com/1263072"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1264734",
        "url": "https://bugzilla.suse.com/1264734"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1266008",
        "url": "https://bugzilla.suse.com/1266008"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1267023",
        "url": "https://bugzilla.suse.com/1267023"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1268659",
        "url": "https://bugzilla.suse.com/1268659"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269000",
        "url": "https://bugzilla.suse.com/1269000"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269004",
        "url": "https://bugzilla.suse.com/1269004"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269238",
        "url": "https://bugzilla.suse.com/1269238"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269242",
        "url": "https://bugzilla.suse.com/1269242"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269306",
        "url": "https://bugzilla.suse.com/1269306"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269655",
        "url": "https://bugzilla.suse.com/1269655"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1269731",
        "url": "https://bugzilla.suse.com/1269731"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271825",
        "url": "https://bugzilla.suse.com/1271825"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1271830",
        "url": "https://bugzilla.suse.com/1271830"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272179",
        "url": "https://bugzilla.suse.com/1272179"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272182",
        "url": "https://bugzilla.suse.com/1272182"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272230",
        "url": "https://bugzilla.suse.com/1272230"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272385",
        "url": "https://bugzilla.suse.com/1272385"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272390",
        "url": "https://bugzilla.suse.com/1272390"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272868",
        "url": "https://bugzilla.suse.com/1272868"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1272877",
        "url": "https://bugzilla.suse.com/1272877"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273060",
        "url": "https://bugzilla.suse.com/1273060"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273105",
        "url": "https://bugzilla.suse.com/1273105"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273251",
        "url": "https://bugzilla.suse.com/1273251"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273276",
        "url": "https://bugzilla.suse.com/1273276"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273303",
        "url": "https://bugzilla.suse.com/1273303"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273311",
        "url": "https://bugzilla.suse.com/1273311"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273422",
        "url": "https://bugzilla.suse.com/1273422"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273484",
        "url": "https://bugzilla.suse.com/1273484"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273488",
        "url": "https://bugzilla.suse.com/1273488"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273523",
        "url": "https://bugzilla.suse.com/1273523"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273555",
        "url": "https://bugzilla.suse.com/1273555"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273742",
        "url": "https://bugzilla.suse.com/1273742"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273745",
        "url": "https://bugzilla.suse.com/1273745"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273748",
        "url": "https://bugzilla.suse.com/1273748"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273762",
        "url": "https://bugzilla.suse.com/1273762"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273774",
        "url": "https://bugzilla.suse.com/1273774"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273869",
        "url": "https://bugzilla.suse.com/1273869"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273882",
        "url": "https://bugzilla.suse.com/1273882"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273891",
        "url": "https://bugzilla.suse.com/1273891"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273930",
        "url": "https://bugzilla.suse.com/1273930"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273944",
        "url": "https://bugzilla.suse.com/1273944"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273966",
        "url": "https://bugzilla.suse.com/1273966"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1273995",
        "url": "https://bugzilla.suse.com/1273995"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274014",
        "url": "https://bugzilla.suse.com/1274014"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274041",
        "url": "https://bugzilla.suse.com/1274041"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274208",
        "url": "https://bugzilla.suse.com/1274208"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274274",
        "url": "https://bugzilla.suse.com/1274274"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274497",
        "url": "https://bugzilla.suse.com/1274497"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274547",
        "url": "https://bugzilla.suse.com/1274547"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274550",
        "url": "https://bugzilla.suse.com/1274550"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274696",
        "url": "https://bugzilla.suse.com/1274696"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274705",
        "url": "https://bugzilla.suse.com/1274705"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274752",
        "url": "https://bugzilla.suse.com/1274752"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274753",
        "url": "https://bugzilla.suse.com/1274753"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274754",
        "url": "https://bugzilla.suse.com/1274754"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274859",
        "url": "https://bugzilla.suse.com/1274859"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274888",
        "url": "https://bugzilla.suse.com/1274888"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274898",
        "url": "https://bugzilla.suse.com/1274898"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274902",
        "url": "https://bugzilla.suse.com/1274902"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274908",
        "url": "https://bugzilla.suse.com/1274908"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1274941",
        "url": "https://bugzilla.suse.com/1274941"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275161",
        "url": "https://bugzilla.suse.com/1275161"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275304",
        "url": "https://bugzilla.suse.com/1275304"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275307",
        "url": "https://bugzilla.suse.com/1275307"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275470",
        "url": "https://bugzilla.suse.com/1275470"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275472",
        "url": "https://bugzilla.suse.com/1275472"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275474",
        "url": "https://bugzilla.suse.com/1275474"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275506",
        "url": "https://bugzilla.suse.com/1275506"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275528",
        "url": "https://bugzilla.suse.com/1275528"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275535",
        "url": "https://bugzilla.suse.com/1275535"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275540",
        "url": "https://bugzilla.suse.com/1275540"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275687",
        "url": "https://bugzilla.suse.com/1275687"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275696",
        "url": "https://bugzilla.suse.com/1275696"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275784",
        "url": "https://bugzilla.suse.com/1275784"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275798",
        "url": "https://bugzilla.suse.com/1275798"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275827",
        "url": "https://bugzilla.suse.com/1275827"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275867",
        "url": "https://bugzilla.suse.com/1275867"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275886",
        "url": "https://bugzilla.suse.com/1275886"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275905",
        "url": "https://bugzilla.suse.com/1275905"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1275985",
        "url": "https://bugzilla.suse.com/1275985"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276006",
        "url": "https://bugzilla.suse.com/1276006"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276350",
        "url": "https://bugzilla.suse.com/1276350"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276395",
        "url": "https://bugzilla.suse.com/1276395"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276665",
        "url": "https://bugzilla.suse.com/1276665"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1276931",
        "url": "https://bugzilla.suse.com/1276931"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277073",
        "url": "https://bugzilla.suse.com/1277073"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277285",
        "url": "https://bugzilla.suse.com/1277285"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277391",
        "url": "https://bugzilla.suse.com/1277391"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277408",
        "url": "https://bugzilla.suse.com/1277408"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277523",
        "url": "https://bugzilla.suse.com/1277523"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277553",
        "url": "https://bugzilla.suse.com/1277553"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277561",
        "url": "https://bugzilla.suse.com/1277561"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277571",
        "url": "https://bugzilla.suse.com/1277571"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277813",
        "url": "https://bugzilla.suse.com/1277813"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277837",
        "url": "https://bugzilla.suse.com/1277837"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277901",
        "url": "https://bugzilla.suse.com/1277901"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1277908",
        "url": "https://bugzilla.suse.com/1277908"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278088",
        "url": "https://bugzilla.suse.com/1278088"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278233",
        "url": "https://bugzilla.suse.com/1278233"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278236",
        "url": "https://bugzilla.suse.com/1278236"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278253",
        "url": "https://bugzilla.suse.com/1278253"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1278294",
        "url": "https://bugzilla.suse.com/1278294"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1279422",
        "url": "https://bugzilla.suse.com/1279422"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1279487",
        "url": "https://bugzilla.suse.com/1279487"
      },
      {
        "category": "self",
        "summary": "SUSE Bug 1279813",
        "url": "https://bugzilla.suse.com/1279813"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2023-53109 page",
        "url": "https://www.suse.com/security/cve/CVE-2023-53109/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2024-57841 page",
        "url": "https://www.suse.com/security/cve/CVE-2024-57841/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-23451 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-23451/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-31502 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-31502/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-43456 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-43456/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-43502 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-43502/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-45968 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-45968/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-52910 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-52910/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-52912 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-52912/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-52929 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-52929/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-52977 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-52977/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53059 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53059/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53163 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53163/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53260 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53260/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53264 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53264/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53381 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53381/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-53388 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-53388/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63801 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63801/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63823 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63823/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63827 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63827/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63887 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63887/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63888 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63888/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63920 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63920/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-63992 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-63992/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64002 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64002/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64007 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64007/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64010 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64010/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64011 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64011/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64015 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64015/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64047 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64047/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64048 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64048/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64098 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64098/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64109 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64109/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64114 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64114/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64115 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64115/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64137 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64137/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64266 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64266/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64268 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64268/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64304 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64304/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64355 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64355/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64423 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64423/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64450 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64450/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64481 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64481/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64541 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64541/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64543 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64543/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64556 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64556/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64562 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64562/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64563 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64563/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64572 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64572/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64581 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64581/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-64593 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-64593/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68121 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68121/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68136 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68136/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68138 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68138/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68155 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68155/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68158 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68158/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68159 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68159/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68160 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68160/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68202 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68202/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68397 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68397/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68398 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68398/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68417 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68417/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68426 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68426/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-68480 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-68480/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72020 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72020/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72069 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72069/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72083 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72083/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72084 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72084/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72123 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72123/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72135 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72135/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72164 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72164/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72251 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72251/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72288 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72288/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72289 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72289/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72323 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72323/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72339 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72339/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-72389 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-72389/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74345 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74345/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74377 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74377/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74378 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74378/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74388 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74388/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74390 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74390/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74394 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74394/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74406 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74406/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74454 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74454/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74488 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74488/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74496 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74496/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74518 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74518/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74537 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74537/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74556 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74556/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74582 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74582/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74615 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74615/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74616 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74616/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74669 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74669/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74695 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74695/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-74743 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-74743/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80580 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80580/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80714 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80714/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80716 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80716/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80737 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80737/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80909 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80909/"
      }
    ],
    "title": "Security update for the Linux Kernel",
    "tracking": {
      "current_release_date": "2026-09-23T08:31:49Z",
      "generator": {
        "date": "2026-09-22T08:32:05Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "SUSE-SU-2026:4279-1",
      "initial_release_date": "2026-09-22T08:32:05Z",
      "revision_history": [
        {
          "date": "2026-09-22T08:32:05Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-09-23T08:31:49Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "kernel-devel-rt-0:5.14.21-150400.15.186.1.noarch",
                "product": {
                  "name": "kernel-devel-rt-0:5.14.21-150400.15.186.1.noarch",
                  "product_id": "kernel-devel-rt-0:5.14.21-150400.15.186.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-devel-rt@5.14.21-150400.15.186.1?arch=noarch&upstream=kernel-source-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
                "product": {
                  "name": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
                  "product_id": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-source-rt@5.14.21-150400.15.186.1?arch=noarch&upstream=kernel-source-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "cluster-md-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "cluster-md-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "cluster-md-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/cluster-md-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "dlm-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "dlm-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "dlm-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/dlm-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "gfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "gfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/gfs2-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-devel-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt-devel@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-extra-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-extra-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-extra-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt-extra@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-livepatch-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-livepatch-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-livepatch-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt-livepatch@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-source-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-livepatch-devel-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-livepatch-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-livepatch-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt-livepatch-devel@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt-optional-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt-optional-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt-optional-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt-optional@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt_debug-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt_debug-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt_debug-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt_debug@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt_debug-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-rt_debug-devel-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-rt_debug-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-rt_debug-devel-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-rt_debug-devel@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt_debug-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kernel-syms-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kernel-syms-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kernel-syms-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kernel-syms-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-syms-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "kselftests-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "kselftests-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "kselftests-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/kselftests-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "ocfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "ocfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "ocfs2-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/ocfs2-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "reiserfs-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                "product": {
                  "name": "reiserfs-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_id": "reiserfs-kmp-rt-0:5.14.21-150400.15.186.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:linux:linux_kernel:5.14.21:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/reiserfs-kmp-rt@5.14.21-150400.15.186.1?arch=x86_64&upstream=kernel-rt-0:5.14.21-150400.15.186.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Micro 5.3",
                "product": {
                  "name": "SUSE Linux Enterprise Micro 5.3",
                  "product_id": "SUSE Linux Enterprise Micro 5.3",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-micro:5.3"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Micro 5.4",
                "product": {
                  "name": "SUSE Linux Enterprise Micro 5.4",
                  "product_id": "SUSE Linux Enterprise Micro 5.4",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sle-micro:5.4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64 as component of SUSE Linux Enterprise Micro 5.3",
          "product_id": "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64"
        },
        "product_reference": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Micro 5.3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch as component of SUSE Linux Enterprise Micro 5.3",
          "product_id": "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        },
        "product_reference": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Micro 5.3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64 as component of SUSE Linux Enterprise Micro 5.4",
          "product_id": "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64"
        },
        "product_reference": "kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
        "relates_to_product_reference": "SUSE Linux Enterprise Micro 5.4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch as component of SUSE Linux Enterprise Micro 5.4",
          "product_id": "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        },
        "product_reference": "kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
        "relates_to_product_reference": "SUSE Linux Enterprise Micro 5.4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-53109",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2023-53109"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tunnels: annotate lockless accesses to dev->needed_headroom\n\nIP tunnels can apparently update dev->needed_headroom\nin their xmit path.\n\nThis patch takes care of three tunnels xmit, and also the\ncore LL_RESERVED_SPACE() and LL_RESERVED_SPACE_EXTRA()\nhelpers.\n\nMore changes might be needed for completeness.\n\nBUG: KCSAN: data-race in ip_tunnel_xmit / ip_tunnel_xmit\n\nread to 0xffff88815b9da0ec of 2 bytes by task 888 on cpu 1:\nip_tunnel_xmit+0x1270/0x1730 net/ipv4/ip_tunnel.c:803\n__gre_xmit net/ipv4/ip_gre.c:469 [inline]\nipgre_xmit+0x516/0x570 net/ipv4/ip_gre.c:661\n__netdev_start_xmit include/linux/netdevice.h:4881 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4895 [inline]\nxmit_one net/core/dev.c:3580 [inline]\ndev_hard_start_xmit+0x127/0x400 net/core/dev.c:3596\n__dev_queue_xmit+0x1007/0x1eb0 net/core/dev.c:4246\ndev_queue_xmit include/linux/netdevice.h:3051 [inline]\nneigh_direct_output+0x17/0x20 net/core/neighbour.c:1623\nneigh_output include/net/neighbour.h:546 [inline]\nip_finish_output2+0x740/0x840 net/ipv4/ip_output.c:228\nip_finish_output+0xf4/0x240 net/ipv4/ip_output.c:316\nNF_HOOK_COND include/linux/netfilter.h:291 [inline]\nip_output+0xe5/0x1b0 net/ipv4/ip_output.c:430\ndst_output include/net/dst.h:444 [inline]\nip_local_out+0x64/0x80 net/ipv4/ip_output.c:126\niptunnel_xmit+0x34a/0x4b0 net/ipv4/ip_tunnel_core.c:82\nip_tunnel_xmit+0x1451/0x1730 net/ipv4/ip_tunnel.c:813\n__gre_xmit net/ipv4/ip_gre.c:469 [inline]\nipgre_xmit+0x516/0x570 net/ipv4/ip_gre.c:661\n__netdev_start_xmit include/linux/netdevice.h:4881 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4895 [inline]\nxmit_one net/core/dev.c:3580 [inline]\ndev_hard_start_xmit+0x127/0x400 net/core/dev.c:3596\n__dev_queue_xmit+0x1007/0x1eb0 net/core/dev.c:4246\ndev_queue_xmit include/linux/netdevice.h:3051 [inline]\nneigh_direct_output+0x17/0x20 net/core/neighbour.c:1623\nneigh_output include/net/neighbour.h:546 [inline]\nip_finish_output2+0x740/0x840 net/ipv4/ip_output.c:228\nip_finish_output+0xf4/0x240 net/ipv4/ip_output.c:316\nNF_HOOK_COND include/linux/netfilter.h:291 [inline]\nip_output+0xe5/0x1b0 net/ipv4/ip_output.c:430\ndst_output include/net/dst.h:444 [inline]\nip_local_out+0x64/0x80 net/ipv4/ip_output.c:126\niptunnel_xmit+0x34a/0x4b0 net/ipv4/ip_tunnel_core.c:82\nip_tunnel_xmit+0x1451/0x1730 net/ipv4/ip_tunnel.c:813\n__gre_xmit net/ipv4/ip_gre.c:469 [inline]\nipgre_xmit+0x516/0x570 net/ipv4/ip_gre.c:661\n__netdev_start_xmit include/linux/netdevice.h:4881 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4895 [inline]\nxmit_one net/core/dev.c:3580 [inline]\ndev_hard_start_xmit+0x127/0x400 net/core/dev.c:3596\n__dev_queue_xmit+0x1007/0x1eb0 net/core/dev.c:4246\ndev_queue_xmit include/linux/netdevice.h:3051 [inline]\nneigh_direct_output+0x17/0x20 net/core/neighbour.c:1623\nneigh_output include/net/neighbour.h:546 [inline]\nip_finish_output2+0x740/0x840 net/ipv4/ip_output.c:228\nip_finish_output+0xf4/0x240 net/ipv4/ip_output.c:316\nNF_HOOK_COND include/linux/netfilter.h:291 [inline]\nip_output+0xe5/0x1b0 net/ipv4/ip_output.c:430\ndst_output include/net/dst.h:444 [inline]\nip_local_out+0x64/0x80 net/ipv4/ip_output.c:126\niptunnel_xmit+0x34a/0x4b0 net/ipv4/ip_tunnel_core.c:82\nip_tunnel_xmit+0x1451/0x1730 net/ipv4/ip_tunnel.c:813\n__gre_xmit net/ipv4/ip_gre.c:469 [inline]\nipgre_xmit+0x516/0x570 net/ipv4/ip_gre.c:661\n__netdev_start_xmit include/linux/netdevice.h:4881 [inline]\nnetdev_start_xmit include/linux/netdevice.h:4895 [inline]\nxmit_one net/core/dev.c:3580 [inline]\ndev_hard_start_xmit+0x127/0x400 net/core/dev.c:3596\n__dev_queue_xmit+0x1007/0x1eb0 net/core/dev.c:4246\ndev_queue_xmit include/linux/netdevice.h:3051 [inline]\nneigh_direct_output+0x17/0x20 net/core/neighbour.c:1623\nneigh_output include/net/neighbour.h:546 [inline]\nip_finish_output2+0x740/0x840 net/ipv4/ip_output.c:228\nip_finish_output+0xf4/0x240 net/ipv4/ip_output.c:316\nNF_HOOK_COND include/linux/netfilter.h:291 [inline]\nip_output+0xe5/0x1b0 net/i\n---truncated---",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2023-53109",
          "url": "https://www.suse.com/security/cve/CVE-2023-53109"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1242405 for CVE-2023-53109",
          "url": "https://bugzilla.suse.com/1242405"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2023-53109"
    },
    {
      "cve": "CVE-2024-57841",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2024-57841"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix memory leak in tcp_conn_request()\n\nIf inet_csk_reqsk_queue_hash_add() return false, tcp_conn_request() will\nreturn without free the dst memory, which allocated in af_ops->route_req.\n\nHere is the kmemleak stack:\n\nunreferenced object 0xffff8881198631c0 (size 240):\n  comm \"softirq\", pid 0, jiffies 4299266571 (age 1802.392s)\n  hex dump (first 32 bytes):\n    00 10 9b 03 81 88 ff ff 80 98 da bc ff ff ff ff  ................\n    81 55 18 bb ff ff ff ff 00 00 00 00 00 00 00 00  .U..............\n  backtrace:\n    [<ffffffffb93e8d4c>] kmem_cache_alloc+0x60c/0xa80\n    [<ffffffffba11b4c5>] dst_alloc+0x55/0x250\n    [<ffffffffba227bf6>] rt_dst_alloc+0x46/0x1d0\n    [<ffffffffba23050a>] __mkroute_output+0x29a/0xa50\n    [<ffffffffba23456b>] ip_route_output_key_hash+0x10b/0x240\n    [<ffffffffba2346bd>] ip_route_output_flow+0x1d/0x90\n    [<ffffffffba254855>] inet_csk_route_req+0x2c5/0x500\n    [<ffffffffba26b331>] tcp_conn_request+0x691/0x12c0\n    [<ffffffffba27bd08>] tcp_rcv_state_process+0x3c8/0x11b0\n    [<ffffffffba2965c6>] tcp_v4_do_rcv+0x156/0x3b0\n    [<ffffffffba299c98>] tcp_v4_rcv+0x1cf8/0x1d80\n    [<ffffffffba239656>] ip_protocol_deliver_rcu+0xf6/0x360\n    [<ffffffffba2399a6>] ip_local_deliver_finish+0xe6/0x1e0\n    [<ffffffffba239b8e>] ip_local_deliver+0xee/0x360\n    [<ffffffffba239ead>] ip_rcv+0xad/0x2f0\n    [<ffffffffba110943>] __netif_receive_skb_one_core+0x123/0x140\n\nCall dst_release() to free the dst memory when\ninet_csk_reqsk_queue_hash_add() return false in tcp_conn_request().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2024-57841",
          "url": "https://www.suse.com/security/cve/CVE-2024-57841"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1235944 for CVE-2024-57841",
          "url": "https://bugzilla.suse.com/1235944"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2024-57841"
    },
    {
      "cve": "CVE-2026-23451",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-23451"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: prevent potential infinite loop in bond_header_parse()\n\nbond_header_parse() can loop if a stack of two bonding devices is setup,\nbecause skb->dev always points to the hierarchy top.\n\nAdd new \"const struct net_device *dev\" parameter to\n(struct header_ops)->parse() method to make sure the recursion\nis bounded, and that the final leaf parse method is called.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-23451",
          "url": "https://www.suse.com/security/cve/CVE-2026-23451"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1261604 for CVE-2026-23451",
          "url": "https://bugzilla.suse.com/1261604"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-23451"
    },
    {
      "cve": "CVE-2026-31502",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-31502"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nteam: fix header_ops type confusion with non-Ethernet ports\n\nSimilar to commit 950803f72547 (\"bonding: fix type confusion in\nbond_setup_by_slave()\") team has the same class of header_ops type\nconfusion.\n\nFor non-Ethernet ports, team_setup_by_port() copies port_dev->header_ops\ndirectly. When the team device later calls dev_hard_header() or\ndev_parse_header(), these callbacks can run with the team net_device\ninstead of the real lower device, so netdev_priv(dev) is interpreted as\nthe wrong private type and can crash.\n\nThe syzbot report shows a crash in bond_header_create(), but the root\ncause is in team: the topology is gre -> bond -> team, and team calls\nthe inherited header_ops with its own net_device instead of the lower\ndevice, so bond_header_create() receives a team device and interprets\nnetdev_priv() as bonding private data, causing a type confusion crash.\n\nFix this by introducing team header_ops wrappers for create/parse,\nselecting a team port under RCU, and calling the lower device callbacks\nwith port->dev, so each callback always sees the correct net_device\ncontext.\n\nAlso pass the selected lower device to the lower parse callback, so\nrecursion is bounded in stacked non-Ethernet topologies and parse\ncallbacks always run with the correct device context.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-31502",
          "url": "https://www.suse.com/security/cve/CVE-2026-31502"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1263072 for CVE-2026-31502",
          "url": "https://bugzilla.suse.com/1263072"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-31502"
    },
    {
      "cve": "CVE-2026-43456",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-43456"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: fix type confusion in bond_setup_by_slave()\n\nkernel BUG at net/core/skbuff.c:2306!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nRIP: 0010:pskb_expand_head+0xa08/0xfe0 net/core/skbuff.c:2306\nRSP: 0018:ffffc90004aff760 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff88807e3c8780 RCX: ffffffff89593e0e\nRDX: ffff88807b7c4900 RSI: ffffffff89594747 RDI: ffff88807b7c4900\nRBP: 0000000000000820 R08: 0000000000000005 R09: 0000000000000000\nR10: 00000000961a63e0 R11: 0000000000000000 R12: ffff88807e3c8780\nR13: 00000000961a6560 R14: dffffc0000000000 R15: 00000000961a63e0\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fe1a0ed8df0 CR3: 000000002d816000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n ipgre_header+0xdd/0x540 net/ipv4/ip_gre.c:900\n dev_hard_header include/linux/netdevice.h:3439 [inline]\n packet_snd net/packet/af_packet.c:3028 [inline]\n packet_sendmsg+0x3ae5/0x53c0 net/packet/af_packet.c:3108\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg net/socket.c:742 [inline]\n ____sys_sendmsg+0xa54/0xc30 net/socket.c:2592\n ___sys_sendmsg+0x190/0x1e0 net/socket.c:2646\n __sys_sendmsg+0x170/0x220 net/socket.c:2678\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x106/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fe1a0e6c1a9\n\nWhen a non-Ethernet device (e.g. GRE tunnel) is enslaved to a bond,\nbond_setup_by_slave() directly copies the slave's header_ops to the\nbond device:\n\n    bond_dev->header_ops = slave_dev->header_ops;\n\nThis causes a type confusion when dev_hard_header() is later called\non the bond device. Functions like ipgre_header(), ip6gre_header(),all use\nnetdev_priv(dev) to access their device-specific private data. When\ncalled with the bond device, netdev_priv() returns the bond's private\ndata (struct bonding) instead of the expected type (e.g. struct\nip_tunnel), leading to garbage values being read and kernel crashes.\n\nFix this by introducing bond_header_ops with wrapper functions that\ndelegate to the active slave's header_ops using the slave's own\ndevice. This ensures netdev_priv() in the slave's header functions\nalways receives the correct device.\n\nThe fix is placed in the bonding driver rather than individual device\ndrivers, as the root cause is bond blindly inheriting header_ops from\nthe slave without considering that these callbacks expect a specific\nnetdev_priv() layout.\n\nThe type confusion can be observed by adding a printk in\nipgre_header() and running the following commands:\n\n    ip link add dummy0 type dummy\n    ip addr add 10.0.0.1/24 dev dummy0\n    ip link set dummy0 up\n    ip link add gre1 type gre local 10.0.0.1\n    ip link add bond1 type bond mode active-backup\n    ip link set gre1 master bond1\n    ip link set gre1 up\n    ip link set bond1 up\n    ip addr add fe80::1/64 dev bond1",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-43456",
          "url": "https://www.suse.com/security/cve/CVE-2026-43456"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1264734 for CVE-2026-43456",
          "url": "https://bugzilla.suse.com/1264734"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271473 for CVE-2026-43456",
          "url": "https://bugzilla.suse.com/1271473"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-43456"
    },
    {
      "cve": "CVE-2026-43502",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-43502"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/rds: handle zerocopy send cleanup before the message is queued\n\nA zerocopy send can fail after user pages have been pinned but before\nthe message is attached to the sending socket.\n\nThe purge path currently infers zerocopy state from rm->m_rs, so an\nunqueued message can be cleaned up as if it owned normal payload pages.\nHowever, zerocopy ownership is really determined by the presence of\nop_mmp_znotifier, regardless of whether the message has reached the\nsocket queue.\n\nCapture op_mmp_znotifier up front in rds_message_purge() and use it as\nthe cleanup discriminator. If the message is already associated with a\nsocket, keep the existing completion path. Otherwise, drop the pinned\npage accounting directly and release the notifier before putting the\npayload pages.\n\nThis keeps early send failure cleanup consistent with the zerocopy\nlifetime rules without changing the normal queued completion path.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-43502",
          "url": "https://www.suse.com/security/cve/CVE-2026-43502"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1266008 for CVE-2026-43502",
          "url": "https://bugzilla.suse.com/1266008"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279563 for CVE-2026-43502",
          "url": "https://bugzilla.suse.com/1279563"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-43502"
    },
    {
      "cve": "CVE-2026-45968",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-45968"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpuidle: Skip governor when only one idle state is available\n\nOn certain platforms (PowerNV systems without a power-mgt DT node),\ncpuidle may register only a single idle state. In cases where that\nsingle state is a polling state (state 0), the ladder governor may\nincorrectly treat state 1 as the first usable state and pass an\nout-of-bounds index. This can lead to a NULL enter callback being\ninvoked, ultimately resulting in a system crash.\n\n[   13.342636] cpuidle-powernv : Only Snooze is available\n[   13.351854] Faulting instruction address: 0x00000000\n[   13.376489] NIP [0000000000000000] 0x0\n[   13.378351] LR  [c000000001e01974] cpuidle_enter_state+0x2c4/0x668\n\nFix this by adding a bail-out in cpuidle_select() that returns state 0\ndirectly when state_count <= 1, bypassing the governor and keeping the\ntick running.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-45968",
          "url": "https://www.suse.com/security/cve/CVE-2026-45968"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1267023 for CVE-2026-45968",
          "url": "https://bugzilla.suse.com/1267023"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-45968"
    },
    {
      "cve": "CVE-2026-52910",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-52910"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Free reuseport cBPF prog after RCU grace period.\n\nEulgyu Kim reported the splat below with a repro. [0]\n\nThe repro sets up a UDP reuseport group with a cBPF prog and\nreplaces it with a new one while another thread is sending\na UDP packet to the group.\n\nThe reuseport prog is freed by sk_reuseport_prog_free().\nbpf_prog_put() is called for \"e\"BPF prog to destruct through\nmultiple stages while cBPF prog is freed immediately by\nbpf_release_orig_filter() and bpf_prog_free().\n\nIf a reuseport prog is detached from the setsockopt() path\n(reuseport_attach_prog() or reuseport_detach_prog()),\nsk_reuseport_prog_free() is called without waiting for RCU\nreaders to complete, resulting in various bugs.\n\nLet's defer freeing the reuseport cBPF prog after one RCU\ngrace period.\n\nNote \"e\"BPF prog is safe as is unless the fast path starts\nto touch fields destroyed in bpf_prog_put_deferred() and\n__bpf_prog_put_noref().\n\n[0]:\nBUG: KASAN: vmalloc-out-of-bounds in reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\nRead of size 4 at addr ffffc9000051e004 by task slowme/10208\nCPU: 6 UID: 1000 PID: 10208 Comm: slowme Not tainted 7.0.0-geb7ac95ff75e #32 PREEMPT(full)\nHardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nCall Trace:\n <IRQ>\n dump_stack_lvl+0xe8/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xca/0x240 mm/kasan/report.c:482\n kasan_report+0x118/0x150 mm/kasan/report.c:595\n reuseport_select_sock+0xedc/0x1220 net/core/sock_reuseport.c:596\n udp4_lib_lookup2+0x3bc/0x950 net/ipv4/udp.c:495\n __udp4_lib_lookup+0x768/0xe20 net/ipv4/udp.c:723\n __udp4_lib_lookup_skb+0x297/0x390 net/ipv4/udp.c:752\n __udp4_lib_rcv+0x1312/0x2620 net/ipv4/udp.c:2752\n ip_protocol_deliver_rcu+0x282/0x440 net/ipv4/ip_input.c:207\n ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n NF_HOOK+0x30c/0x3a0 include/linux/netfilter.h:318\n __netif_receive_skb_one_core net/core/dev.c:6181 [inline]\n __netif_receive_skb net/core/dev.c:6294 [inline]\n process_backlog+0xaa4/0x1960 net/core/dev.c:6645\n __napi_poll+0xae/0x340 net/core/dev.c:7709\n napi_poll net/core/dev.c:7772 [inline]\n net_rx_action+0x5d7/0xf50 net/core/dev.c:7929\n handle_softirqs+0x22b/0x870 kernel/softirq.c:622\n do_softirq+0x76/0xd0 kernel/softirq.c:523\n </IRQ>\n <TASK>\n __local_bh_enable_ip+0xf8/0x130 kernel/softirq.c:450\n local_bh_enable include/linux/bottom_half.h:33 [inline]\n rcu_read_unlock_bh include/linux/rcupdate.h:924 [inline]\n __dev_queue_xmit+0x1dd7/0x3710 net/core/dev.c:4890\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xca9/0x1070 net/ipv4/ip_output.c:237\n NF_HOOK_COND include/linux/netfilter.h:307 [inline]\n ip_output+0x29f/0x450 net/ipv4/ip_output.c:438\n ip_send_skb+0x45/0xc0 net/ipv4/ip_output.c:1508\n udp_send_skb+0xb04/0x1510 net/ipv4/udp.c:1195\n udp_sendmsg+0x1a71/0x2350 net/ipv4/udp.c:1485\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg net/socket.c:742 [inline]\n __sys_sendto+0x554/0x680 net/socket.c:2206\n __do_sys_sendto net/socket.c:2213 [inline]\n __se_sys_sendto net/socket.c:2209 [inline]\n __x64_sys_sendto+0xde/0x100 net/socket.c:2209\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x160/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x415a2d\nCode: b3 66 2e 0f 1f 84 00 00 00 00 00 66 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6bc31e41e8 EFLAGS: 00000212 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f6bc31e4cdc RCX: 0000000000415a2d\nRDX: 0000000000000001 RSI: 00007f6bc31e421f RDI: 0000000000000003\nRBP: 00007f6bc31e4240 R08: 00007f6bc31e4220 R09: 0000000000000010\nR10: 0000000000000000 R11: \n---truncated---",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-52910",
          "url": "https://www.suse.com/security/cve/CVE-2026-52910"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1268659 for CVE-2026-52910",
          "url": "https://bugzilla.suse.com/1268659"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273819 for CVE-2026-52910",
          "url": "https://bugzilla.suse.com/1273819"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-52910"
    },
    {
      "cve": "CVE-2026-52912",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-52912"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_queue: hold bridge skb->dev while queued\n\nbr_pass_frame_up() rewrites skb->dev from the ingress port to the bridge\nmaster before queueing bridge LOCAL_IN packets. NFQUEUE only holds\nreferences on state.in/out and bridge physdevs, so a queued bridge\npacket can retain a freed bridge master in skb->dev until reinjection.\n\nWhen the verdict is reinjected later, br_netif_receive_skb() re-enters\nthe receive path with skb->dev still pointing at the freed bridge master,\ntriggering a use-after-free.\n\nStore skb->dev in the queue entry, hold a reference on it for the queue\nlifetime, and use the saved device when dropping queued packets during\nNETDEV_DOWN handling.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-52912",
          "url": "https://www.suse.com/security/cve/CVE-2026-52912"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269000 for CVE-2026-52912",
          "url": "https://bugzilla.suse.com/1269000"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276762 for CVE-2026-52912",
          "url": "https://bugzilla.suse.com/1276762"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-52912"
    },
    {
      "cve": "CVE-2026-52929",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-52929"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: stream: fully roll back denied add-stream state\n\nWhen ADD_OUT_STREAMS is denied, SCTP only shrinks the queued chunks and\nthen lowers outcnt. That leaves removed stream metadata behind, so a\nlater re-add can reuse a stale ext and hit a null-pointer dereference in\nthe scheduler get path.\n\nFix the rollback by tearing down the removed stream state the same way\nother stream resizes do. Unschedule the current scheduler state, drop\nthe removed stream ext state with sctp_stream_outq_migrate(), and then\nreschedule the remaining streams.\n\nThis keeps scheduler-private RR/FC/PRIO lists consistent while fully\nrolling back denied outgoing stream additions.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-52929",
          "url": "https://www.suse.com/security/cve/CVE-2026-52929"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269004 for CVE-2026-52929",
          "url": "https://bugzilla.suse.com/1269004"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276219 for CVE-2026-52929",
          "url": "https://bugzilla.suse.com/1276219"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-52929"
    },
    {
      "cve": "CVE-2026-52977",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-52977"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Prevent lockup in requeue-PI during signal/ timeout wakeup\n\nDuring wait-requeue-pi (task A) and requeue-PI (task B) the following\nrace can happen:\n\n     Task A                             Task B\n  futex_wait_requeue_pi()\n    futex_setup_timer()\n    futex_do_wait()\n                                   futex_requeue()\n                                        CLASS(hb, hb1)(&key1);\n                                        CLASS(hb, hb2)(&key2);\n        *timeout*\n    futex_requeue_pi_wakeup_sync()\n        requeue_state = Q_REQUEUE_PI_IGNORE\n\n    *blocks on hb->lock*\n\n                                        futex_proxy_trylock_atomic()\n                                          futex_requeue_pi_prepare()\n                                            Q_REQUEUE_PI_IGNORE => -EAGAIN\n                                        double_unlock_hb(hb1, hb2)\n                                         *retry*\n\nTask B acquires both hb locks and attempts to acquire the PI-lock of the\ntop most waiter (task B). Task A is leaving early due to a signal/\ntimeout and started removing itself from the queue. It updates its\nrequeue_state but can not remove it from the list because this requires\nthe hb lock which is owned by task B.\n\nUsually task A is able to swoop the lock after task B unlocked it.\nHowever if task B is of higher priority then task A may not be able to\nwake up in time and acquire the lock before task B gets it again.\nEspecially on a UP system where A is never scheduled.\n\nAs a result task A blocks on the lock and task B busy loops, trying to\nmake progress but live locks the system instead. Tragic.\n\nThis can be fixed by removing the top most waiter from the list in this\ncase. This allows task B to grab the next top waiter (if any) in the\nnext iteration and make progress.\n\nRemove the top most waiter if futex_requeue_pi_prepare() fails.\nLet the waiter conditionally remove itself from the list in\nhandle_early_requeue_pi_wakeup().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-52977",
          "url": "https://www.suse.com/security/cve/CVE-2026-52977"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269242 for CVE-2026-52977",
          "url": "https://bugzilla.suse.com/1269242"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-52977"
    },
    {
      "cve": "CVE-2026-53059",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53059"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm log: fix out-of-bounds write due to region_count overflow\n\nThe local variable region_count in create_log_context() is declared as\nunsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit).\nWhen a device-mapper target has a sufficiently large ti->len with a small\nregion_size, the division result can exceed UINT_MAX. The truncated\nvalue is then used to calculate bitset_size, causing clean_bits,\nsync_bits, and recovering_bits to be allocated far smaller than needed\nfor the actual number of regions.\n\nSubsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use\nregion indices derived from the full untruncated region space, causing\nout-of-bounds writes to kernel heap memory allocated by vmalloc.\n\nThis can be reproduced by creating a mirror target whose region_count\noverflows 32 bits:\n\n  dmsetup create bigzero --table '0 8589934594 zero'\n  dmsetup create mymirror --table '0 8589934594 mirror \\\n    core 2 2 nosync 2 /dev/mapper/bigzero 0 \\\n    /dev/mapper/bigzero 0'\n\nThe status output confirms the truncation (sync_count=1 instead of\n4294967297, because 0x100000001 was truncated to 1):\n\n  $ dmsetup status mymirror\n  0 8589934594 mirror 2 254:1 254:1 1/4294967297 ...\n\nThis leads to a kernel crash in core_in_sync:\n\n  BUG: scheduling while atomic: (udev-worker)/9150/0x00000000\n  RIP: 0010:core_in_sync+0x14/0x30 [dm_log]\n  CR2: 0000000000000008\n  Fixing recursive fault but reboot is needed!\n\nFix by widening the local region_count to sector_t and adding an\nexplicit overflow check before the value is assigned to lc->region_count.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53059",
          "url": "https://www.suse.com/security/cve/CVE-2026-53059"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269655 for CVE-2026-53059",
          "url": "https://bugzilla.suse.com/1269655"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1270376 for CVE-2026-53059",
          "url": "https://bugzilla.suse.com/1270376"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-53059"
    },
    {
      "cve": "CVE-2026-53163",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53163"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rtmutex: Skip remove_waiter() when waiter is not enqueued\n\nsyzbot triggered the following splat in remove_waiter() via\nFUTEX_CMP_REQUEUE_PI:\n\n  KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f]\n   class_raw_spinlock_constructor\n   remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561\n   rt_mutex_start_proxy_lock+0x103/0x120\n   futex_requeue+0x10e4/0x20d0\n   __x64_sys_futex+0x34f/0x4d0\n\ntask_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection,\nleaving waiter->task nil, where 3bfdc63936dd (\"rtmutex: Use waiter::task instead\nof current in remove_waiter()\") made this fatal.\n\nFurthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter()\nupon a successfully grabbing the rtmutex. 1a1fb985f2e2 (\"futex: Handle early deadlock\nreturn correctly\"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock()\n(where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to\naccount for try_to_take_rt_mutex().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53163",
          "url": "https://www.suse.com/security/cve/CVE-2026-53163"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269306 for CVE-2026-53163",
          "url": "https://bugzilla.suse.com/1269306"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-53163"
    },
    {
      "cve": "CVE-2026-53260",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53260"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().\n\nsyzbot reported a weird reqsk->rsk_refcnt underflow in\n__inet_csk_reqsk_queue_drop().\n\nThe captured reqsk_put() in __inet_csk_reqsk_queue_drop()\nis called only when it successfully removes reqsk from ehash.\n\nMoreover, reqsk_timer_handler() calls another reqsk_put()\nafter that.\n\nThis indicates that the reqsk was missing both refcnts for\nehash and the timer itself.\n\nSince all the syzbot reports had PREEMPT_RT enabled, the only\npossible scenario is that reqsk_queue_hash_req() is preempted\nafter mod_timer() and before refcount_set(), and then the timer\ntriggered after 1s aborts the reqsk due to its listener's close().\n\nLet's wrap mod_timer() and refcount_set() with\npreempt_disable_nested() and preempt_enable_nested().\n\nNote that inet_ehash_insert() holds the normal spin_lock()\n(mutex in PREEMPT_RT), so it must be called outside of\npreempt_disable_nested(), but this is fine.\n\nThe lookup path just ignores 0 sk_refcnt entries in ehash\nand tries to create another reqsk, but this will fail at\ninet_ehash_insert().\n\n[0]:\nrefcount_t: underflow; use-after-free.\nWARNING: lib/refcount.c:28 at refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28, CPU#0: ktimers/0/16\nModules linked in:\nCPU: 0 UID: 0 PID: 16 Comm: ktimers/0 Tainted: G             L      syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nRIP: 0010:refcount_warn_saturate+0xb2/0x110 lib/refcount.c:28\nCode: e4 7d d1 0a 67 48 0f b9 3a eb 4a e8 38 3d 23 fd 48 8d 3d e1 7d d1 0a 67 48 0f b9 3a eb 37 e8 25 3d 23 fd 48 8d 3d de 7d d1 0a <67> 48 0f b9 3a eb 24 e8 12 3d 23 fd 48 8d 3d db 7d d1 0a 67 48 0f\nRSP: 0000:ffffc90000157948 EFLAGS: 00010246\nRAX: ffffffff84a1301b RBX: 0000000000000003 RCX: ffff88801ca98000\nRDX: 0000000000000100 RSI: 0000000000000000 RDI: ffffffff8f72ae00\nRBP: ffffffff99ae3b01 R08: ffff88801ca98000 R09: 0000000000000005\nR10: 0000000000000100 R11: 0000000000000004 R12: ffff8880425ef568\nR13: ffff8880425ef4f8 R14: ffff8880425ef578 R15: 0000000000000000\nFS:  0000000000000000(0000) GS:ffff888126386000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f7b46710e9c CR3: 000000000dbb6000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n __refcount_sub_and_test include/linux/refcount.h:400 [inline]\n __refcount_dec_and_test include/linux/refcount.h:432 [inline]\n refcount_dec_and_test include/linux/refcount.h:450 [inline]\n reqsk_put include/net/request_sock.h:136 [inline]\n __inet_csk_reqsk_queue_drop+0x3ce/0x440 net/ipv4/inet_connection_sock.c:1007\n reqsk_timer_handler+0x651/0xdf0 net/ipv4/inet_connection_sock.c:1137\n call_timer_fn+0x192/0x5e0 kernel/time/timer.c:1748\n expire_timers kernel/time/timer.c:1799 [inline]\n __run_timers kernel/time/timer.c:2374 [inline]\n __run_timer_base+0x6a3/0x9f0 kernel/time/timer.c:2386\n run_timer_base kernel/time/timer.c:2395 [inline]\n run_timer_softirq+0x67/0x170 kernel/time/timer.c:2403\n handle_softirqs+0x1de/0x6d0 kernel/softirq.c:622\n __do_softirq kernel/softirq.c:656 [inline]\n run_ktimerd+0x69/0x100 kernel/softirq.c:1151\n smpboot_thread_fn+0x541/0xa50 kernel/smpboot.c:160\n kthread+0x388/0x470 kernel/kthread.c:436\n ret_from_fork+0x514/0xb70 arch/x86/kernel/process.c:158\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n </TASK>",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53260",
          "url": "https://www.suse.com/security/cve/CVE-2026-53260"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269731 for CVE-2026-53260",
          "url": "https://bugzilla.suse.com/1269731"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-53260"
    },
    {
      "cve": "CVE-2026-53264",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53264"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_api: use RCU with deferred freeing for action lifecycle\n\nWhen NEWTFILTER and DELFILTER are run concurrently it is possible to create a\nrace with an associated action.\n\nLet's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER:\n\n 0: mutex_lock() <-- holds the idr lock\n 0: rcu_read_lock()\n 0: p = idr_find(idr, index) <-- action p is valid (RCU protects IDR)\n 0: mutex_unlock() <-- releases the idr lock\n 1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held\n 1: idr_remove(idr, index) <-- Action removed from IDR\n 1: mutex_unlock() <-- mutex released allowing us to delete the action\n 1: tcf_action_cleanup(p); kfree(p) <-- Kfrees p immediately, no deferral\n 0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- ouch, UAF p points to freed memory\n\nThis patch fixes the race condition between NEWTFILTER and DELFILTER by\nadding struct rcu_head to tc_action used in the deferral and introducing a\ncall_rcu() in the delete path to defer the final kfree().\n\nNote: this is a revert of commit d7fb60b9cafb (\"net_sched: get rid of tcfa_rcu\")\nbut also modernization/simplification to directly use kfree_rcu().\n\nLet's illustrate the new restored code path:\n\n 0: rcu_read_lock()\n 1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held\n 1: idr_remove(idr, index)\n 1: mutex_unlock()\n 1: call_rcu(&p->tcfa_rcu, tcf_action_rcu_free) <-- defer kfree after grace period\n 0: p = idr_find(idr, index)\n 0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- fails, refcnt already 0\n 1: rcu_read_unlock() <-- release so freeing can run after grace period\n\nAfter CPU1 calls idr_remove(), the object is no longer reachable through the IDR.\nCPU0's subsequent idr_find() will return NULL, and even if it still held a\nstale pointer, the immediate kfree() is now deferred until after the RCU grace\nperiod, so no UAF can occur.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53264",
          "url": "https://www.suse.com/security/cve/CVE-2026-53264"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269238 for CVE-2026-53264",
          "url": "https://bugzilla.suse.com/1269238"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273216 for CVE-2026-53264",
          "url": "https://bugzilla.suse.com/1273216"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-53264"
    },
    {
      "cve": "CVE-2026-53381",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53381"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtiofs: fix UAF on submount umount\n\niput() called from fuse_release_end() can Oops if the super block has\nalready been destroyed.  Normally this is prevented by waiting for\nnum_waiting to go down to zero before commencing with super block shutdown.\n\nThis only works, however, for the last submount instance, as the wait\ncounter is per connection, not per superblock.\n\nRevert to using synchronous release requests for the auto_submounts case,\nwhich is virtiofs only at this time.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53381",
          "url": "https://www.suse.com/security/cve/CVE-2026-53381"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271830 for CVE-2026-53381",
          "url": "https://bugzilla.suse.com/1271830"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271837 for CVE-2026-53381",
          "url": "https://bugzilla.suse.com/1271837"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-53381"
    },
    {
      "cve": "CVE-2026-53388",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-53388"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before replacing page cache folio\n\nfuse_try_move_folio() unlocks the request on entry but does not\nre-lock it on the success path. This means fuse_chan_abort() can end the\nrequest and free the fuse_io_args (eg fuse_readpages_end()) while the\nsubsequent copy chain logic after fuse_try_move_folio() accesses the\nfuse_io_args, leading to use-after-free issues.\n\nFix this by calling lock_request() before replace_page_cache_folio().\nThis ensures the request is locked on the success path which will\nprevent the fuse_io_args from being freed while the later copying logic\nruns, and also ensures that the ap->folios[i]->mapping is never null\nsince ap->folios[i] will always point to the newfolio after\nreplace_page_cache_folio().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-53388",
          "url": "https://www.suse.com/security/cve/CVE-2026-53388"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1271825 for CVE-2026-53388",
          "url": "https://bugzilla.suse.com/1271825"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-53388"
    },
    {
      "cve": "CVE-2026-63801",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63801"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix slab-use-after-free Read in tipc_aead_decrypt_done\n\ntipc_aead_decrypt() goes straight from tipc_bearer_hold(b) to\ncrypto_aead_decrypt(req) without taking a reference on the netns, unlike\nthe encrypt path. When crypto_aead_decrypt() is offloaded asynchronously\n(e.g. the SIMD aead wrapper queuing to cryptd), the cryptd worker runs\ntipc_aead_decrypt_done() later. If the bearer's netns is torn down in the\nmeantime, cleanup_net() -> tipc_exit_net() -> tipc_crypto_stop() frees the\nper-netns tipc_crypto, and the completion then reads it:\ntipc_aead_decrypt_done() dereferences aead->crypto->stats and\naead->crypto->net, and tipc_crypto_rcv_complete() dereferences\naead->crypto->aead[] and the node table -- reading freed memory.\n\nDecoded KASAN splat (v7.1-rc7, CONFIG_KASAN_INLINE + TIPC + TIPC_CRYPTO):\n\n  BUG: KASAN: slab-use-after-free in tipc_aead_decrypt_done (net/tipc/crypto.c:999)\n  Read of size 8 at addr ffff8881056258a8 by task kworker/u16:2/51\n  Workqueue: events_unbound\n  Call Trace:\n   tipc_aead_decrypt_done (net/tipc/crypto.c:999)\n   process_one_work (kernel/workqueue.c:3314)\n   worker_thread (kernel/workqueue.c:3397 kernel/workqueue.c:3478)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n\n  Allocated by task 169:\n   __kasan_kmalloc (mm/kasan/common.c:398 mm/kasan/common.c:415)\n   tipc_crypto_start (net/tipc/crypto.c:1502)\n   tipc_init_net (net/tipc/core.c:72)\n   ops_init (net/core/net_namespace.c:137)\n   setup_net (net/core/net_namespace.c:446)\n   copy_net_ns (net/core/net_namespace.c:579)\n   create_new_namespaces (kernel/nsproxy.c:132)\n   __x64_sys_unshare (kernel/fork.c:3316)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:63)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\n  Freed by task 8:\n   kfree (mm/slub.c:6566)\n   tipc_exit_net (net/tipc/core.c:119)\n   cleanup_net (net/core/net_namespace.c:704)\n   process_one_work (kernel/workqueue.c:3314)\n   kthread (kernel/kthread.c:436)\n\nThis is the same class of bug that commit e279024617134 (\"net/tipc: fix\nslab-use-after-free Read in tipc_aead_encrypt_done\") fixed for the encrypt\nside. The encrypt path takes maybe_get_net(aead->crypto->net) before\ncrypto_aead_encrypt() and drops it with put_net() on the synchronous\nreturn paths and in tipc_aead_encrypt_done(); the -EINPROGRESS/-EBUSY\nreturn keeps the reference for the async callback to release. The decrypt\npath was left without the equivalent guard.\n\nMirror the encrypt-side fix on the decrypt path: take a net reference\nbefore crypto_aead_decrypt() (failing with -ENODEV and the matching\nbearer put if it cannot be acquired), keep it across the\n-EINPROGRESS/-EBUSY async return, and drop it with put_net() on the\nsynchronous success/error return and at the end of\ntipc_aead_decrypt_done().\n\nReproduced under KASAN on v7.1-rc7: a UDP bearer with a cluster key is\nflooded with crafted encrypted frames from an unknown peer (driving the\ncluster-key decrypt path) while the bearer's netns is repeatedly torn\ndown. The completion must run asynchronously to outlive\ntipc_crypto_stop(); on x86 the stock aesni gcm(aes) now decrypts\nsynchronously, so the async path was exercised via cryptd offload. The\nunguarded aead->crypto dereference in tipc_aead_decrypt_done() is the\nunpatched upstream path; tipc_aead_decrypt() still lacks\nmaybe_get_net(aead->crypto->net), so the completion can outlive the free\non any config where crypto_aead_decrypt() goes async.\n\nFound by 0sec automated security-research tooling (https://0sec.ai).",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63801",
          "url": "https://www.suse.com/security/cve/CVE-2026-63801"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272230 for CVE-2026-63801",
          "url": "https://bugzilla.suse.com/1272230"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-63801"
    },
    {
      "cve": "CVE-2026-63823",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63823"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: Pin request_key_auth payload in instantiate paths\n\nA: request_key()       B: KEYCTL_INSTANTIATE_IOV\n================       =========================\n\ncreate auth key\nstore rka in auth key\nwait for helper\n                       get auth key\n                       load rka from auth key\n                       copy user payload\n                       sleep on #PF\n\nhelper completed\ndetach and free rka\ndestroy auth key\n                       wake up\n                       use rka->target_key\n                       **USE-AFTER-FREE**\n\nGive request_key_auth payloads a refcount.  Take a payload reference while\nauthkey->sem stabilizes the payload and revocation state.  Hold that\nreference across the instantiate and reject paths.  Drop the auth key\nowning reference from revoke and destroy.\n\n[jarkko: Replaced the first two paragraphs of text with an actual\n concurrency scenario.]",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63823",
          "url": "https://www.suse.com/security/cve/CVE-2026-63823"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272182 for CVE-2026-63823",
          "url": "https://bugzilla.suse.com/1272182"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272190 for CVE-2026-63823",
          "url": "https://bugzilla.suse.com/1272190"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63823"
    },
    {
      "cve": "CVE-2026-63827",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63827"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix use-after-free in rawdata dedup loop\n\naa_replace_profiles() walks ns->rawdata_list to dedup the incoming\npolicy blob against entries already attached to existing profiles.\nPer the kernel-doc on struct aa_loaddata, list membership does not\nhold a reference: profiles hold pcount, and when the last pcount\ndrops, do_ploaddata_rmfs() is queued on a workqueue that takes\nns->lock and removes the entry. Between dropping the last pcount\nand the workqueue running, an entry remains on the list with\npcount == 0.\n\naa_get_profile_loaddata() is an unconditional kref_get() on\npcount, so when the dedup loop hits such an entry, refcount\nhardening reports\n\n  refcount_t: addition on 0; use-after-free.\n\ninside aa_replace_profiles(), and the poisoned counter then\ntrips \"saturated\" and \"underflow\" warnings on the subsequent\nuses of the same loaddata.\n\nBefore commit a0b7091c4de4 (\"apparmor: fix race on rawdata\ndereference\") the dedup path used a get_unless_zero-style helper\non a single counter, so the existing \"if (tmp)\" guard was\nmeaningful. The split-refcount refactor introduced\naa_get_profile_loaddata(), which has plain kref_get() semantics,\nand the guard quietly became a no-op.\n\nIntroduce aa_get_profile_loaddata_not0(), matching the existing\n_not0 convention used by aa_get_profile_not0(), and use it for\nthe rawdata_list dedup lookup so dying entries are skipped.\n\nReproduced on x86_64 with v7.1-rc5 in QEMU+KVM running Ubuntu\n24.04 + stress-ng 0.17.06:\n\n  stress-ng --apparmor 1 --klog-check --timeout 60s\n\nWithout this patch the three refcount_t warnings fire within a\nfew seconds. With it the same 60 s run is clean. Coverage is a\nsmoke-test only; a longer soak with CONFIG_KASAN, CONFIG_KCSAN\nand CONFIG_PROVE_LOCKING would be welcome from anyone with the\ncycles.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63827",
          "url": "https://www.suse.com/security/cve/CVE-2026-63827"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272179 for CVE-2026-63827",
          "url": "https://bugzilla.suse.com/1272179"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272203 for CVE-2026-63827",
          "url": "https://bugzilla.suse.com/1272203"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63827"
    },
    {
      "cve": "CVE-2026-63887",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63887"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf\n\niscsi_encode_text_output() concatenates \"key=value\\0\" records into\nlogin->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer\nallocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call\nsites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check\nthe remaining buffer capacity:\n\n\t*length += sprintf(output_buf, \"%s=%s\", er->key, er->value);\n\t*length += 1;\n\toutput_buf = textbuf + *length;\n\nThe 8192-byte ceiling at iscsi_target_check_login_request() bounds the\n*input* Login PDU payload, but a single PDU can carry up to 2048 minimal\nfour-byte \"a=b\\0\" pairs, each unknown key expanding to a 16-byte\n\"a=NotUnderstood\\0\" output record via iscsi_add_notunderstood_response().\n2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB\nheap overrun in the kmalloc-8k slab.\n\nThe fix introduces a static iscsi_encode_text_record() helper that uses\nsnprintf() with a per-call bounds check against the remaining buffer,\nand threads a u32 textbuf_size parameter through\niscsi_encode_text_output(). Both call sites in\niscsi_target_handle_csg_zero() (PHASE_SECURITY) and\niscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass\nMAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls\niscsi_release_extra_responses() to drop queued records, and returns -1;\nboth caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /\nISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,\nso the initiator sees an explicit failed-login response rather than a\nsilent connection drop. (Prior to this patch only the PHASE_OPERATIONAL\ncaller did that; the PHASE_SECURITY caller is converted to the same\nshape.)",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63887",
          "url": "https://www.suse.com/security/cve/CVE-2026-63887"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272385 for CVE-2026-63887",
          "url": "https://bugzilla.suse.com/1272385"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272386 for CVE-2026-63887",
          "url": "https://bugzilla.suse.com/1272386"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63887"
    },
    {
      "cve": "CVE-2026-63888",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63888"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c (\"iscsi-target: Add\niSCSI fabric support for target v4.1\"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n   text_in is kzalloc()'d at ALIGN(payload_length, 4).  rx_size is then\n   incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n   in the iovec, but the same (now-bumped) rx_size is passed as the\n   buffer length to iscsit_crc_buf():\n\n       if (conn->conn_ops->DataDigest) {\n               ...\n               rx_size += ISCSI_CRC_LEN;\n       }\n       ...\n       if (conn->conn_ops->DataDigest) {\n               data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n   iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n   when DataDigest is negotiated it reads 4 bytes past the end of the\n   text_in allocation.  KASAN reproduces this directly on the unpatched\n   mainline tree as slab-out-of-bounds in crc32c() called from the Text\n   PDU path.  The OOB bytes feed crc32c() and are then compared against\n   the initiator-supplied checksum, so the value does not flow back to\n   the attacker, but the kernel does read past the buffer on every Text\n   PDU with DataDigest=CRC32C.\n\n   Fix by passing the actual padded payload length\n   (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest\n   drop.\n\n   On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler\n   silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n               kfree(text_in);\n               return 0;\n\n   cmd->text_in_ptr still points at the freed buffer.  The next Text\n   Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n   unconditionally does\n\n       kfree(cmd->text_in_ptr);\n       cmd->text_in_ptr = NULL;\n\n   freeing the same pointer a second time.  Session teardown via\n   iscsit_release_cmd() has the same shape and hits the same double-free\n   if the connection is dropped before a second Text Request arrives.\n\n   On an unmodified mainline tree the bug-1 CRC overread fires first on\n   the initial valid Text Request and perturbs the subsequent state, so\n   #4 was isolated by building a kernel with only the bug-1 hunk of this\n   patch applied plus temporary printk() observability around the three\n   relevant kfree() sites.  The observability prints are not part of\n   this patch.  On that build, a three-PDU Text Request sequence after\n   login produces two back-to-back splats:\n\n       BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n       BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n   showing the same pointer freed in the ERL>0 drop path and again in\n   iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n   more in iscsit_release_cmd() (session teardown).  On distro kernels\n   with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n   becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n   the slab freelist.\n\n   Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop\n   path.  With both hunks applied #4 is directly observable on the stock\n   tree without observability printks; fixing bug-1 alone would mask #4\n   less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners.  The Text PDU state machine is unchanged and\nthe wire protocol is unaffected.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63888",
          "url": "https://www.suse.com/security/cve/CVE-2026-63888"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272390 for CVE-2026-63888",
          "url": "https://bugzilla.suse.com/1272390"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272391 for CVE-2026-63888",
          "url": "https://bugzilla.suse.com/1272391"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63888"
    },
    {
      "cve": "CVE-2026-63920",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63920"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: validate extension header length before copying to cmsg\n\nip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR}\ncmsgs (and their IPV6_2292* legacy counterparts) by trusting the\non-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length.\nThe length was validated only at parse time (ipv6_parse_hopopts(),\netc.).  An nftables payload-write expression can rewrite hdrlen after\nparsing and before the skb reaches recvmsg; the write itself is\nin-bounds but put_cmsg() then reads up to ((hdrlen+1) << 3) = 2040\nbytes from an 8-byte header.  nftables is reachable from an\nunprivileged user namespace, so this is an unprivileged\nslab-out-of-bounds read:\n\n  BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540\n   put_cmsg+0x3ac/0x540\n   udpv6_recvmsg+0xca0/0x1250\n   sock_recvmsg+0xdf/0x190\n   ____sys_recvmsg+0x1b1/0x620\n\nAdd ipv6_get_exthdr_len() which validates that at least two bytes\nare accessible before reading the hdrlen field, then checks the\ncomputed length against skb_tail_pointer(skb), returning 0 on\nfailure.  Extension headers are kept in the linear skb area by\npskb_may_pull() during input, so skb_tail_pointer() is the correct\nbound.\n\nUse ipv6_get_exthdr_len() at all non-AH call sites: the five\nstandalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR)\nand the three standard cases in the extension-header walk loop\n(DSTOPTS, ROUTING, default).  AH retains an inline bounds check\nbecause its length formula differs ((ptr[1]+2)<<2).\n\nThe walk loop also gets a pre-read bounds check at the top to\nvalidate ptr before any case accesses ptr[0] or ptr[1].\n\nWhen the walk loop detects a corrupted header, return from the\nfunction instead of continuing to process later socket options.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63920",
          "url": "https://www.suse.com/security/cve/CVE-2026-63920"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272877 for CVE-2026-63920",
          "url": "https://bugzilla.suse.com/1272877"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273012 for CVE-2026-63920",
          "url": "https://bugzilla.suse.com/1273012"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63920"
    },
    {
      "cve": "CVE-2026-63992",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-63992"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n\nThis triggers an out-of-bound access, because\n(typeof(skb->transport_header))~0U is 65535.\n\nAccess the icmp header based on IPv4 network header,\nafter making sure icmp->type is present in skb linear part.\n\nNote that iptunnel_pmtud_check_icmpv6()) is fine.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-63992",
          "url": "https://www.suse.com/security/cve/CVE-2026-63992"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1272868 for CVE-2026-63992",
          "url": "https://bugzilla.suse.com/1272868"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273001 for CVE-2026-63992",
          "url": "https://bugzilla.suse.com/1273001"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-63992"
    },
    {
      "cve": "CVE-2026-64002",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64002"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()\n\nipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports\ntoo soon.\n\nOnly after unregister_net_sysctl_table() we can be sure no threads can possibly\nuse the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64002",
          "url": "https://www.suse.com/security/cve/CVE-2026-64002"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273774 for CVE-2026-64002",
          "url": "https://bugzilla.suse.com/1273774"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276496 for CVE-2026-64002",
          "url": "https://bugzilla.suse.com/1276496"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64002"
    },
    {
      "cve": "CVE-2026-64007",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64007"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: refresh tcphdr after skb_ensure_writable\n\nsynproxy_tstamp_adjust() rewrites the TCP timestamp option in place\nand then patches the TCP checksum via inet_proto_csum_replace4() on\nthe caller-supplied tcphdr pointer.  Both ipv4_synproxy_hook() and\nipv6_synproxy_hook() obtain that pointer with skb_header_pointer()\nbefore calling in, so it may either alias skb->head directly or\npoint at the caller's on-stack _tcph buffer.\n\nBetween obtaining the pointer and using it, the function calls\nskb_ensure_writable(skb, optend), which on a cloned or non-linear\nskb invokes pskb_expand_head() and frees the old skb->head.  After\nthat point the cached th is stale:\n\n    caller (ipv[46]_synproxy_hook)\n      th = skb_header_pointer(skb, ..., &_tcph)\n      synproxy_tstamp_adjust(skb, protoff, th, ...)\n        skb_ensure_writable(skb, optend)\n          pskb_expand_head()        /* kfree(old skb->head) */\n        ...\n        inet_proto_csum_replace4(&th->check, ...)\n                                    /* writes into freed head, or\n                                       into the caller's stack copy\n                                       leaving the on-wire checksum\n                                       stale */\n\nThe option bytes are written through skb->data and are fine; only\nthe checksum update goes through th and so lands in the wrong\nplace.  The result is either a write into freed slab memory or a\npacket leaving with a checksum that does not match its payload.\n\nFix by re-deriving th from skb->data + protoff immediately after\nskb_ensure_writable() succeeds, so the subsequent checksum update\ntargets the linear, writable header.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64007",
          "url": "https://www.suse.com/security/cve/CVE-2026-64007"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273105 for CVE-2026-64007",
          "url": "https://bugzilla.suse.com/1273105"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273108 for CVE-2026-64007",
          "url": "https://bugzilla.suse.com/1273108"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64007"
    },
    {
      "cve": "CVE-2026-64010",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64010"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()\n\nA race condition exists in the NFC LLCP connection state machine where\nthe connection acceptance packet (CC) can be processed concurrently with\nsocket release.  This can lead to a use-after-free of the socket object.\n\nWhen nfc_llcp_recv_cc() moves the socket from the connecting_sockets\nlist to the sockets list, it does so without holding the socket lock.\nIf llcp_sock_release() is executing concurrently, it might have already\nunlinked the socket and dropped its references, which can result in\nnfc_llcp_recv_cc() linking a freed socket into the live list.\n\nFix this by holding lock_sock() during the state transition and list\nmovement in nfc_llcp_recv_cc().  After acquiring the lock, check if\nthe socket is still hashed to ensure it hasn't already been unlinked\nand marked for destruction by the release path.  This aligns the locking\npattern with recv_hdlc() and recv_disc().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64010",
          "url": "https://www.suse.com/security/cve/CVE-2026-64010"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273882 for CVE-2026-64010",
          "url": "https://bugzilla.suse.com/1273882"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276494 for CVE-2026-64010",
          "url": "https://bugzilla.suse.com/1276494"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64010"
    },
    {
      "cve": "CVE-2026-64011",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64011"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: Fix use-after-free in llcp_sock_release()\n\nllcp_sock_release() unconditionally unlinks the socket from the local\nsockets list.  However, if the socket is still in connecting state, it\nis on the connecting list.\n\nFix this by checking the socket state and unlinking from the correct list.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64011",
          "url": "https://www.suse.com/security/cve/CVE-2026-64011"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273891 for CVE-2026-64011",
          "url": "https://bugzilla.suse.com/1273891"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276493 for CVE-2026-64011",
          "url": "https://bugzilla.suse.com/1276493"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64011"
    },
    {
      "cve": "CVE-2026-64015",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64015"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity/keys: fix missed RCU read section on lookup\n\nNicholas Carlini reports that the keyring code calls assoc_array_find()\nin find_key_to_update() without holding the RCU read lock, while the\nassoc_array_gc() code really is designed around removing the node from\nthe tree and then freeing it after an RCU grace-period.\n\nThe regular key handling doesn't see this because holding the keyring\nsemaphore hides any lifetime issues, but the persistent key handling\nuses a different model.\n\nInstead of extending the keyring locking, just do the simple RCU locking\nthat the assoc_array was designed for.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64015",
          "url": "https://www.suse.com/security/cve/CVE-2026-64015"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273762 for CVE-2026-64015",
          "url": "https://bugzilla.suse.com/1273762"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273823 for CVE-2026-64015",
          "url": "https://bugzilla.suse.com/1273823"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64015"
    },
    {
      "cve": "CVE-2026-64047",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64047"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring\n\nWhen an sk_msg scatterlist ring wraps (sg.end < sg.start),\ntls_push_record() chains the tail portion of the ring to the head\nusing sg_chain(). An extra entry in the sg array is reserved for\nthis:\n\n  struct sk_msg_sg {\n        [...]\n        /* The extra two elements:\n         * 1) used for chaining the front and sections when the list becomes\n         *    partitioned (e.g. end < start). The crypto APIs require the\n         *    chaining;\n         * 2) to chain tailer SG entries after the message.\n         */\n        struct scatterlist              data[MAX_MSG_FRAGS + 2];\n\nThe current code uses MAX_SKB_FRAGS + 1 as the ring size:\n\n    sg_chain(&msg_pl->sg.data[msg_pl->sg.start],\n             MAX_SKB_FRAGS - msg_pl->sg.start + 1,\n             msg_pl->sg.data);\n\nThis places the chain pointer at\n\n  sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =\n  &data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =\n  data[start + (MAX_SKB_FRAGS - start + 1) - 1] =\n  data[MAX_SKB_FRAGS]\n\ninstead of the true last entry. This is likely due to a \"race\" of\nthe commit under Fixes landing close to\ncommit 031097d9e079 (\"bpf: sk_msg, zap ingress queue on psock down\")\n\nConvert to ARRAY_SIZE and drop the data[start] / - start (as suggested\nby Sabrina).",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64047",
          "url": "https://www.suse.com/security/cve/CVE-2026-64047"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273060 for CVE-2026-64047",
          "url": "https://bugzilla.suse.com/1273060"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273061 for CVE-2026-64047",
          "url": "https://bugzilla.suse.com/1273061"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.4,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-64047"
    },
    {
      "cve": "CVE-2026-64048",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64048"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot\n\nOn the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is\nreserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()\npopulates V2 entries starting at index 1, so when no V1 device is\nselected slot 0 is left in its kzalloc()'ed state with ism_dev[0] ==\nNULL and ism_chid[0] == 0.\n\nsmc_v2_determine_accepted_chid() then matches the peer's CHID against\nthe array starting from index 0 using the CHID alone. A malicious\npeer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches\nthe empty slot, ini->ism_selected becomes 0, and the subsequent\nism_dev[0]->lgr_lock dereference in smc_conn_create() faults at\noffsetof(struct smcd_dev, lgr_lock) == 0x68:\n\n  BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0\n  Write of size 4 at addr 0000000000000068 by task exploit/144\n  Call Trace:\n   _raw_spin_lock_bh\n   smc_conn_create (net/smc/smc_core.c:1997)\n   __smc_connect (net/smc/af_smc.c:1447)\n   smc_connect (net/smc/af_smc.c:1720)\n   __sys_connect\n   __x64_sys_connect\n   do_syscall_64\n\nRequire ism_dev[i] to be non-NULL before accepting a CHID match.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64048",
          "url": "https://www.suse.com/security/cve/CVE-2026-64048"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273484 for CVE-2026-64048",
          "url": "https://bugzilla.suse.com/1273484"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273513 for CVE-2026-64048",
          "url": "https://bugzilla.suse.com/1273513"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64048"
    },
    {
      "cve": "CVE-2026-64098",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64098"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: use uninterruptible resv lock for plane updates\n\nvirtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock\nthe framebuffer BO's dma_resv via virtio_gpu_array_lock_resv() and\nignore its return value. The function can fail with -EINTR from\ndma_resv_lock_interruptible() (signal during lock wait) or with\n-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),\nleaving the resv lock not held. The queue path then walks the object\narray and calls dma_resv_add_fence(), which requires the lock held;\nwith lockdep enabled this trips dma_resv_assert_held():\n\n  WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840\n  Call Trace:\n   virtio_gpu_array_add_fence\n   virtio_gpu_queue_ctrl_sgs\n   virtio_gpu_queue_fenced_ctrl_buffer\n   virtio_gpu_cursor_plane_update\n   drm_atomic_helper_commit_planes\n   drm_atomic_helper_commit_tail\n   commit_tail\n   drm_atomic_helper_commit\n   drm_atomic_commit\n   drm_atomic_helper_update_plane\n   __setplane_atomic\n   drm_mode_cursor_universal\n   drm_mode_cursor_common\n   drm_mode_cursor_ioctl\n   drm_ioctl\n   __x64_sys_ioctl\n\nBeyond the WARN, mutating the dma_resv fence list without the lock\nraces with concurrent readers/writers and can corrupt the list.\n\nBoth call sites run inside the .atomic_update plane callback, which\nDRM atomic helpers do not allow to fail (by the time it runs, the\ncommit has been signed off to userspace and there is no clean\nrollback path). Moving the lock acquisition to .prepare_fb was\nrejected because the broader lock scope deadlocks against other BO\nlocking paths in the same atomic commit.\n\nIntroduce virtio_gpu_lock_one_resv_uninterruptible() that uses\ndma_resv_lock() instead of dma_resv_lock_interruptible(). This\neliminates the -EINTR failure mode -- the realistic syzbot trigger\n-- without extending the lock hold across the commit. The helper\nlocks a single BO and rejects nents > 1 with -EINVAL; both fix\nsites lock exactly one BO.\n\nUse it from virtio_gpu_cursor_plane_update() and\nvirtio_gpu_resource_flush(); check the return value to handle the\nremaining -ENOMEM case from dma_resv_reserve_fences() by freeing\nthe objs and skipping the plane update for that frame. The\nframebuffer BOs touched here are not shared with other contexts\nand lock contention is expected to be brief, so the loss of\nsignal-interruptibility is acceptable.\n\nOther callers of virtio_gpu_array_lock_resv() (the ioctl paths)\ncontinue to use the interruptible variant.\n\nThe bug was reported by syzbot, triggered via fault injection\n(fail_nth) on the DRM_IOCTL_MODE_CURSOR path, which forces the\n-ENOMEM branch in dma_resv_reserve_fences().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64098",
          "url": "https://www.suse.com/security/cve/CVE-2026-64098"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273488 for CVE-2026-64098",
          "url": "https://bugzilla.suse.com/1273488"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273528 for CVE-2026-64098",
          "url": "https://bugzilla.suse.com/1273528"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64098"
    },
    {
      "cve": "CVE-2026-64109",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64109"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix UAF read of tail->len in unix_stream_data_wait()\n\nunix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without\nholding any lock that prevents SKBs on that queue from being dequeued and\nfreed.\nThis has been the case since commit 79f632c71bea (\"unix/stream: fix\npeeking with an offset larger than data in queue\").\nThe first consequence of this is that the pointer comparison\n`tail != last` can be false even if `last` semantically refers to an\nalready-freed SKB while `tail` is a new SKB allocated at the same address;\nwhich can cause unix_stream_data_wait() to wrongly keep blocking after new\ndata has arrived, but only in a weird scenario where a peeking recv() and\na normal recv() on the same socket are racing, which is probably not a\nreal problem.\n\nBut since commit 2b514574f7e8 (\"net: af_unix: implement splice for stream\naf_unix sockets\"), `tail` is actually dereferenced, which can cause UAF in\nthe following race scenario (where test_setup() runs single-threaded,\nand afterwards, test_thread1() and test_thread2() run concurrently in\ntwo threads:\n```\nstatic int socks[2];\nvoid test_setup(void) {\n  socketpair(AF_UNIX, SOCK_STREAM, 0, socks);\n  send(socks[1], \"A\", 1, 0);\n  int peekoff = 1;\n  setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff));\n}\nvoid test_thread1(void) {\n  char dummy;\n  recv(socks[0], &dummy, 1, MSG_PEEK);\n}\nvoid test_thread2(void) {\n  char dummy;\n  recv(socks[0], &dummy, 1, 0);\n  shutdown(socks[1], SHUT_WR);\n}\n```\n\nwhen racing like this:\n```\nthread1                       thread2\nunix_stream_read_generic\n  mutex_lock(&u->iolock)\n  skb_peek(&sk->sk_receive_queue)\n  skb_peek_next(skb, &sk->sk_receive_queue)\n  mutex_unlock(&u->iolock)\n                              unix_stream_read_generic\n                                unix_state_lock(sk)\n                                skb_peek(&sk->sk_receive_queue)\n                                unix_state_unlock(sk)\n  unix_stream_data_wait\n    unix_state_lock(sk)\n    tail = skb_peek_tail(&sk->sk_receive_queue)\n                                spin_lock(&sk->sk_receive_queue.lock)\n                                __skb_unlink(skb, &sk->sk_receive_queue)\n                                spin_unlock(&sk->sk_receive_queue.lock)\n                                consume_skb(skb) [frees the SKB]\n    `tail != last`: false\n    `tail`: true\n    `tail->len != last_len` ***UAF***\n```\n\nFix the UAF by removing the read of tail->len; checking tail->len would\nonly make sense if SKBs in the receive queue of a UNIX socket could grow,\nwhich can no longer happen.\n\nKuniyuki explained:\n\n> When commit 869e7c62486e (\"net: af_unix: implement stream sendpage\n> support\") added sendpage() support, data could be appended to the last\n> skb in the receiver's queue.\n>\n> That's why we needed to check if the length of the last skb was changed\n> while waiting for new data in unix_stream_data_wait().\n>\n> However, commit a0dbf5f818f9 (\"af_unix: Support MSG_SPLICE_PAGES\") and\n> commit 57d44a354a43 (\"unix: Convert unix_stream_sendpage() to use\n> MSG_SPLICE_PAGES\") refactored sendmsg(), and now data is always added\n> to a new skb.\n\nThat means this fix is not suitable for kernels before 6.5.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64109",
          "url": "https://www.suse.com/security/cve/CVE-2026-64109"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273748 for CVE-2026-64109",
          "url": "https://bugzilla.suse.com/1273748"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273829 for CVE-2026-64109",
          "url": "https://bugzilla.suse.com/1273829"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64109"
    },
    {
      "cve": "CVE-2026-64114",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64114"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: raw: reject IP_HDRINCL packets with ihl < 5\n\nraw_send_hdrinc() validates that the caller-supplied IPv4 header\nfits within the message length:\n\n    iphlen = iph->ihl * 4;\n    err = -EINVAL;\n    if (iphlen > length)\n        goto error_free;\n\n    if (iphlen >= sizeof(*iph)) {\n        /* fix up saddr, tot_len, id, csum, transport_header */\n    }\n\nIt does not, however, reject ihl < 5.  For such a packet the\n\"if (iphlen >= sizeof(*iph))\" branch is skipped, leaving the\ncrafted iphdr untouched, but the packet is still handed to\n__ip_local_out() and onward.  Downstream consumers that read\niph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in\nparticular subtracts sizeof(struct iphdr) from top_iph->ihl * 4\nand passes the (signed-int-negative, then cast to size_t)\nresult to memcpy(), producing an OOB access of length close to\nSIZE_MAX and a host kernel panic.\n\nAn IPv4 header with ihl < 5 is malformed by definition (RFC 791:\n\"Internet Header Length is the length of the internet header in\n32 bit words ... Note that the minimum value for a correct header\nis 5.\").  The kernel should not be willing to inject such a\npacket into its own output path.\n\nReject \"iphlen < sizeof(*iph)\" alongside the existing\n\"iphlen > length\" check.  This matches the principle that locally\nconstructed packets that re-enter the IP stack must pass the same\nbasic sanity tests that a foreign packet would be subjected to.\n\nOnce this lands, the \"if (iphlen >= sizeof(*iph))\" wrapper around\nthe fixup branch becomes redundant; left in place to keep the\npatch minimal and backport-friendly.  A follow-up can unwrap it.\n\nNote that commit 86f4c90a1c5c (\"ipv4, ipv6: ensure raw socket\nmessage is big enough to hold an IP header\") ensures the message\nbuffer is large enough to hold an iphdr, but does not constrain\nthe self-reported iph->ihl.\n\nReachability: the malformed packet source is any caller with\nCAP_NET_RAW, including an unprivileged process in a user+net\nnamespace on a kernel with CONFIG_USER_NS=y.  The reproduced AH\ncrash also requires a matching xfrm AH policy on the outgoing\nroute; a container granted CAP_NET_ADMIN can install that state\nand policy in its netns.  Loopback bypasses xfrm_output, so the\ntrigger uses a real netdev.\n\nReproduced on UML + KASAN: kernel-mode fault at addr 0x0 with\nmemcpy_orig at the crash site.  Same shape reproduces inside a\nrootless Docker container with --cap-add NET_ADMIN on a stock\ndistro kernel.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64114",
          "url": "https://www.suse.com/security/cve/CVE-2026-64114"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273742 for CVE-2026-64114",
          "url": "https://bugzilla.suse.com/1273742"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273833 for CVE-2026-64114",
          "url": "https://bugzilla.suse.com/1273833"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64114"
    },
    {
      "cve": "CVE-2026-64115",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64115"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/vmci: fix UAF when peer resets connection during handshake\n\nvmci_transport_recv_connecting_server() returned err = 0 for a peer\nRST in its default switch arm:\n\n\terr = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL;\n\nThat made vmci_transport_recv_listen() skip vsock_remove_pending(),\nleaving the pending socket on the listener's pending_links with\nsk_state = TCP_CLOSE while destroy: still dropped the explicit\nreference taken before schedule_delayed_work().\n\nOne second later vsock_pending_work() observed is_pending=true and\nperformed full cleanup: vsock_remove_pending() then the two trailing\nsock_put(sk) calls -- the first reached refcount 0 and __sk_freed\nthe socket, and the second wrote into the freed object:\n\n  BUG: KASAN: slab-use-after-free in refcount_warn_saturate\n  Write of size 4 at addr ffff88800b1cac80 by task kworker\n  Workqueue: events vsock_pending_work\n\nTreat peer RST like any other unexpected packet type (err = -EINVAL).\nAll destroy: arms now return err < 0, so vmci_transport_recv_listen()\nremoves pending from pending_links synchronously and\nvsock_pending_work() takes the is_pending=false / !rejected branch,\ndropping only its own work reference.  This also closes the\nmulti-packet race Sashiko reported on v2: pending is removed from\nthe list before any subsequent packet can find it.\n\nThe pre-existing sk_acceptq_removed() gap on the err < 0 path of\nvmci_transport_recv_listen() that Sashiko also noted is not\nintroduced or changed by this patch.\n\nTested on lts-6.12.79 with KASAN: 52/100 unpatched -> 0/100 patched.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64115",
          "url": "https://www.suse.com/security/cve/CVE-2026-64115"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273745 for CVE-2026-64115",
          "url": "https://bugzilla.suse.com/1273745"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273835 for CVE-2026-64115",
          "url": "https://bugzilla.suse.com/1273835"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64115"
    },
    {
      "cve": "CVE-2026-64137",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64137"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: require net admin for CIFS SWN netlink\n\nCIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command.  The\nintended sender is the cifs.witness helper, but the generic-netlink\noperation currently has no capability flag, so any local process can send\nRESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness\nhandler.\n\nThe same family exposes CIFS_GENL_MCGRP_SWN without multicast-group\ncapability flags.  Register messages sent to that group include the witness\nregistration id and, for NTLM-authenticated mounts, the username, domain,\nand password attributes copied from the CIFS session.  An unprivileged\nlocal process should not be able to join that group and receive those\nmessages.\n\nRequire CAP_NET_ADMIN for incoming SWN_NOTIFY commands with\nGENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for\njoining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN.  The\ncifs.witness service runs with the privileges needed for both operations.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64137",
          "url": "https://www.suse.com/security/cve/CVE-2026-64137"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273966 for CVE-2026-64137",
          "url": "https://bugzilla.suse.com/1273966"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273979 for CVE-2026-64137",
          "url": "https://bugzilla.suse.com/1273979"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64137"
    },
    {
      "cve": "CVE-2026-64266",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64266"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: re-lock request before returning from fuse_ref_folio()\n\nfuse_ref_folio() unlocks the request but does not re-lock it before\nreturning. fuse_chan_abort() can end the request and the async end\ncallback (eg fuse_writepage_free()) can free the args while the\nsubsequent copy chain logic after fuse_ref_folio() accesses them,\nleading to use-after-free issues.\n\nFix this by locking the request in fuse_ref_folio() before returning.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64266",
          "url": "https://www.suse.com/security/cve/CVE-2026-64266"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273555 for CVE-2026-64266",
          "url": "https://bugzilla.suse.com/1273555"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-64266"
    },
    {
      "cve": "CVE-2026-64268",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64268"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: bound Read Response placement to the RREAD length\n\nIn drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each\ninbound Read Response DDP segment at sge->laddr + wqe->processed and then\naccumulates wqe->processed, but it never checks the running total against\nthe sink buffer length on continuation segments. siw_check_sge() resolves\nand validates the sink memory only on the first fragment (the if (!*mem)\nbranch), and siw_rresp_check_ntoh() compares the cumulative length against\nwqe->bytes only on the final segment (the !frx->more_ddp_segs guard).\n\nA connected siw peer that answers an outstanding RREAD with Read Response\nsegments that keep the DDP Last flag clear, carrying more total payload\nthan the RREAD requested, drives wqe->processed past the validated sink\nbuffer; the next siw_rx_data() call writes out of bounds at\nsge->laddr + wqe->processed. siw runs iWARP over ordinary routable TCP,\nso the peer is the remote end of an established RDMA connection and needs\nno local privilege.\n\nBound every segment before placement, exactly as siw_proc_send() and\nsiw_proc_write() already do for their tagged and untagged paths, and\nterminate the connection with a base-or-bounds DDP error when the\nRead Response would overrun the sink buffer.\n\nThis is the second receive-path length fix for this file. A separate\nchange rejects an MPA FPDU length that underflows the per-fragment\nremainder in the header decode; that guard does not cover this case,\nbecause here each individual segment length is self-consistent and only\nthe accumulated placement offset overruns the buffer.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64268",
          "url": "https://www.suse.com/security/cve/CVE-2026-64268"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273276 for CVE-2026-64268",
          "url": "https://bugzilla.suse.com/1273276"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273278 for CVE-2026-64268",
          "url": "https://bugzilla.suse.com/1273278"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "critical"
        }
      ],
      "title": "CVE-2026-64268"
    },
    {
      "cve": "CVE-2026-64304",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64304"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - validate RSA CRT component lengths\n\nThe generic RSA key parser (rsa_helper.c) bounds each CRT component (p,\nq, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt()\nallocates half-size DMA buffers (key_sz / 2) and right-aligns each\ncomponent with:\n\n    memcpy(dst + half_key_sz - len, src, len)\n\nWhen a CRT component is larger than half_key_sz the subtraction\nunderflows and memcpy writes past the DMA buffer, causing memory\ncorruption.\n\nAdd a len > half_key_sz check next to the existing !len check for each\nof the five CRT components so the driver falls back to the non-CRT path\ninstead of writing out of bounds.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64304",
          "url": "https://www.suse.com/security/cve/CVE-2026-64304"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273944 for CVE-2026-64304",
          "url": "https://bugzilla.suse.com/1273944"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273983 for CVE-2026-64304",
          "url": "https://bugzilla.suse.com/1273983"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64304"
    },
    {
      "cve": "CVE-2026-64355",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64355"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject fragmented frames in devmap\n\nDevmap broadcast redirects clone the packet for all but the last\ndestination.\n\nFor native XDP, that clone path copies only the linear xdp_frame data,\nwhile fragmented frames keep skb_shared_info in tailroom outside the\nlinear area. Cloning such a frame leaves XDP_FLAGS_HAS_FRAGS set but\nwithout valid frag metadata, and the later free path can interpret\nuninitialized tail data as skb_shared_info, leading to an out-of-bounds\naccess during frame return.\n\nReject fragmented native XDP frames in dev_map_enqueue_clone().\n\nAdd the same restriction to the generic XDP clone path in\ndev_map_redirect_clone(). Generic XDP represents fragmented packets as\nnonlinear skbs, and rejecting them here keeps clone-based broadcast\nsupport aligned between native and generic XDP.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64355",
          "url": "https://www.suse.com/security/cve/CVE-2026-64355"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273422 for CVE-2026-64355",
          "url": "https://bugzilla.suse.com/1273422"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273423 for CVE-2026-64355",
          "url": "https://bugzilla.suse.com/1273423"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64355"
    },
    {
      "cve": "CVE-2026-64423",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64423"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: remove multicast group from hash table on device destruction\n\nWhen a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through\nthe multicast list and calls ip_ma_put() on each membership, scheduling\nthem for RCU reclamation. However, they are not unlinked from the device's\nmulticast hash table (mc_hash).\n\nSince the device remains published in dev->ip_ptr until after\nip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash\ncan still locate and access the multicast group after its refcount is\ndecremented. If the RCU callback runs and frees the group while a reader is\naccessing it, a use-after-free occurs.\n\nFix this by unlinking the multicast group from mc_hash using\nip_mc_hash_remove() before scheduling it for reclamation.\n\nBUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0\nRead of size 4 at addr ffff888009bf1408 by task mausezahn/2276\n\nCall Trace:\n <IRQ>\n dump_stack_lvl+0x67/0x90\n print_report+0x175/0x7c0\n kasan_report+0x147/0x180\n ip_check_mc_rcu+0x149/0x3f0\n udp_v4_early_demux+0x36d/0x12d0\n ip_rcv_finish_core+0xb8b/0x1390\n ip_rcv_finish+0x54/0x120\n NF_HOOK+0x213/0x2b0\n __netif_receive_skb+0x126/0x340\n process_backlog+0x4f2/0xf00\n __napi_poll+0x92/0x2c0\n net_rx_action+0x583/0xc60\n handle_softirqs+0x236/0x7f0\n do_softirq+0x57/0x80\n </IRQ>\n\nAllocated by task 2239:\n kasan_save_track+0x3e/0x80\n __kasan_kmalloc+0x72/0x90\n ____ip_mc_inc_group+0x31a/0xa40\n __ip_mc_join_group+0x334/0x3f0\n do_ip_setsockopt+0x16fa/0x2010\n ip_setsockopt+0x3f/0x90\n do_sock_setsockopt+0x1ad/0x300\n\nFreed by task 0:\n kasan_save_track+0x3e/0x80\n kasan_save_free_info+0x40/0x50\n __kasan_slab_free+0x3a/0x60\n __rcu_free_sheaf_prepare+0xd4/0x220\n rcu_free_sheaf+0x36/0x190\n rcu_core+0x8d9/0x12f0\n handle_softirqs+0x236/0x7f0",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64423",
          "url": "https://www.suse.com/security/cve/CVE-2026-64423"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274274 for CVE-2026-64423",
          "url": "https://bugzilla.suse.com/1274274"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275458 for CVE-2026-64423",
          "url": "https://bugzilla.suse.com/1275458"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64423"
    },
    {
      "cve": "CVE-2026-64450",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64450"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix out-of-bounds read in broadcast Gap ACK blocks\n\nA broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its\ndata area. tipc_get_gap_ack_blks() only verifies that the record's len\nfield is self-consistent with its ugack_cnt/bgack_cnt counts\n(sz == struct_size(p, gacks, ugack_cnt + bgack_cnt)); it does not check\nthat the record actually fits in the message data area, msg_data_sz().\n\nThe unicast caller tipc_link_proto_rcv() bounds it (\"if (glen > dlen)\nbreak;\"), but the broadcast caller tipc_bcast_sync_rcv() discards the\nreturned size, so tipc_link_advance_transmq() copies the record off the\nreceive skb with an attacker-controlled count:\n\n\tthis_ga = kmemdup(ga, struct_size(ga, gacks, ga->bgack_cnt),\n\t\t\t  GFP_ATOMIC);\n\nA TIPC neighbour that negotiated TIPC_GAP_ACK_BLOCK triggers it with one\nordinary broadcast STATE_MSG (msg_bc_ack_invalid() clear), sized so its\ndata area is short, carrying a Gap ACK record with len = 0x400,\nbgack_cnt = 0xff and ugack_cnt = 0. len then equals\nstruct_size(p, gacks, 255), so the consistency check passes and ga is\nnon-NULL; kmemdup() reads struct_size(ga, gacks, 255) = 1024 bytes out\nof the much smaller skb:\n\n  BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x48/0x60\n  Read of size 1024 at addr ffff0000c7030d38 by task poc864/69\n  Call trace:\n   kmemdup_noprof+0x48/0x60\n   tipc_link_advance_transmq+0x86c/0xb80\n   tipc_link_bc_ack_rcv+0x19c/0x1e0\n   tipc_bcast_sync_rcv+0x1c4/0x2c4\n   tipc_rcv+0x85c/0x1340\n   tipc_l2_rcv_msg+0xac/0x104\n  The buggy address belongs to the object at ffff0000c7030d00\n   which belongs to the cache skbuff_small_head of size 704\n  The buggy address is located 56 bytes inside of\n   allocated 704-byte region [ffff0000c7030d00, ffff0000c7030fc0)\n\nThe copied-out bytes are subsequently consumed as gap/ack values, but\nthe read is already out of bounds at the kmemdup() regardless of how\nthey are used.\n\nThe unicast STATE path drops such a message: \"if (glen > dlen) break;\"\nskips the rest of STATE_MSG handling and the skb is freed. Make the\nbroadcast path drop it too. tipc_bcast_sync_rcv() now bounds the record\nagainst msg_data_sz() and, when it does not fit, reports it back through\ntipc_node_bc_sync_rcv() to tipc_rcv() so the skb is discarded rather than\nprocessed. ga is not cleared on this path: ga == NULL already means\n\"legacy peer without Selective ACK\", a distinct legitimate state.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64450",
          "url": "https://www.suse.com/security/cve/CVE-2026-64450"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273523 for CVE-2026-64450",
          "url": "https://bugzilla.suse.com/1273523"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274291 for CVE-2026-64450",
          "url": "https://bugzilla.suse.com/1274291"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64450"
    },
    {
      "cve": "CVE-2026-64481",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64481"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs35l41: Fix firmware load work teardown\n\ncs35l41_hda creates ALSA controls whose private data points at the\ncs35l41_hda object. The firmware load control can also queue\nfw_load_work.\n\nThose controls are not removed on component unbind, and device remove\nonly cancels fw_load_work through cs35l41_remove_dsp(). That helper is\nskipped when halo_initialized is false. With firmware_autostart\ndisabled, a firmware load can be requested before the DSP has been\ninitialized. If the component or device is removed before the queued\nwork runs, the worker can run after teardown and dereference driver\nstate that is no longer valid.\n\nTrack the created controls and remove them on unbind so no new control\ncallback can reach the driver data or queue more work. Then cancel\nfw_load_work to drain any request that was already queued. Also cancel\nthe work unconditionally during device remove before runtime PM teardown.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64481",
          "url": "https://www.suse.com/security/cve/CVE-2026-64481"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274547 for CVE-2026-64481",
          "url": "https://bugzilla.suse.com/1274547"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276490 for CVE-2026-64481",
          "url": "https://bugzilla.suse.com/1276490"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64481"
    },
    {
      "cve": "CVE-2026-64541",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64541"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket\n\nsmc_cdc_rx_handler() looks up the connection by token under the link\ngroup's conns_lock, drops the lock, and then dereferences conn and the\nsmc_sock derived from it, ending in sock_hold(&smc->sk) inside\nsmc_cdc_msg_recv(). No reference is held across the lock release.\n\nThe only reference pinning the socket while the connection is\ndiscoverable in the link group is taken in smc_lgr_register_conn()\n(sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both\nunder conns_lock. Once the handler drops conns_lock, a concurrent\nclose() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn()\ncan drop that reference and free the smc_sock, so the handler's later\nsock_hold() runs on freed memory:\n\n  WARNING: lib/refcount.c:25 at refcount_warn_saturate\n  Workqueue: rxe_wq do_work\n   refcount_warn_saturate (lib/refcount.c:25)\n   smc_cdc_msg_recv (net/smc/smc_cdc.c:430)\n   smc_cdc_rx_handler (net/smc/smc_cdc.c:502)\n   smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445)\n   tasklet_action_common (kernel/softirq.c:938)\n   handle_softirqs (kernel/softirq.c:622)\n  Kernel panic - not syncing: panic_on_warn set\n\nOnly SMC-R is affected. The SMC-D receive tasklet is stopped by\ntasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection\nis unregistered, so it cannot run concurrently with the free.\n\nTake the socket reference while still holding conns_lock, so the\nregistration reference can no longer be the last one, and drop it once\nthe handler is done.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64541",
          "url": "https://www.suse.com/security/cve/CVE-2026-64541"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273303 for CVE-2026-64541",
          "url": "https://bugzilla.suse.com/1273303"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273308 for CVE-2026-64541",
          "url": "https://bugzilla.suse.com/1273308"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64541"
    },
    {
      "cve": "CVE-2026-64543",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64543"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free of the discoverer in tipc_disc_rcv()\n\nbearer_disable() frees b->disc with tipc_disc_delete()'s plain kfree(),\nbut tipc_disc_rcv() still dereferences b->disc in RX softirq under\nrcu_read_lock() (tipc_udp_recv -> tipc_rcv -> tipc_disc_rcv).\n\nL2 bearers are safe thanks to the synchronize_net() in\ntipc_disable_l2_media(), but the UDP bearer defers that call to the\ncleanup_bearer() workqueue, so the discoverer is freed with no grace\nperiod:\n\n BUG: KASAN: slab-use-after-free in tipc_disc_rcv (net/tipc/discover.c:149)\n Read of size 8 at addr ffff88802348b728 by task poc_tipc/184\n <IRQ>\n  tipc_disc_rcv (net/tipc/discover.c:149)\n  tipc_rcv (net/tipc/node.c:2126)\n  tipc_udp_recv (net/tipc/udp_media.c:391)\n  udp_rcv (net/ipv4/udp.c:2643)\n  ip_local_deliver_finish (net/ipv4/ip_input.c:241)\n </IRQ>\n Freed by task 181:\n  kfree (mm/slub.c:6565)\n  bearer_disable (net/tipc/bearer.c:418)\n  tipc_nl_bearer_disable (net/tipc/bearer.c:1001)\n\nThe bearer is freed with kfree_rcu(); free the discoverer the same way.\nAdd an rcu_head to struct tipc_discoverer and free it and its skb from an\nRCU callback.\n\nBecause the RCU callback (tipc_disc_free_rcu) lives in module text, a\ncall_rcu() that is still pending when the tipc module is unloaded would\ninvoke a freed function. Add an rcu_barrier() to tipc_exit() after the\nbearer subsystem has been torn down, so all pending discoverer callbacks\nhave run before the module text goes away.\n\nReachable from an unprivileged user namespace: the TIPCv2 genl family is\nnetnsok and its bearer commands have no GENL_ADMIN_PERM. Needs CONFIG_TIPC\nand CONFIG_TIPC_MEDIA_UDP.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64543",
          "url": "https://www.suse.com/security/cve/CVE-2026-64543"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273311 for CVE-2026-64543",
          "url": "https://bugzilla.suse.com/1273311"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273313 for CVE-2026-64543",
          "url": "https://bugzilla.suse.com/1273313"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64543"
    },
    {
      "cve": "CVE-2026-64556",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64556"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Detach event groups during remove_on_exec\n\nperf_event_remove_on_exec() removes events by calling\nperf_event_exit_event(). For top-level events, this removes the event from\nthe context with DETACH_EXIT only.\n\nThis can leave inconsistent group state when a removed event is a group\nleader and the group contains siblings without remove_on_exec. If the group\nwas active, the surviving siblings can remain active and attached to the\nremoved leader's sibling list, but are no longer represented by a valid\ngroup leader on the PMU context active lists.\n\nA later close of the removed leader uses DETACH_GROUP and can promote the\nstill-active siblings from this stale group state. The next schedule-in can\nthen add an already-linked active_list entry again, corrupting the PMU\ncontext active list.\n\nWith DEBUG_LIST enabled, this is caught as a list_add double-add in\nmerge_sched_in().\n\nFix this by detaching group relationships when remove_on_exec removes an\nevent. This preserves the existing task-exit and revoke behavior, while\nensuring surviving siblings are ungrouped before the removed event leaves\nthe context.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64556",
          "url": "https://www.suse.com/security/cve/CVE-2026-64556"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273251 for CVE-2026-64556",
          "url": "https://bugzilla.suse.com/1273251"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274648 for CVE-2026-64556",
          "url": "https://bugzilla.suse.com/1274648"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64556"
    },
    {
      "cve": "CVE-2026-64562",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64562"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nVMX: Hide shadow VMCS right after VMCLEAR\n\nfree_nested() frees the shadow VMCS while vmcs01 still points to it. But\nbecause it is asynchronous with respect to loaded_vmcs_clear(), the vCPU\nmight migrate before the pointer is cleared and __loaded_vmcs_clear()\nmay then execute VMCLEAR.\n\nThe VMCS needs to stay attached until its explicit VMCLEAR completes, but\nthen it can be hidden and the page safely freed.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64562",
          "url": "https://www.suse.com/security/cve/CVE-2026-64562"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273930 for CVE-2026-64562",
          "url": "https://bugzilla.suse.com/1273930"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273987 for CVE-2026-64562",
          "url": "https://bugzilla.suse.com/1273987"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64562"
    },
    {
      "cve": "CVE-2026-64563",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64563"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: clear stale iter->p on table restart\n\nrhashtable_walk_start_check() has two restart paths when resuming a walk.\nWhen iter->walker.tbl is valid, it re-validates iter->p against the table\nand sets iter->p = NULL if the object is gone.  When iter->walker.tbl is\nNULL (table was freed during resize), it resets slot and skip but forgets\nto clear iter->p.\n\nrhashtable_walk_next() then dereferences the stale iter->p, reading\nfreed memory.  This is a use-after-free.\n\nAny caller that does multi-fragment rhashtable walks across\nwalk_stop/walk_start boundaries is affected.  Concrete cases include\nnetlink_diag (__netlink_diag_dump in net/netlink/diag.c) and TIPC\n(tipc_nl_sk_walk in net/tipc/socket.c).\n\nCrash stack (netlink_diag):\n  BUG: KASAN: slab-use-after-free in rhashtable_walk_next+0x365/0x3c0\n  Read of size 8 at addr ffff88801a9d2438 (freed kmalloc-2k, offset 1080)\n  Call Trace:\n   rhashtable_walk_next+0x365/0x3c0 (lib/rhashtable.c:1016)\n   __netlink_diag_dump+0x160/0x760 (net/netlink/diag.c:122)\n   netlink_diag_dump+0xc2/0x240\n   netlink_dump+0x5bc/0x1270\n   netlink_recvmsg+0x7a3/0x980\n   sock_recvmsg+0x1bc/0x200\n   __sys_recvfrom+0x1d4/0x2c0",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64563",
          "url": "https://www.suse.com/security/cve/CVE-2026-64563"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273995 for CVE-2026-64563",
          "url": "https://bugzilla.suse.com/1273995"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273996 for CVE-2026-64563",
          "url": "https://bugzilla.suse.com/1273996"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64563"
    },
    {
      "cve": "CVE-2026-64572",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64572"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: fib: free fib_alias with kfree_rcu() on insert error path\n\nfib_table_insert() publishes new_fa into the leaf's fa_list with\nfib_insert_alias() before calling the fib entry notifiers. When a\nnotifier fails, the error path removes new_fa with fib_remove_alias()\n(hlist_del_rcu) and frees it right away with kmem_cache_free().\n\nfib_table_lookup() walks that list under rcu_read_lock() only, so a\nconcurrent lookup that already reached new_fa keeps reading it after the\nfree:\n\n BUG: KASAN: slab-use-after-free in fib_table_lookup (net/ipv4/fib_trie.c:1601)\n Read of size 1 at addr ffff88810676d4eb by task exploit/297\n Call Trace:\n  fib_table_lookup (net/ipv4/fib_trie.c:1601)\n  ip_route_output_key_hash_rcu (net/ipv4/route.c:2814)\n  ip_route_output_key_hash (net/ipv4/route.c:2705)\n  __ip4_datagram_connect (net/ipv4/datagram.c:49)\n  udp_connect (net/ipv4/udp.c:2144)\n  __sys_connect (net/socket.c:2167)\n  __x64_sys_connect (net/socket.c:2173)\n  do_syscall_64\n  entry_SYSCALL_64_after_hwframe\n which belongs to the cache ip_fib_alias of size 56\n\nTriggering the error path needs CAP_NET_ADMIN and a registered fib\nnotifier that can reject a route; a netdevsim device whose IPv4 FIB\nresource is exhausted is enough.\n\nFree new_fa with alias_free_mem_rcu(), as fib_table_delete() already\ndoes for a fib_alias removed from the trie.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64572",
          "url": "https://www.suse.com/security/cve/CVE-2026-64572"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274014 for CVE-2026-64572",
          "url": "https://bugzilla.suse.com/1274014"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274015 for CVE-2026-64572",
          "url": "https://bugzilla.suse.com/1274015"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64572"
    },
    {
      "cve": "CVE-2026-64581",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64581"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix sk_dst_cache double-free in xfrm_user_policy()\n\nxfrm_user_policy() clears the socket dst cache with __sk_dst_reset(),\ni.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with\nrcu_dereference_protected(), stores NULL and dst_release()s the old dst.\nThat is only safe if no other thread modifies sk_dst_cache concurrently.\n\nFor a connected UDP socket that does not hold: the transmit fast path\n(udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly\nwith an atomic xchg(). A per-socket policy change racing a send can make\nboth sides observe the same old dst and each dst_release() it, dropping\nthe socket's single reference twice and freeing the xfrm_dst bundle while\nit is still referenced:\n\n  BUG: KASAN: slab-use-after-free in dst_release\n  Write of size 4 at addr ffff88801897b6c0 by task exploit/155\n  Call Trace:\n   ...\n   dst_release (... ./include/linux/rcuref.h:109)\n   xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053)\n   do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347)\n   ip_setsockopt (net/ipv4/ip_sockglue.c:1417)\n   do_sock_setsockopt (net/socket.c:2368)\n   __sys_setsockopt (net/socket.c:2393)\n   __x64_sys_setsockopt (net/socket.c:2396)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n\nReachable by an unprivileged user via a user+network namespace.\n\nUse the atomic sk_dst_reset() so the cache is cleared and released with a\nsingle xchg(): whichever side wins releases the dst once, the other sees\nNULL and does nothing. Behaviour is otherwise unchanged.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64581",
          "url": "https://www.suse.com/security/cve/CVE-2026-64581"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274041 for CVE-2026-64581",
          "url": "https://bugzilla.suse.com/1274041"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274042 for CVE-2026-64581",
          "url": "https://bugzilla.suse.com/1274042"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-64581"
    },
    {
      "cve": "CVE-2026-64593",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-64593"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not trim a device which is not writeable\n\n[BUG]\nThere is a bug report that btrfs/242 can randomly fail with the\nfollowing NULL pointer dereference:\n\n  run fstests btrfs/242 at 2026-06-01 10:25:08\n  BTRFS: device fsid d4d7f234-487c-4787-88e4-47a8b68c9874 devid 1 transid 9 /dev/sdc (8:32) scanned by mount (122609)\n  BTRFS info (device sdc): first mount of filesystem d4d7f234-487c-4787-88e4-47a8b68c9874\n  BTRFS info (device sdc): using crc32c checksum algorithm\n  BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing\n  BTRFS warning (device sdc): devid 2 uuid fbe72d72-3272-482d-80fb-ab88ed398192 is missing\n  BTRFS info (device sdc): allowing degraded mounts\n  BTRFS info (device sdc): turning on async discard\n  BTRFS info (device sdc): enabling free space tree\n  Unable to handle kernel NULL pointer dereference at virtual address 0000000000000018\n  user pgtable: 4k pages, 48-bit VAs, pgdp=000000013fd6b000\n  CPU: 4 UID: 0 PID: 122625 Comm: fstrim Not tainted 7.0.10-2-default #1 PREEMPT(full) openSUSE Tumbleweed e9a5f6b24978fba3bf015a992f865837fdfff3dd\n  Hardware name: QEMU KVM Virtual Machine, BIOS edk2-20250812-19.fc42 08/12/2025\n  pstate: 01400005 (nzcv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n  pc : btrfs_trim_fs+0x34c/0xa00 [btrfs]\n  lr : btrfs_trim_fs+0x1f0/0xa00 [btrfs]\n  Call trace:\n   btrfs_trim_fs+0x34c/0xa00 [btrfs f02c1d570ceea621c69d302ba75dd61868083840] (P)\n   btrfs_ioctl_fitrim+0xe8/0x178 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]\n   btrfs_ioctl+0xdd4/0x2bd8 [btrfs f02c1d570ceea621c69d302ba75dd61868083840]\n   __arm64_sys_ioctl+0xac/0x108\n   invoke_syscall.constprop.0+0x5c/0xd0\n   el0_svc_common.constprop.0+0x40/0xf0\n   do_el0_svc+0x24/0x40\n   el0_svc+0x40/0x1d0\n   el0t_64_sync_handler+0xa0/0xe8\n   el0t_64_sync+0x1b0/0x1b8\n  Code: 17ffff83 f94017e0 f9002be0 f9402ea0 (f9400c00)\n  ---[ end trace 0000000000000000  ]---\n\nAlso the reporter is very kind to test the following ASSERT() added to\nbtrfs_trim_free_extents_throttle():\n\n\tASSERT(device->bdev,\n\t       \"devid=%llu path=%s dev_state=0x%lx\\n\",\n\t       device->devid, btrfs_dev_name(device), device->dev_state);\n\nAnd it shows the following output:\n\n  assertion failed: device->bdev, in extent-tree.c:6630 (devid=2 path=/dev/sdd dev_state=0x82)\n\nWhich means the device->bdev is NULL, and the dev_state is\nBTRFS_DEV_STATE_IN_FS_METADATA | BTRFS_DEV_STATE_ITEM_FOUND, without\nBTRFS_DEV_STATE_WRITEABLE flag set.\n\n[CAUSE]\nThe pc points to the following call chain:\n\n  btrfs_trim_fs()\n  |- btrfs_trim_free_extents()\n     |- btrfs_trim_free_extents_throttle()\n        |- bdev_max_discard_sectors(device->bdev)\n\nSo the NULL pointer dereference is caused by device->bdev being NULL.\n\nThis looks impossible by a quick glance, as just before calling\nbtrfs_trim_free_extents_throttle(), we have skipped any device that has\nBTRFS_DEV_STATE_MISSING flag set.\n\nHowever in this particular case, there is a window where the missing\ndevice is later re-scanned, causing btrfs to remove the\nBTRFS_DEV_STATE_MISSING flag:\n\n  btrfs_control_ioctl()\n  |- btrfs_scan_one_device()\n     |- device_list_add()\n        |- rcu_assign_pointer(device->name, name);\n        |  This updates the missing device's path to the new good path.\n        |\n        |- clear_bit(BTRFS_DEV_STATE_MISSING, &device->dev_state)\n           This removes the BTRFS_DEV_STATE_MISSING flag.\n\nThis allows the missing device to re-appear and clear the\nBTRFS_DEV_STATE_MISSING flag.  However the device still does not have\nthe BTRFS_DEV_STATE_WRITEABLE flag set, nor is its bdev pointer updated.\n\nThe bdev pointer remains NULL, triggering the crash later.\n\n[FIX]\nThis is a big de-synchronization between BTRFS_DEV_STATE_MISSING and\ndevice->bdev pointer, and shows a gap in btrfs's re-appearing-device\nhandling.\n\nThe proper handling of re-appearing device will need quite some extra\nwork, which is out of the context of this small\n---truncated---",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-64593",
          "url": "https://www.suse.com/security/cve/CVE-2026-64593"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274497 for CVE-2026-64593",
          "url": "https://bugzilla.suse.com/1274497"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-64593"
    },
    {
      "cve": "CVE-2026-68121",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68121"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npppoe: reload header pointer after dev_hard_header()\n\npppoe_sendmsg() saves a pointer to the PPPoE header before calling\ndev_hard_header(). Device header callbacks are allowed to reallocate the\nskb head, invalidating pointers into it.\n\nThis can happen when a send is blocked in copy_from_user() while the first\nnon-Ethernet port is added to an empty team device. The team's delegated\nGRE header callback then expands the skb head. PPPoE subsequently writes\nsix bytes through the stale pointer into the freed head.\n\nReload the PPPoE header through the skb's network-header offset after\ndevice header creation. pskb_expand_head() updates that offset when it\nrelocates the head.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68121",
          "url": "https://www.suse.com/security/cve/CVE-2026-68121"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274888 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1274888"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275228 for CVE-2026-68121",
          "url": "https://bugzilla.suse.com/1275228"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68121"
    },
    {
      "cve": "CVE-2026-68136",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68136"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gro: fix double aggregation of flush-marked skbs\n\nCommit 0ab03f353d36 (\"net-gro: Fix GRO flush when receiving a GSO\npacket.\") added a flush check to skb_gro_receive(), but\nskb_gro_receive_list() lacks the same validation.\n\nAs a result, packets marked with NAPI_GRO_CB(skb)->flush may still be\nre-aggregated.\n\nThis allows already-GRO'd packets with existing frag_list to be\nre-aggregated into a new GRO session, corrupting the frag_list chain\nstructure. When skb_segment() attempts to unpack these malformed packets,\nit encounters invalid state and triggers a kernel panic.\n\nScenario (Tethering/Device forwarding):\n  1. Driver: Generated aggregated packet P1 via LRO with frag_list\n  2. Dev A: Receives aggregated fraglist packet and flush flag set\n  3. Dev A: Re-enters GRO, skb_gro_receive_list() is called\n  4. Missing flush check allows re-aggregation despite flush flag\n  5. Frag_list chain becomes corrupted (loops or dangling refs)\n  6. Dev B: TX path calls skb_segment(), crashes on corrupted frag_list\n\nRoot cause in skb_segment():\n  The check at line ~4891:\n    if (hsize <= 0 && i >= nfrags && skb_headlen(list_skb) &&\n        (skb_headlen(list_skb) == len || sg)) {\n\n  When frag_list is corrupted by double aggregation, when list_skb is\n  a NULL pointer from skb->next, skb_headlen(list_skb) dereference\n  NULL/corrupted pointers occurs.\n\nCall Trace:\n skb_headlen(NULL skb)\n skb_segment\n tcp_gso_segment\n tcp4_gso_segment\n inet_gso_segment\n skb_mac_gso_segment\n __skb_gso_segment\n skb_gso_segment\n validate_xmit_skb\n validate_xmit_skb_list\n sch_direct_xmit\n qdisc_restart\n __qdisc_run\n qdisc_run\n net_tx_action\n\nFix: Add NAPI_GRO_CB(skb)->flush validation to the early-return check in\nskb_gro_receive_list(), matching the defensive programming pattern of\nskb_gro_receive().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68136",
          "url": "https://www.suse.com/security/cve/CVE-2026-68136"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275474 for CVE-2026-68136",
          "url": "https://bugzilla.suse.com/1275474"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275478 for CVE-2026-68136",
          "url": "https://bugzilla.suse.com/1275478"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68136"
    },
    {
      "cve": "CVE-2026-68138",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68138"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: serialize qdisc_rtab_list against concurrent get/put\n\nqdisc_get_rtab() and qdisc_put_rtab() mutate the process-global singly\nlinked list qdisc_rtab_list and a plain non-atomic 'int refcnt' with no\nlock. This was only safe because every caller historically held the RTNL\nmutex, which serialized all rate-table lookups, inserts and frees.\n\nThat invariant no longer holds. cls_flower sets\nTCF_PROTO_OPS_DOIT_UNLOCKED, so tc_new_tfilter() keeps rtnl_held == false\nfor it and sets TCA_ACT_FLAGS_NO_RTNL. That flag propagates through\ntcf_exts_validate_ex() -> tcf_action_init() -> tcf_action_init_1() ->\ntcf_police_init(), which calls qdisc_get_rtab()/qdisc_put_rtab() with the\nRTNL mutex NOT held. Two RTM_NEWTFILTER requests on different CPUs, each\nadding a flower filter with a police action carrying the same rate, then\nrace on qdisc_rtab_list and on the non-atomic refcnt, leading to a\nuse-after-free / double-free of the kmalloc-2k struct qdisc_rate_table.\nqdisc_rtab_list is a single global (not per-netns), so the corrupted\nobject is shared system-wide.\n\n  BUG: KASAN: slab-use-after-free in qdisc_put_rtab+0x12f/0x160\n   qdisc_put_rtab+0x12f/0x160\n   tcf_police_init+0xda9/0x1590\n   tcf_action_init_1+0x460/0x6b0\n   tcf_action_init+0x439/0xa40\n   tcf_exts_validate_ex+0x42d/0x550\n   fl_change+0xddd/0x7da0\n   tc_new_tfilter+0xaa7/0x2420\n   rtnetlink_rcv_msg+0x95e/0xe90\n  which belongs to the cache kmalloc-2k of size 2048\n\nProtect qdisc_rtab_list and the refcount with a dedicated spinlock. The\n(sleeping, GFP_KERNEL) allocation in qdisc_get_rtab() is performed before\ntaking the lock; if a concurrent inserter added an identical table in the\nmeantime the freshly allocated one is freed under the lock, so no\nduplicate is leaked. qdisc_put_rtab() now decrements the refcount and\nunlinks under the same lock.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68138",
          "url": "https://www.suse.com/security/cve/CVE-2026-68138"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274941 for CVE-2026-68138",
          "url": "https://bugzilla.suse.com/1274941"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274942 for CVE-2026-68138",
          "url": "https://bugzilla.suse.com/1274942"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68138"
    },
    {
      "cve": "CVE-2026-68155",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68155"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Reject monmaps advertising zero monitors\n\nA message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a\nmonitor to the client. This monmap contains information about the\nexisting monitors in the cluster. Currently, a monmap indicating that\nthere are zero monitors in the cluster is treated as valid. However, it\nis impossible to have zero monitors in the cluster and still receive a\nvalid monmap from a monitor. Therefore, such a monmap must be corrupted\nand should be treated as invalid. Furthermore, a monmap with a monitor\ncount of zero can subsequently crash the client when attempting to open\na session with a monitor in __open_session(). This happens because the\n\"BUG_ON(monc->monmap->num_mon < 1)\" assertion in pick_new_mon() is\ntriggered.\n\nThis patch extends a check in ceph_monmap_decode() to also reject\narriving mon_maps with num_mon == 0 rather than only with\nnum_mon > CEPH_MAX_MON.\n\n[ idryomov: drop \"log output for unusual values of num_mon\" part ]",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68155",
          "url": "https://www.suse.com/security/cve/CVE-2026-68155"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275304 for CVE-2026-68155",
          "url": "https://bugzilla.suse.com/1275304"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276305 for CVE-2026-68155",
          "url": "https://bugzilla.suse.com/1276305"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68155"
    },
    {
      "cve": "CVE-2026-68158",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68158"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: Fix multiplication overflow in decode_new_up_state_weight()\n\nIf a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted\nosdmap, out-of-bounds memory accesses may occur in\ndecode_new_up_state_weight(). This happens because the bounds check for\nthe new_state part is based on calculating its length depending on a len\nvalue read from the incoming message. This calculation may overflow\nleading to an incorrect bounds check. Subsequently, out-of-bounds reads\nmay occur when decoding this part.\n\nThis patch switches the multiplication to use check_mul_overflow() to\nabort processing the osdmap if an overflow occurred. Therefore,\nosdmaps/messages containing large values for len that result in a\nmultiplication overflow are treated as invalid.\n\n[ idryomov: rename new_state_len -> new_state_item_size, formatting ]",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68158",
          "url": "https://www.suse.com/security/cve/CVE-2026-68158"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275307 for CVE-2026-68158",
          "url": "https://bugzilla.suse.com/1275307"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276303 for CVE-2026-68158",
          "url": "https://bugzilla.suse.com/1276303"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68158"
    },
    {
      "cve": "CVE-2026-68159",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68159"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE\n\n__decode_pg_temp() decodes an user-controlled length but only rejects\nvalues large enough to overflow the allocation; it does not bound it to\nCEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and\napply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size\non-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends\nan OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack\nout-of-bounds write.\n\nAn OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer\nentries at decode time. The bound is well below the old overflow threshold, so\nit also covers the allocation-size overflow the previous check guarded against.\n\n  BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds\n  Write of size 4 ... by task exploit\n   kasan_report (mm/kasan/report.c:595)\n   ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833)\n   calc_target (net/ceph/osd_client.c:1638)\n   __submit_request (net/ceph/osd_client.c:2394)\n   ceph_osdc_start_request (net/ceph/osd_client.c:2490)\n   ceph_osdc_call (net/ceph/osd_client.c:5164)\n   rbd_dev_image_probe (drivers/block/rbd.c:6899)\n   do_rbd_add (drivers/block/rbd.c:7138)\n   ...\n  kernel BUG at net/ceph/osdmap.c:2670!\n\n[ idryomov: do the same in __decode_pg_upmap_items() ]",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68159",
          "url": "https://www.suse.com/security/cve/CVE-2026-68159"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275470 for CVE-2026-68159",
          "url": "https://bugzilla.suse.com/1275470"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275471 for CVE-2026-68159",
          "url": "https://bugzilla.suse.com/1275471"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68159"
    },
    {
      "cve": "CVE-2026-68160",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68160"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps()\n\nceph_handle_caps() reads snap_trace_len from the wire-format\nceph_mds_caps header and uses it unconditionally to build a fake\nend pointer (snaptrace + snaptrace_len) that is later handed to\nceph_update_snap_trace() in the CEPH_CAP_OP_IMPORT case:\n\n    snaptrace     = h + 1;\n    snaptrace_len = le32_to_cpu(h->snap_trace_len);\n    p             = snaptrace + snaptrace_len;\n    ...\n    case CEPH_CAP_OP_IMPORT:\n        if (snaptrace_len) {\n            ...\n            if (ceph_update_snap_trace(mdsc, snaptrace,\n                                       snaptrace + snaptrace_len,\n                                       false, &realm)) { ... }\n\nceph_update_snap_trace() then decodes a struct ceph_mds_snap_realm\nfrom snaptrace using ceph_decode_need(&p, e, sizeof(*ri), bad)\nwith the attacker-supplied fake end e == snaptrace + snaptrace_len.\nWith snaptrace_len == 0xFFFFFFFF the bound check is trivially\nsatisfied, ri = p reads sizeof(struct ceph_mds_snap_realm) past\nthe legitimate msg->front buffer, and ri->num_snaps /\nri->num_prior_parent_snaps then drive further out-of-bounds\nreads of the encoded snap arrays.\n\nThe eleven msg_version >= 2 .. msg_version >= 12 decoder blocks\nabove the op switch each catch this OOB through their\nceph_decode_*_safe() / ceph_decode_need() helpers, but they sit\nbehind a hdr.version-gated if, so a malicious or compromised\nMDS that sets msg->hdr.version = 1 reaches the IMPORT path with\nno version-gated decoder having validated snap_trace_len. The\nshape has been present since ceph_handle_caps() was introduced.\n\nValidate snap_trace_len against the message front buffer before\nconsuming it, using the canonical ceph_decode_need() / ceph_has_room()\nhelper.  The helper bounds the length with subtraction (n <= end - p,\nguarded by end >= p) rather than pointer addition, so it is wrap-safe\nfor the attacker-controlled u32 length on 32-bit builds where\np + snap_trace_len could overflow the address space.  This matches the\nrest of the ceph decode path (e.g. the pool_ns_len check a few lines\nbelow), and the existing goto bad cleanup already covers this exit\npath.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68160",
          "url": "https://www.suse.com/security/cve/CVE-2026-68160"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275472 for CVE-2026-68160",
          "url": "https://bugzilla.suse.com/1275472"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275473 for CVE-2026-68160",
          "url": "https://bugzilla.suse.com/1275473"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68160"
    },
    {
      "cve": "CVE-2026-68202",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68202"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: close a re-opened queue timer in the destructor\n\nqueue_delete() closes the queue timer, then frees it. snd_seq_timer_close()\nclears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and\nsnd_seq_timer_delete() frees q->timer.\n\nA borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT\nthat took a queueptr() use_lock reference before the queue was unlinked\nruns snd_seq_timer_open() after the close. Open refuses re-open only while\ntimeri is set, and the close just cleared it, so it re-opens timeri.\n\nsnd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop()\nis a no-op, because running was cleared first. So it frees q->timer with the\ninstance still live. The queue is freed next.\n\nThe instance stays on the global timer with callback_data pointing at the\nfreed queue. A non-owner START on the unlocked queue arms it. The next tick\nderefs the freed queue in snd_seq_timer_interrupt().\n\nReachable by an unprivileged user with access to /dev/snd/seq. No CAP and\nno queue ownership required.\n\nClose any lingering instance in the destructor. There, ->timeri can no\nlonger change: the queue is unlinked and all use_lock borrowers have\ndrained, so no snd_seq_queue_use() can re-open it. Close it before clearing\nq->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt()\nto finish, and that callback still reads q->timer (via snd_seq_check_queue()),\nso q->timer must stay valid until it drains.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68202",
          "url": "https://www.suse.com/security/cve/CVE-2026-68202"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275161 for CVE-2026-68202",
          "url": "https://bugzilla.suse.com/1275161"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275162 for CVE-2026-68202",
          "url": "https://bugzilla.suse.com/1275162"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68202"
    },
    {
      "cve": "CVE-2026-68397",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68397"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/iucv: take a reference on the socket found in afiucv_hs_rcv()\n\nafiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock,\ndrops the lock, and then passes the socket to the afiucv_hs_callback_*()\nhandlers without holding a reference. AF_IUCV sockets are not\nRCU-protected and are freed synchronously by iucv_sock_kill() ->\nsock_put(), so a concurrent close can free the socket in the window\nbetween read_unlock() and the handler, which then dereferences freed\nmemory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()).\n\nTake a reference with sock_hold() while the socket is still on the list\nand release it with sock_put() once the handler has run.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68397",
          "url": "https://www.suse.com/security/cve/CVE-2026-68397"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274898 for CVE-2026-68397",
          "url": "https://bugzilla.suse.com/1274898"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274918 for CVE-2026-68397",
          "url": "https://bugzilla.suse.com/1274918"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68397"
    },
    {
      "cve": "CVE-2026-68398",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68398"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF\n\npppol2tp_recv() runs in the L2TP UDP-encap softirq RX path:\n\n l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv()\n   -> ppp_input(&po->chan)\n\nIt runs under rcu_read_lock() holding only an l2tp_session reference and\ntakes NO reference on the internal PPP channel (struct channel,\nchan->ppp) that ppp_input() dereferences.\n\nThe pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel\nare RCU-safe.  But the internal struct channel is a separate allocation\nthat ppp_release_channel() frees with a plain kfree():\n\n close(data socket) -> pppol2tp_release() -> pppox_unbind_sock()\n   -> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch)\n\nFor a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit\n(no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips\nboth ppp_disconnect_channel()'s synchronize_net() and\nppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace\nperiod.  rcu_read_lock() in pppol2tp_recv() does not protect against a\nplain kfree(), so an in-flight ppp_input() on one CPU can dereference\nthe channel just freed by close() on another CPU.\n\nThe bug is reachable by an unprivileged user.\n\nDefer the channel free to an RCU callback via call_rcu() so the grace\nperiod fences any in-flight ppp_input(). The disconnect and unbridge\nteardown paths already fence with synchronize_net()/synchronize_rcu();\ncall_rcu() does the same here without stalling the close() path.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68398",
          "url": "https://www.suse.com/security/cve/CVE-2026-68398"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274908 for CVE-2026-68398",
          "url": "https://bugzilla.suse.com/1274908"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274916 for CVE-2026-68398",
          "url": "https://bugzilla.suse.com/1274916"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68398"
    },
    {
      "cve": "CVE-2026-68417",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68417"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: publish QP after initialization\n\nsiw_create_qp() currently calls siw_qp_add() before the queues, CQ\npointers, state, completion, and device list entry are ready. A QPN\nlookup can therefore reach a QP that is still being constructed.\n\nMove siw_qp_add() to the end of siw_create_qp(), after QP\ninitialization and before adding the QP to the siw device list.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68417",
          "url": "https://www.suse.com/security/cve/CVE-2026-68417"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274696 for CVE-2026-68417",
          "url": "https://bugzilla.suse.com/1274696"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274711 for CVE-2026-68417",
          "url": "https://bugzilla.suse.com/1274711"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68417"
    },
    {
      "cve": "CVE-2026-68426",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68426"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix stale skb->prev after async crypto steals a GSO segment\n\nskb_gso_segment() leaves the segment list head with ->prev pointing at\nthe last segment, an invariant validate_xmit_skb_list() relies on when\nit sets its tail pointer (tail = skb->prev).\n\nWhen validate_xmit_xfrm() walks a GSO list and some segments are stolen\nby async crypto (->xmit() returns -EINPROGRESS), those segments are\nunlinked from the list but the head ->prev is never updated.  If the\nlast segment is the one stolen, the returned head still has ->prev\npointing at it, even though it is now owned by the crypto engine and may\nbe freed.  validate_xmit_skb_list() later does tail->next = skb, writing\nthrough that stale pointer -- a use-after-free.\n\nRepoint skb->prev at the last retained segment before returning.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68426",
          "url": "https://www.suse.com/security/cve/CVE-2026-68426"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274705 for CVE-2026-68426",
          "url": "https://bugzilla.suse.com/1274705"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274712 for CVE-2026-68426",
          "url": "https://bugzilla.suse.com/1274712"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-68426"
    },
    {
      "cve": "CVE-2026-68480",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-68480"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bugs: Make Safe-RET robust against interrupt injection\n\nAn attacker injecting interrupts while the Safe-RET mitigation executes\non machines affected by SRSO can neutralize the safe return sequence,\npotentially leading to data leakage through speculative execution.\n\nFixup register state as if the Safe-RET sequence executed successfully\nby \"emulating\" it, in a manner of speaking, and avoid executing a RET\ninstruction after returning from the interrupt.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-68480",
          "url": "https://www.suse.com/security/cve/CVE-2026-68480"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274208 for CVE-2026-68480",
          "url": "https://bugzilla.suse.com/1274208"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274209 for CVE-2026-68480",
          "url": "https://bugzilla.suse.com/1274209"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.6,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-68480"
    },
    {
      "cve": "CVE-2026-72020",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72020"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: reset full ip_vs_seq structs in ip_vs_conn_new\n\nCommit 9a05475cebdd (\"ipvs: avoid kmem_cache_zalloc in\nip_vs_conn_new\") changed ip_vs_conn_new() to allocate an ip_vs_conn\nobject with kmem_cache_alloc().  The function then initializes many\nfields explicitly, but only resets in_seq.delta and out_seq.delta in the\ntwo struct ip_vs_seq members.\n\nThat leaves init_seq and previous_delta uninitialized.  This is normally\nharmless while the corresponding IP_VS_CONN_F_IN_SEQ or\nIP_VS_CONN_F_OUT_SEQ flag is clear.  For connections learned from a sync\nmessage, however, ip_vs_proc_conn() preserves those flags from\nIP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits\nIPVS_OPT_SEQ_DATA.  In that case the new connection can be hashed with\nSEQ flags set but with the rest of in_seq/out_seq still containing stale\nslab data.\n\nWhen a packet for such a connection is later handled by an IPVS\napplication helper, vs_fix_seq() and vs_fix_ack_seq() use\nprevious_delta and init_seq to rewrite TCP sequence numbers.  A malformed\nsync message can therefore make forwarded packets carry stale slab bytes\nin their TCP seq/ack numbers, and can also corrupt the forwarded TCP\nflow.\n\nReset both struct ip_vs_seq members completely before publishing the\nconnection.  This matches the existing \"reset struct ip_vs_seq\" comment\nand keeps the sequence-adjustment gates inactive unless valid sequence\ndata is installed later.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72020",
          "url": "https://www.suse.com/security/cve/CVE-2026-72020"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275506 for CVE-2026-72020",
          "url": "https://bugzilla.suse.com/1275506"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276301 for CVE-2026-72020",
          "url": "https://bugzilla.suse.com/1276301"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72020"
    },
    {
      "cve": "CVE-2026-72069",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72069"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nlocking/rt: Fix the incorrect RCU protection in rt_spin_unlock()\n\nrt_spin_unlock() releases the RCU protection before unlocking the\nlock. That opens the door for the following UAF scenario:\n\n T1\t\t\t\t\tT2\n spin_lock(&p->lock);\t\trcu_read_lock();\n invalidate(p);\t\t\tp = rcu_dereference(ptr);\n rcu_assign_pointer(ptr, NULL);\tif (!p) return;\n spin_unlock(&p->lock);\t\tspin_lock(&p->lock)\n \t\t\t\t   lock(&lock->lock);\n\t\t\t\t   rcu_read_lock();\n kfree_rcu(p);\t\t\trcu_read_unlock();\n\t\t\t\t....\n\t\t\t\tspin_unlock(&p->lock)\n\t\t\t\t  rcu_read_unlock(); // Ends grace period\n rcu_do_batch()\n   kfree(p);\n\t\t\t    UAF ->\t  rt_mutex_cmpxchg_release(&lock->lock...)\n\nRegular spinlocks keep preemption disabled accross the unlock operation,\nwhich provides full RCU protection, but the RT substitution fails to\nresemble that. Same applies for the rwlock substitution.\n\nMove the rcu_read_unlock() invocation past the unlock operations to match\nthe non-RT semantics. This makes it asymmetric vs. rt_xxx_lock(), but\nthat's harmless as the caller needs to hold RCU read lock across the lock\noperation. The migrate_enable() call stays before the unlock operation\nbecause there is no per CPU operation in the unlock path which would\nrequire migration to be kept disabled.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72069",
          "url": "https://www.suse.com/security/cve/CVE-2026-72069"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275528 for CVE-2026-72069",
          "url": "https://bugzilla.suse.com/1275528"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275529 for CVE-2026-72069",
          "url": "https://bugzilla.suse.com/1275529"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72069"
    },
    {
      "cve": "CVE-2026-72083",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72083"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE\n\ncore_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT\nparameter list with transport_kmap_data_sg() and parses the destination\nTransportID with target_parse_pr_out_transport_id(). For an iSCSI\nTransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns\nthe ISID in iport_ptr as a raw pointer into that mapped buffer.\n\nThe function then unmaps the buffer with transport_kunmap_data_sg() before\ndereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and\ncore_scsi3_alloc_registration(). When the parameter list spans more than\none page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses\nvmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual\naddress backing iport_ptr is torn down and every subsequent dereference is\na use-after-free read of the unmapped region.\n\nKeep the parameter list mapped until iport_ptr is no longer needed: drop\nthe early transport_kunmap_data_sg() and unmap once on the success path,\nright before returning. The error paths already unmap through the existing\n\"if (buf) transport_kunmap_data_sg(cmd)\" at the out: label, which now runs\non every post-map error exit because buf is no longer cleared early. Only\nreads of the mapping happen while spinlocks are held; the map and unmap\ncalls remain outside any lock. The sibling caller\ncore_scsi3_decode_spec_i_port() already uses the buffer before unmapping it\nand is left unchanged.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72083",
          "url": "https://www.suse.com/security/cve/CVE-2026-72083"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275535 for CVE-2026-72083",
          "url": "https://bugzilla.suse.com/1275535"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275536 for CVE-2026-72083",
          "url": "https://bugzilla.suse.com/1275536"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72083"
    },
    {
      "cve": "CVE-2026-72084",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72084"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Bound PR-OUT TransportID parsing to the received buffer\n\ncore_scsi3_decode_spec_i_port() and core_scsi3_emulate_register_and_move()\nhand the raw PERSISTENT RESERVE OUT parameter buffer to\ntarget_parse_pr_out_transport_id() without telling it how many bytes are\nvalid.  For an iSCSI TransportID (FORMAT CODE 01b),\niscsi_parse_pr_out_transport_id() locates the \",i,0x\" ISID separator with\nan unbounded strstr() (and on the error path prints the name with a further\nunbounded \"%s\").  An initiator can submit a TransportID whose iSCSI name\ncontains neither a \",i,0x\" substring nor a NUL terminator, filling the\nparameter list to its end, so the scan runs off the end of the buffer.\n\nWhen the parameter list spans more than one page the buffer is a multi-page\nvmap (transport_kmap_data_sg()), so the over-read walks into the trailing\nvmalloc guard page and oopses (KASAN: vmalloc-out-of-bounds in strstr).  It\nis reachable by any fabric that delivers a PR OUT to a device exported\nthrough an iSCSI TPG, including a guest via vhost-scsi.\n\nPass the number of received bytes down to the parser and validate the iSCSI\nTransportID's own self-described length (ADDITIONAL LENGTH + 4) once, up\nfront: reject it if it is below the spc4r17 minimum or larger than the\nreceived buffer, then bound the separator search, the ISID walk and the\nname copy by that length.  This is the length check the callers already\nperform after the parse (core_scsi3_decode_spec_i_port() compares tid_len\nagainst tpdl, core_scsi3_emulate_register_and_move() validates it against\ndata_length), moved ahead of the scan.  Also drop the unbounded \"%s\" of the\nunterminated name.\n\nAdd per-format explicit name-length checks before copying into i_str,\nrather than silently truncating with min_t: for FORMAT CODE 00b reject if\nthe descriptor body (tid_len - 4 bytes) cannot fit in\ni_str[TRANSPORT_IQN_LEN]; for FORMAT CODE 01b reject if the name portion\n(from &buf[4] up to the separator) cannot fit.  Both checks make the bounds\nintent explicit at each format branch.\n\nWhile here, also reject a FORMAT CODE 01b TransportID whose \",i,0x\"\nseparator sits at the very end of the descriptor: that leaves an empty ISID\nand points the returned port nexus pointer at buf + tid_len, one past the\ndescriptor, which the registration code (__core_scsi3_locate_pr_reg(),\n__core_scsi3_alloc_registration()) then dereferences as the ISID string --\nthe same over-read of the parameter buffer for a malformed descriptor.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72084",
          "url": "https://www.suse.com/security/cve/CVE-2026-72084"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275540 for CVE-2026-72084",
          "url": "https://bugzilla.suse.com/1275540"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275541 for CVE-2026-72084",
          "url": "https://bugzilla.suse.com/1275541"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72084"
    },
    {
      "cve": "CVE-2026-72123",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72123"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF\n\nCommit f1b4e32aca08 (\"can: bcm: use call_rcu() instead of costly\nsynchronize_rcu()\") replaced synchronize_rcu() in bcm_delete_rx_op()\nwith call_rcu() and introduced the RX_NO_AUTOTIMER flag.\n\nHowever, this flag check was omitted for thrtimer in the packet rx\nfast-path. During BCM RX operation teardown, a concurrent RCU reader\n(bcm_rx_handler) can race and re-arm thrtimer via\nbcm_rx_update_and_send() after call_rcu() has been scheduled.  Once\nthe RCU grace period elapses, bcm_op is freed.  The subsequently\nfiring thrtimer then dereferences the deallocated op, causing a UAF.\n\nAdding flag checks to the rx fast-path (bcm_rx_update_and_send) does not\nfully close the TOCTOU race and introduces latency for every CAN frame.\nConversely, calling hrtimer_cancel() directly inside the RCU callback\n(softirq context) is fatal as hrtimer_cancel() can sleep, triggering\na \"scheduling while atomic\" panic.\n\nResolve this by deferring the timer cancellation and memory free to a\ndedicated unbound workqueue (bcm_wq).  The RCU callback now queues a\nwork item to bcm_wq, which safely cancels both timers and deallocates\nmemory in sleepable process context.  A dedicated workqueue is used to\nprevent system-wide WQ saturation and is cleanly flushed/destroyed\non module unload to avoid rmmod page faults.\n\nSince the deferred work can now outlive the calling context by an\nunbounded amount, also take a reference on op->sk when it is assigned\nand drop it only once the deferred work has cancelled both timers, so a\nsocket can no longer be freed out from under a still-armed timer whose\ncallback (bcm_send_to_user()) dereferences op->sk.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72123",
          "url": "https://www.suse.com/security/cve/CVE-2026-72123"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277523 for CVE-2026-72123",
          "url": "https://bugzilla.suse.com/1277523"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277865 for CVE-2026-72123",
          "url": "https://bugzilla.suse.com/1277865"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72123"
    },
    {
      "cve": "CVE-2026-72135",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72135"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Make the TPM character devices non-seekable\n\nThe TPM character devices expose a sequential command/response\ninterface, but their open handlers leave FMODE_PREAD and FMODE_PWRITE\nenabled.\n\nAfter a command leaves a response pending, pread(fd, buf, 16, 0x1400)\npasses 0x1400 as *off to tpm_common_read(). The transfer length is\nbounded by response_length, but the offset is used unchecked when\nforming data_buffer + *off. A sufficiently large offset therefore causes\nan out-of-bounds heap read through copy_to_user() and, if the copy\nsucceeds, an out-of-bounds zero-write through the following memset().\n\nPositional I/O does not provide coherent semantics for this interface.\nAn arbitrary pread offset cannot represent how much of a response has\nbeen consumed sequentially. The write callback always stores a command\nat the start of data_buffer, while pwrite() does not update file->f_pos\nand can leave the sequential read cursor stale.\n\nCall nonseekable_open() from both open handlers. This removes\nFMODE_PREAD and FMODE_PWRITE, causing positional reads and writes to\nfail with -ESPIPE before reaching the TPM callbacks, and explicitly\nmarks the files non-seekable. Normal read() and write() continue to use\nthe existing sequential f_pos cursor, leaving the response state machine\nunchanged.\n\nTested on Linux 6.12 with KASAN and a swtpm TPM2 device:\n\n - sequential partial reads returned the complete response\n - pread() and preadv() with offset 0x1400 returned -ESPIPE\n - pwrite() and pwritev() with offset zero returned -ESPIPE\n - the pending response remained intact after the rejected operations\n - a subsequent normal command/response cycle completed normally\n - no KASAN report was produced.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72135",
          "url": "https://www.suse.com/security/cve/CVE-2026-72135"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277571 for CVE-2026-72135",
          "url": "https://bugzilla.suse.com/1277571"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277573 for CVE-2026-72135",
          "url": "https://bugzilla.suse.com/1277573"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72135"
    },
    {
      "cve": "CVE-2026-72164",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72164"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: avoid moving extents to occupied clusters\n\nFor non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical\nme_goal.  ocfs2_move_extent() initializes new_phys_cpos from that goal and\nexpects ocfs2_probe_alloc_group() to replace it with a free run in the\ntarget block group.\n\nThe probe currently leaves *phys_cpos unchanged if the scan reaches the\nend of the group without finding a free run.  An occupied goal at the last\nbit can therefore survive the probe and be passed to\n__ocfs2_move_extent(), which copies file data into a cluster still owned\nby another inode before the bitmap is updated.\n\nWhen the probe does find a free run, it also subtracts move_len from the\nending bit.  The start of an N-bit run ending at i is i - N + 1, so the\ncurrent calculation can report the bit immediately before the free run.\n\nClear *phys_cpos before scanning and use the correct free-run start. \nCallers already treat a zero result as -ENOSPC, so failed probes no longer\ncontinue with an occupied caller-controlled goal.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72164",
          "url": "https://www.suse.com/security/cve/CVE-2026-72164"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277553 for CVE-2026-72164",
          "url": "https://bugzilla.suse.com/1277553"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277868 for CVE-2026-72164",
          "url": "https://bugzilla.suse.com/1277868"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72164"
    },
    {
      "cve": "CVE-2026-72251",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72251"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_nat_sip: reload possible stale data pointer\n\nquoting sashiko:\n ------------------------------------------------------------------------\n [..] noticed a potential memory bug and header corruption involving the\n SIP NAT helper.\n\n In net/netfilter/nf_nat_sip.c:nf_nat_sip():\n\tif (skb_ensure_writable(skb, skb->len)) {\n\t\tnf_ct_helper_log(skb, ct, \"cannot mangle packet\");\n\t\treturn NF_DROP;\n\t}\n\tuh = (void *)skb->data + protoff;\n\tuh->dest = ct_sip_info->forced_dport;\n\tif (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff,\n\t\t\t\t      0, 0, NULL, 0)) {\n\n If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the\n old data buffer is freed. However, nf_nat_sip() fails to update *dptr to\n point to the new buffer.\n\n It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP\n packet, which would overwrite the sequence number with a checksum update.\n ------------------------------------------------------------------------\n\nnf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen.\nBut clones are possible, so rebuild dptr.\n\nDisable nf_nat_mangle_udp_packet() branch for TCP streams.\nIt doesn't look like this can ever happen, else we should have received\nbug reports about this, so just check the conntrack is UDP and drop\notherwise.\n\nThe calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages,\nso I don't think this is ever expected to be true for a TCP stream.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72251",
          "url": "https://www.suse.com/security/cve/CVE-2026-72251"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275827 for CVE-2026-72251",
          "url": "https://bugzilla.suse.com/1275827"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276297 for CVE-2026-72251",
          "url": "https://bugzilla.suse.com/1276297"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72251"
    },
    {
      "cve": "CVE-2026-72288",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72288"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling\n\nHyunwoo Kim reports some really bad races should the following\nsituation occur:\n\n- LPI-I is pending in vcpu-B's AP list\n- vcpu-A writes to vcpu-B's RD to disable its LPIs\n- vcpu-C moves I from B to C\n\nIf the last two race nicely enough, vgic_prune_ap_list() can drop\nthe irq and AP list locks, reacquire them, and in the interval\nthe irq has been freed. UAF follows.\n\nThe fix is two-fold:\n\n- Before dropping the irq and ap_list locks, take a reference on\n  the irq\n\n- Do not try to handle migration of the pending bit: there is no\n  expectation that this state is retained, as per the architecture\n\nWith that, we're sure that the interrupt is still around, and we\nsafely remove it from the AP list as it has no target at this\nstage (unless another interrupt fires, but that's another story).",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72288",
          "url": "https://www.suse.com/security/cve/CVE-2026-72288"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275886 for CVE-2026-72288",
          "url": "https://bugzilla.suse.com/1275886"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275887 for CVE-2026-72288",
          "url": "https://bugzilla.suse.com/1275887"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72288"
    },
    {
      "cve": "CVE-2026-72289",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72289"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Check the interrupt is still ours before migrating it\n\nvgic_prune_ap_list() drops both ap_list_lock and irq_lock while migrating\nan interrupt to another vCPU. After reacquiring the locks it only checks\nthat the affinity is unchanged (target_vcpu == vgic_target_oracle(irq))\nbefore moving the interrupt, which assumes that an interrupt whose affinity\nis preserved is still queued on this vCPU's ap_list.\n\nThat assumption no longer holds if the interrupt is taken off the ap_list\nwhile the locks are dropped. vgic_flush_pending_lpis() removes the\ninterrupt from the list and sets irq->vcpu to NULL, but leaves\nenabled/pending/target_vcpu untouched. As the interrupt is still enabled\nand pending, vgic_target_oracle() returns the same target_vcpu, so the\naffinity check passes and list_del() is run a second time on an entry that\nhas already been removed.\n\nAlso check that the interrupt is still assigned to this vCPU\n(irq->vcpu == vcpu) before moving it.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72289",
          "url": "https://www.suse.com/security/cve/CVE-2026-72289"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275905 for CVE-2026-72289",
          "url": "https://bugzilla.suse.com/1275905"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276296 for CVE-2026-72289",
          "url": "https://bugzilla.suse.com/1276296"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72289"
    },
    {
      "cve": "CVE-2026-72323",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72323"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: igmp: Fix potential UAF in igmp_gq_start_timer()\n\nA race condition exists between device teardown (inetdev_destroy) and\nincoming IGMP query processing (igmp_rcv), leading to a Use-After-Free\nin the IGMP timer callback.\n\nDuring device destruction, inetdev_destroy() drops the primary reference\nto in_device, which can drop its refcount to 0. The actual freeing of\nin_device memory is deferred via RCU (using call_rcu()).\n\nConcurrently, igmp_rcv() runs under RCU read lock and obtains the\nin_device pointer. Because the memory is RCU-protected, CPU-0 can safely\ndereference in_device even if its refcount has hit 0.\n\nHowever, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it\nattempts to acquire a reference using in_dev_hold(). This increments the\nrefcount from 0 to 1, triggering a \"refcount_t: addition on 0\" warning.\nSince the in_device memory is still scheduled to be freed after the RCU\ngrace period (as the free callback does not check the refcount again),\nthe device is freed while the timer is still armed. When the timer\nexpires, it accesses the freed memory, causing a kernel panic.\n\nFix this by using refcount_inc_not_zero() (via a new helper\nin_dev_hold_safe()) to prevent acquiring a reference if the device is\nalready being destroyed. If the refcount is 0, we do not arm the timer.\n\nA similar issue in IPv6 MLD is fixed in a subsequent patch.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72323",
          "url": "https://www.suse.com/security/cve/CVE-2026-72323"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275985 for CVE-2026-72323",
          "url": "https://bugzilla.suse.com/1275985"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275986 for CVE-2026-72323",
          "url": "https://bugzilla.suse.com/1275986"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72323"
    },
    {
      "cve": "CVE-2026-72339",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72339"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nqede: fix off-by-one in BD ring consumption on build_skb failure\n\nqede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a\nNULL return from qede_build_skb(). When it returns NULL under memory\npressure, the functions still consume a BD from the ring before\nreturning NULL. The callers then recycle additional BDs, resulting in\none extra BD being consumed (off-by-one). This desynchronizes the BD\nring, which can corrupt DMA page reference counts and lead to SLUB\nfreelist corruption.\n\nCommit 4e910dbe3650 (\"qede: confirm skb is allocated before using\")\nadded a NULL check inside qede_build_skb() to prevent a NULL pointer\ndereference, but did not address the missing NULL checks in the\ncallers, making this off-by-one reachable.\n\nFix this by adding NULL checks for the return value of\nqede_build_skb() in both qede_rx_build_skb() and\nqede_tpa_rx_build_skb(), returning NULL immediately before any BD ring\nmanipulation.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72339",
          "url": "https://www.suse.com/security/cve/CVE-2026-72339"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276006 for CVE-2026-72339",
          "url": "https://bugzilla.suse.com/1276006"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276318 for CVE-2026-72339",
          "url": "https://bugzilla.suse.com/1276318"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72339"
    },
    {
      "cve": "CVE-2026-72389",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-72389"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: stp: Fix a potential use-after-free when deleting a bridge\n\nThe three STP timers are not supposed to be armed while the bridge is\nadministratively down. They are synchronously deactivated when the\nbridge is put administratively down and the various call sites check for\n'IFF_UP' before arming them.\n\nThis check is missing from br_topology_change_detection() and it is\npossible to engineer a situation in which the topology change timer is\narmed while the bridge is administratively down, resulting in a\nuse-after-free [1] when the bridge is deleted.\n\nFix by adding the missing check and for good measures synchronously\nshutdown the three timers when the bridge is deleted.\n\n[1]\nODEBUG: free active (active state 0) object: ffff88811662b9b0 object type: timer_list hint: br_topology_change_timer_expired (net/bridge/br_stp_timer.c:120)\nWARNING: lib/debugobjects.c:629 at debug_print_object+0x1bc/0x450, CPU#9: ip/359",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-72389",
          "url": "https://www.suse.com/security/cve/CVE-2026-72389"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1273869 for CVE-2026-72389",
          "url": "https://bugzilla.suse.com/1273869"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1274051 for CVE-2026-72389",
          "url": "https://bugzilla.suse.com/1274051"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-72389"
    },
    {
      "cve": "CVE-2026-74345",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74345"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix endpoint/socket association handling\n\nDisassociating a socket from an endpoint via siw_socket_disassoc() may\nrelease the last reference on that endpoint and free it. Therefore, don't\nclear the endpoints socket pointer after calling that function, but\nwithin.\n\nThis fixes a:\n\n  BUG: KASAN: slab-use-after-free in siw_cm_work_handler (drivers/infiniband/sw/siw/siw_cm.c:1053 drivers/infiniband/sw/siw/siw_cm.c:1075)\n\nwhich occurred after processing a malformed MPA request during connection\nestablishment, causing the new endpoint to be closed.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74345",
          "url": "https://www.suse.com/security/cve/CVE-2026-74345"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277285 for CVE-2026-74345",
          "url": "https://bugzilla.suse.com/1277285"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277287 for CVE-2026-74345",
          "url": "https://bugzilla.suse.com/1277287"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74345"
    },
    {
      "cve": "CVE-2026-74377",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74377"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Copy WQE to local buffer in non-SRQ receive path\n\nFor non-SRQ QPs, the responder reads WQE fields directly from the\nshared queue buffer mapped into userspace. This allows a malicious\nuser to modify fields like num_sge or sge entries while the kernel\nis processing the WQE, leading to out-of-bounds reads in\nrxe_resp_check_length() and copy_data().\n\nIntroduce get_recv_wqe() that validates num_sge and copies the WQE\nto a kernel-local buffer before processing, matching the approach\nalready used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is\nreused since SRQ and non-SRQ paths are mutually exclusive per QP.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74377",
          "url": "https://www.suse.com/security/cve/CVE-2026-74377"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278236 for CVE-2026-74377",
          "url": "https://bugzilla.suse.com/1278236"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 6.1,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-74377"
    },
    {
      "cve": "CVE-2026-74378",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74378"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe\n\nget_srq_wqe() reads wqe->dma.num_sge from the shared receive queue\nbuffer, which is mapped into userspace. It validates num_sge against\nmax_sge, but then re-reads the same field to calculate the memcpy\nsize. A concurrent userspace thread can modify num_sge between\nvalidation and use, causing a heap buffer overflow when copying the\nWQE into qp->resp.srq_wqe.\n\nRead num_sge into a local variable and use it for both the bounds\ncheck and the size calculation.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74378",
          "url": "https://www.suse.com/security/cve/CVE-2026-74378"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278233 for CVE-2026-74378",
          "url": "https://bugzilla.suse.com/1278233"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278234 for CVE-2026-74378",
          "url": "https://bugzilla.suse.com/1278234"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74378"
    },
    {
      "cve": "CVE-2026-74388",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74388"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: oss: Fix UAF at handling events with embedded SysEx data\n\nThe OSS sequencer processes the input MIDI bytes into a sequencer\nevent to be dispatched later (in snd_seq_oss_midi_putc() called from\nsnd_seq_oss_process_event()).  When it's a SysEx data, the event\nrecord contains data.ext.ptr pointer to the original SysEx bytes, and\nthe referred data is copied into the pool afterwards at dispatching.\nThe problem is that, if the sequencer port gets closed concurrently\nbefore the dispatch, the OSS sequencer core also releases the\nresources (in snd_seq_oss_midi_check_exit_port()), while the pending\nevent may hold a stale pointer, eventually leading to a UAF at a later\ndispatch.\n\nFortunately, there is already a refcounting mechanism (snd_use_lock_t)\nfor the OSS MIDI device access, and for addressing the issue above, we\njust need to extend the refcount until the event gets dispatched.\n\nThis patch extends snd_seq_oss_process_event() to give back the\nrefcount object, which is in turn released after calling the sequencer\ndispatcher with the given event in the caller side.\n\nAccording to the original report, KASAN report as below:\n\nKASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470\nRIP: 0033:0x7f2cb66a6340\nRead of size 6\nCall trace:\n  dump_stack_lvl+0x73/0xb0 (?:?)\n  print_report+0xd1/0x650 (?:?)\n  srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n  __virt_addr_valid+0x1a7/0x340 (?:?)\n  kasan_complete_mode_report_info+0x64/0x200 (?:?)\n  kasan_report+0xf7/0x130 (?:?)\n  snd_seq_event_dup+0x40c/0x470 (?:?)\n  kasan_check_range+0x10c/0x1c0 (?:?)\n  __asan_memcpy+0x27/0x70 (?:?)\n  snd_seq_event_dup+0x9/0x470 (?:?)\n  snd_seq_client_enqueue_event+0x139/0x240 (?:?)\n  _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?)\n  snd_seq_kernel_client_enqueue+0x102/0x120 (?:?)\n  snd_seq_oss_write+0x416/0x4e0 (?:?)\n  apparmor_file_permission+0x20/0x30 (?:?)\n  odev_write+0x3b/0x60 (?:?)\n  vfs_write+0x1ce/0x850 (?:?)\n  lock_release+0xc8/0x2a0 (?:?)\n  __kasan_check_write+0x18/0x20 (?:?)\n  __mutex_unlock_slowpath+0x129/0x510 (?:?)\n  ksys_write+0xe1/0x180 (?:?)\n  mutex_unlock+0x16/0x20 (?:?)\n  odev_ioctl+0x65/0xc0 (?:?)\n  __x64_sys_write+0x46/0x60 (?:?)\n  x64_sys_call+0x7d/0x20d0 (?:?)\n  do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87)\n  entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74388",
          "url": "https://www.suse.com/security/cve/CVE-2026-74388"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278253 for CVE-2026-74388",
          "url": "https://bugzilla.suse.com/1278253"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278254 for CVE-2026-74388",
          "url": "https://bugzilla.suse.com/1278254"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74388"
    },
    {
      "cve": "CVE-2026-74390",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74390"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs\n\nThe irdma_copy_user_pgaddrs function loops through all of the umem DMA\nblocks to populate the PBLEs and will stop when either the last DMA\nblock is reached or palloc->total_cnt is reached. The issue is that\nthe logic for checking palloc->total_cnt would only work for non-zero\nvalues.\n\nWhen irdma_setup_pbles is called with lvl==0, it\ncalls irdma_copy_user_pgaddrs with palloc->total_cnt==0, which means\nthe only way to break out of the loop is to reach the last umem DMA\nblock, which means it could end up going beyond the fixed size of 4\niwmr->pgaddrmem array that is used in the lvl==0 case.\n\nIn the case of QP/CQ/SRQ rings, the value of lvl is determined by a\nseparate input (for example, req.cq_pages in the case of a CQ). So,\nwe must perform explicit checking to ensure we don't overflow the\npgaddrmem array if the user provides a umem that consists of more\nblocks than their provided req.cq_pages.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74390",
          "url": "https://www.suse.com/security/cve/CVE-2026-74390"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278088 for CVE-2026-74390",
          "url": "https://bugzilla.suse.com/1278088"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278089 for CVE-2026-74390",
          "url": "https://bugzilla.suse.com/1278089"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74390"
    },
    {
      "cve": "CVE-2026-74394",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74394"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srpt: fix integer overflow in immediate data length check\n\nimm_buf->len is a user-controlled uint32_t received from the network.\nAdding it to imm_data_offset without overflow checking allows a\nmalicious initiator to send len=0xFFFFFFFF, causing req_size to wrap\naround to a small value, bypassing the bounds check, and subsequently\npassing a ~4GB length to sg_init_one().\n\nUse check_add_overflow() to detect wrapping before the comparison.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74394",
          "url": "https://www.suse.com/security/cve/CVE-2026-74394"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277408 for CVE-2026-74394",
          "url": "https://bugzilla.suse.com/1277408"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277409 for CVE-2026-74394",
          "url": "https://bugzilla.suse.com/1277409"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74394"
    },
    {
      "cve": "CVE-2026-74406",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74406"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().\n\nudp_tunnel_sock_release() could set sk->sk_user_data to NULL\nwhile vxlan_gro_prepare_receive() is running.\n\nLet's check if rcu_dereference_sk_user_data() is NULL after\nskb_gro_remcsum_init().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74406",
          "url": "https://www.suse.com/security/cve/CVE-2026-74406"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276395 for CVE-2026-74406",
          "url": "https://bugzilla.suse.com/1276395"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280096 for CVE-2026-74406",
          "url": "https://bugzilla.suse.com/1280096"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74406"
    },
    {
      "cve": "CVE-2026-74454",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74454"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size\n\nvc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB\nbinner BO, but writes the size of the whole BO to BPOS. On every binner\nout-of-memory event the PTB is therefore authorized to write tile lists\nacross all the other slots (which may hold the tile state, tile alloc and\noverflow memory of in-flight jobs) and, for any slot but the first, past\nthe end of the binner BO into unrelated CMA memory.\n\nSince CMA pages are recycled into page cache and user allocations, this\nis arbitrary memory corruption by GPU DMA. In practice it shows up as GPU\nhangs with corrupted control list pointers, userspace heap corruption, a\nGPU that stays permanently wedged after the first hang, and occasional\nfull system crashes, whenever a job overflows the initial binner slot.\n\nThe bug dates back to the conversion from a dedicated overflow BO (where\nwriting the full BO size was correct) to the slotted binner BO.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74454",
          "url": "https://www.suse.com/security/cve/CVE-2026-74454"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277073 for CVE-2026-74454",
          "url": "https://bugzilla.suse.com/1277073"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277074 for CVE-2026-74454",
          "url": "https://bugzilla.suse.com/1277074"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74454"
    },
    {
      "cve": "CVE-2026-74488",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74488"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames\n\nmwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with\nieee80211_amsdu_to_8023s() and walks the resulting subframes. For each\nsubframe it passes the subframe data pointer to\nmwifiex_process_tdls_action_frame(), but pairs it with skb->len, the\nlength of the A-MSDU parent, instead of rx_skb->len:\n\n\trx_skb = __skb_dequeue(&list);\n\trx_hdr = (struct rx_packet_hdr *)rx_skb->data;\n\tif (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) &&\n\t    ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) {\n\t\tmwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr,\n\t\t\t\t\t\t  skb->len);\n\t}\n\nThe parent is not a valid description of that buffer, and may not be\nvalid memory at all. ieee80211_amsdu_to_8023s() ends with\n\n\tif (!reuse_skb)\n\t\tdev_kfree_skb(skb);\n\nand it only sets reuse_skb when the parent is linear, is not a\nhead_frag, and is being consumed as the *last* subframe. So when the\nparent does not qualify for reuse it has already been freed, and the\nread of skb->len is a use-after-free. When it is reused, skb->len is\nthe length of the last subframe, applied to every earlier subframe,\nwhich over-states the buffer whenever an earlier subframe is shorter.\n\nThe callee cannot absorb a wrong length, because it derives its own\nceiling from the value it is given. Each frame type computes\n\n\ties_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN;\n\nand the element walk is then bounded entirely against that ceiling,\n\n\tfor (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) {\n\t\tu8 ie_len = pos[1];\n\n\t\tif (pos + 2 + ie_len > end)\n\t\t\tbreak;\n\nso a too-large len moves end past the end of the subframe and the walk\nreads and copies beyond it. The A-MSDU layout is chosen by the sender,\nwhich makes the difference between the last subframe and a shorter\nearlier one remotely selectable. Reaching this requires TDLS support in\nfirmware and the TDLS ethertype on the subframe.\n\nThe other caller, mwifiex_process_rx_packet(), is correct: it passes a\npointer and a length that describe the same region of the RX buffer.\n\nPass rx_skb->len, the length of the subframe actually being parsed.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74488",
          "url": "https://www.suse.com/security/cve/CVE-2026-74488"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276350 for CVE-2026-74488",
          "url": "https://bugzilla.suse.com/1276350"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277289 for CVE-2026-74488",
          "url": "https://bugzilla.suse.com/1277289"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74488"
    },
    {
      "cve": "CVE-2026-74496",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74496"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfou: Fix use-after-free in fou_create()\n\nfou_create() publishes struct fou through sk_user_data before adding the\nnew FOU port to the per-netns list.  If fou_add_to_port_list() fails,\nthe error path frees fou while it is still reachable through\nsk_user_data.  A concurrent receive can then dereference the freed\nobject in fou_from_sock().\n\nThis ordering issue was previously noted in the linked discussion.\n\nThe failure is reachable when local port 0 is requested.  Each socket\nbinds to a different ephemeral port, but fou_cfg_cmp() compares the\nrequested port 0 and reports -EALREADY once an entry already exists.\n\nRelease the tunnel socket before freeing fou so sk_user_data is cleared\nfirst, and defer reclamation with kfree_rcu() to protect concurrent RCU\nreaders.  This matches the lifetime handling in fou_release().",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74496",
          "url": "https://www.suse.com/security/cve/CVE-2026-74496"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275867 for CVE-2026-74496",
          "url": "https://bugzilla.suse.com/1275867"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275868 for CVE-2026-74496",
          "url": "https://bugzilla.suse.com/1275868"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74496"
    },
    {
      "cve": "CVE-2026-74518",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74518"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix list corruption in allocate_file_region_entries()\n\nallocate_file_region_entries() tops up resv->region_cache with freshly\nallocated file_region descriptors.  The allocation uses GFP_KERNEL, so\nresv->lock is dropped around it: the new entries are gathered on a\nstack-local list head, allocated_regions, and spliced into\nresv->region_cache once the lock is re-acquired.\n\nThe splice used list_splice(), which moves the entries but does not\nre-initialize the source head, so allocated_regions is left pointing at an\nentry that now lives on resv->region_cache.  The top-up runs in a while\nloop that re-checks the cache deficit after re-acquiring the lock.  For a\nshared mapping the resv_map is shared by every mapper of the hugetlbfs\ninode, so a concurrent region_chg()/region_add()/region_del() on the same\nresv_map can consume cache entries during the unlocked window and force a\nsecond iteration.  That iteration calls list_add() on the stale head and\ncorrupts the list; with CONFIG_DEBUG_LIST the __list_add_valid() check\ntrips:\n\n  list_add corruption. next->prev should be prev (ffffc900011ff7f8),\n  but was ffff88814c281460. (next=ffff88814c545640).\n  kernel BUG at lib/list_debug.c:31!\n   allocate_file_region_entries+0x191/0x420\n   region_chg+0x267/0x300\n   hugetlb_reserve_pages+0x387/0xc80\n   hugetlbfs_file_mmap+0x2ce/0x3f0\n   mmap_region+0x1348/0x1a80\n   do_mmap+0x85e/0xb90\n   vm_mmap_pgoff+0x18c/0x330\n   ksys_mmap_pgoff+0x2a1/0x3e0\n   do_syscall_64+0xd7/0x420\n\nWithout CONFIG_DEBUG_LIST the bad list_add() silently links a kernel-stack\naddress into resv->region_cache, leading to later use-after-free.\n\nThis was observed as a real host panic on a dense KVM host where a QEMU\nguest-RAM hugetlbfs file was mapped MAP_SHARED by both QEMU and a separate\nSPDK/DPDK vhost-user target, generating concurrent region_* traffic on one\nshared resv_map.\n\nUse list_splice_init() so the source head is re-initialized empty after\neach splice, making the retry loop safe.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74518",
          "url": "https://www.suse.com/security/cve/CVE-2026-74518"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275798 for CVE-2026-74518",
          "url": "https://bugzilla.suse.com/1275798"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275815 for CVE-2026-74518",
          "url": "https://bugzilla.suse.com/1275815"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74518"
    },
    {
      "cve": "CVE-2026-74537",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74537"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: hold sk properly in iso_conn_ready\n\nsk deref in iso_conn_ready must be done either under conn->lock, or\nholding a refcount, to avoid concurrent close. conn->sk is currently\naccessed without either:\n\n    [Task 1]            [Task 2]\n                        iso_sock_release\n    iso_conn_ready\n      sk = conn->sk\n                          lock_sock(sk)\n                            conn->sk = NULL\n      lock_sock(sk)\n                          release_sock(sk)\n                          iso_sock_kill(sk)\n       UAF on sk deref\n\nFix possible UAF by holding sk refcount in iso_conn_ready().  Also\nrecheck after lock_sock that the socket is still valid.  Adjust locking\nso conn->sk is cleared only under lock_sock.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74537",
          "url": "https://www.suse.com/security/cve/CVE-2026-74537"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275687 for CVE-2026-74537",
          "url": "https://bugzilla.suse.com/1275687"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275701 for CVE-2026-74537",
          "url": "https://bugzilla.suse.com/1275701"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74537"
    },
    {
      "cve": "CVE-2026-74556",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74556"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer\n\niscsi_tcp_hdr_dissect() receives the data segment of several PDU types\ninto the fixed-size conn->data buffer, which is allocated for\nISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes.  For the LOGIN_RSP, TEXT_RSP,\nREJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU\nwhose DataSegmentLength exceeds that buffer.\n\nThe SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its\ndata segment (sense/response data) into conn->data via\niscsi_tcp_data_recv_prep(), but it does so without the same check.  The\nonly upstream bound on in.datalen is conn->max_recv_dlength, the\ninitiator's advertised MaxRecvDataSegmentLength, which is commonly\nnegotiated well above 8192 (open-iscsi defaults to 262144).  A target\nthat returns a SCSI Response with a DataSegmentLength between 8193 and\nmax_recv_dlength therefore overflows the 8192-byte conn->data buffer.\n\nOnce the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly\nlike those responses: bound the data segment, receive it into conn->data\nwhen present, and otherwise complete the PDU with no data.  Fold the\nopcode into that case group rather than duplicating the check.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74556",
          "url": "https://www.suse.com/security/cve/CVE-2026-74556"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275696 for CVE-2026-74556",
          "url": "https://bugzilla.suse.com/1275696"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275700 for CVE-2026-74556",
          "url": "https://bugzilla.suse.com/1275700"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74556"
    },
    {
      "cve": "CVE-2026-74582",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74582"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\npacket: use consistent hard_header_len in non-ring send paths\n\npacket_snd() reads dev->hard_header_len multiple times while allocating\nand constructing an skb. Device reconfiguration can change this value\nconcurrently, for example through bonding device type changes.\n\nFor SOCK_RAW, packet_snd() can save a larger value in reserve and later\nallocate headroom using a smaller value. Moving skb->data back by reserve\nthen places it before skb->head, and the following copy from userspace can\nattempt an out-of-bounds write.\n\npacket_sendmsg_spkt() has the same issue because it calculates its\nreservation and header offset from separate reads before dropping the RCU\nread lock to allocate the skb.\n\nAdd LL_RESERVED_SPACE_EX() for callers that already saved a header length.\nRead hard_header_len once in packet_snd() and use it for allocation and\nconstruction. In packet_sendmsg_spkt(), preserve the allocation-time value\nthrough the device lookup retry.\n\nThe separate SOCK_DGRAM consistency problem between hard_header_len and\nheader_ops->create is not addressed here.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74582",
          "url": "https://www.suse.com/security/cve/CVE-2026-74582"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1275784 for CVE-2026-74582",
          "url": "https://bugzilla.suse.com/1275784"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276281 for CVE-2026-74582",
          "url": "https://bugzilla.suse.com/1276281"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74582"
    },
    {
      "cve": "CVE-2026-74615",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74615"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: do not arm the ageing timer on a device that is down\n\nvxlan_changelink() arms vxlan->age_timer whenever the requested ageing\ninterval differs from the configured one:\n\n\tif (conf.age_interval != vxlan->cfg.age_interval)\n\t\tmod_timer(&vxlan->age_timer, jiffies);\n\nThere is no netif_running() test, so the timer is armed even on a device\nthat was never brought up.  The only synchronous cancel in the driver is\nthe timer_delete_sync() in vxlan_stop(), which is .ndo_stop.\nnetif_close_many() drops devices without IFF_UP before\n__dev_close_many() runs, so that cancel is skipped for such a device.\n\nvxlan_setup() sets dev->needs_free_netdev = true and age_timer is a\nmember of struct vxlan_dev, so free_netdev() releases the allocation the\ntimer lives in while it is still queued on a timer_base.\nexpire_timers() unlinks the entry before it loads timer->function, so\nthe timer core writes through the freed object's list pointers:\n\n  BUG: KASAN: slab-use-after-free in __run_timers+0x208/0x654\n  Write of size 8 at addr ffff00001adace68 by task true/192\n   __asan_store8+0x84/0xac\n   __run_timers+0x208/0x654\n   run_timer_softirq+0x154/0x18c\n  Allocated by task 189:\n   alloc_netdev_mqs+0x64/0x720\n   rtnl_create_link+0x4ac/0x520\n   rtnl_newlink+0x758/0xd00\n  Freed by task 191:\n   netdev_release+0x40/0x58\n   netdev_run_todo+0x4a4/0x8c0\n   rtnl_dellink+0x200/0x4e8\n\nThe rtnl operations involved are netns-scoped, so an unprivileged user\ncan perform them in a new user and network namespace.\n\nArming the timer on a down device never had an effect: vxlan_cleanup()\nreturns early on !netif_running(), and vxlan_open() arms the timer for\nany non-zero interval once the device is brought up.  Add the missing\ntest.\n\nDiscovered by XBOW, triaged by Baul Lee <baul.lee@xbow.com>",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74615",
          "url": "https://www.suse.com/security/cve/CVE-2026-74615"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277901 for CVE-2026-74615",
          "url": "https://bugzilla.suse.com/1277901"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277902 for CVE-2026-74615",
          "url": "https://bugzilla.suse.com/1277902"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74615"
    },
    {
      "cve": "CVE-2026-74616",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74616"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: reject clones that overrun skb_shared_info tailroom\n\nxdpf_clone() clones broadcast copies into a single page and sets\nframe_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that\npage like a normal XDP frame and expects the usual skb_shared_info\ntailroom at the end of the buffer.\n\nThe current check only rejects frames whose linear xdp_frame header,\nheadroom, and packet data exceed PAGE_SIZE. A source frame backed by a\nlarger allocation can still satisfy that check while extending into the\nclone's required shared-info area. When such a clone is converted back\ninto an skb, build_skb_around() places skb_shared_info over live packet\nbytes and later writes can corrupt XDP return metadata.\n\nReject clones unless their linear area fits inside\nSKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already\nenforced by the XDP-to-skb conversion path.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74616",
          "url": "https://www.suse.com/security/cve/CVE-2026-74616"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277813 for CVE-2026-74616",
          "url": "https://bugzilla.suse.com/1277813"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277814 for CVE-2026-74616",
          "url": "https://bugzilla.suse.com/1277814"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74616"
    },
    {
      "cve": "CVE-2026-74669",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74669"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear IPv4 options after rebasing tunnel ICMP errors\n\nip_vs_in_icmp() rebases an skb from the outer ICMP packet to the\nquoted original request before passing it to icmp_send(). However,\nIPCB(skb)->opt still describes the outer IPv4 header.\n\nA timestamp option in the outer header can therefore leave an offset\nthat points into the quoted transport header after the rebase.\n__ip_options_echo() treats a byte at that stale location as the option\nlength and copies it into the fixed-size option storage on the\n__icmp_send() stack, causing a stack out-of-bounds write.\n\nClear the stale option metadata after resetting the network header.\nKeep the remaining control block fields, including the ingress\ninterface used by the ICMP response path.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74669",
          "url": "https://www.suse.com/security/cve/CVE-2026-74669"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277391 for CVE-2026-74669",
          "url": "https://bugzilla.suse.com/1277391"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277399 for CVE-2026-74669",
          "url": "https://bugzilla.suse.com/1277399"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74669"
    },
    {
      "cve": "CVE-2026-74695",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74695"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref()\n\nIncoming skbs passing through netfilter flowtable offload hooks (or XFRM\noffload path) might already carry a ref-counted dst_entry assigned during\nearlier RX or routing steps.\n\nCalling skb_dst_set_noref() when skb already holds a ref-counted dst\noverwrites skb->_skb_refdst, leaking the previous dst_entry reference\ncount and triggering a DEBUG_NET_WARN_ON_ONCE assertion in\nskb_dst_check_unset():\n\n  WARNING: at skb_dst_check_unset include/linux/skbuff.h:1170\n  WARNING: at skb_dst_set_noref include/linux/skbuff.h:1234\n  WARNING: at nf_flow_offload_ip_hook+0xf6c/0x2b60 net/netfilter/nf_flow_table_ip.c:864\n\nDrop any existing dst_entry reference with skb_dst_drop(skb) before\nsetting the non-referenced flowtable destination.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74695",
          "url": "https://www.suse.com/security/cve/CVE-2026-74695"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276931 for CVE-2026-74695",
          "url": "https://bugzilla.suse.com/1276931"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1276936 for CVE-2026-74695",
          "url": "https://bugzilla.suse.com/1276936"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74695"
    },
    {
      "cve": "CVE-2026-74743",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-74743"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: inherit needed_headroom and needed_tailroom from lowerdev\n\nmacvlan devices inherit hard_header_len from lowerdev during macvlan_init(),\nbut leave needed_headroom and needed_tailroom set to 0.\n\nWhen the underlying lowerdev requires extra headroom or tailroom for\nheaders/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx\nheadroom), upper layers calculating packet headroom and tailroom fail to\nreserve sufficient space.\n\nThis can result in reallocation overhead, skb headroom underflows, or KASAN\nslab-use-after-free crashes when dev_hard_header() / macvlan_hard_header()\nprepends header data or when lower devices append tailroom.\n\nFix this by:\n1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init().\n2. Propagating needed_headroom and needed_tailroom updates to attached macvlans\n   in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-74743",
          "url": "https://www.suse.com/security/cve/CVE-2026-74743"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277908 for CVE-2026-74743",
          "url": "https://bugzilla.suse.com/1277908"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277909 for CVE-2026-74743",
          "url": "https://bugzilla.suse.com/1277909"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-74743"
    },
    {
      "cve": "CVE-2026-80580",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80580"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: bound mode sysfs output to the sysfs buffer\n\nmode_string() uses snprintf() which can return a value larger than the\nremaining buffer space. show_modes() accumulates the return value into i\nwithout checking whether i has reached PAGE_SIZE, causing the offset to\nadvance past the sysfs buffer if the modelist is long enough.\n\nAdd a size parameter to mode_string() and use scnprintf() to return\nonly the bytes actually written. Add an early return when offset\nalready exceeds the buffer. In show_modes(), stop accumulating once\nthe buffer is full.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80580",
          "url": "https://www.suse.com/security/cve/CVE-2026-80580"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278294 for CVE-2026-80580",
          "url": "https://bugzilla.suse.com/1278294"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1278295 for CVE-2026-80580",
          "url": "https://bugzilla.suse.com/1278295"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-80580"
    },
    {
      "cve": "CVE-2026-80714",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80714"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: do not propagate one-packet flag to synced conns\n\nSynced connections can be created before their destination exists. When\nthe destination is later added, ip_vs_bind_dest() copies connection flags\nfrom the destination into cp->flags.\n\nIP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced\nconnection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed,\nexpiry can treat it as a one-packet connection and skip unlinking the\nexisting conn_tab node, leaving stale hash nodes pointing at a freed\nstruct ip_vs_conn.\n\nDrop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced\nconnections.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80714",
          "url": "https://www.suse.com/security/cve/CVE-2026-80714"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277561 for CVE-2026-80714",
          "url": "https://bugzilla.suse.com/1277561"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277583 for CVE-2026-80714",
          "url": "https://bugzilla.suse.com/1277583"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-80714"
    },
    {
      "cve": "CVE-2026-80716",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80716"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: wake linked drain waiters on unlink\n\nsnd_pcm_drain() on a linked stream parks an on-stack wait entry on the\ndrained peer's runtime->sleep, and after schedule_timeout() removes it\nonly if that peer is still found in the caller's group.  If group\nmembership changes during the wait and the sleep ends by signal or\ntimeout (so autoremove_wake_function() does not run), finish_wait() is\nskipped and snd_pcm_drain() returns with the entry still queued on that\nstream's sleep list; a later wake_up() then walks a freed stack frame.\nThis is reachable by unlinking either the drained or the draining stream.\n\nUnlike the close path (snd_pcm_drop() -> snd_pcm_post_stop()),\nsnd_pcm_unlink() never wakes the sleep queues.  Wake every group member\nunder the group lock before the membership change, so a linked drainer is\nreleased and drops its entry while the streams are still grouped.\n\nThe window was opened when snd_pcm_link_rwsem stopped being held across\nthe wait and the removal became conditional on group membership (see\nFixes). The later switch to finish_wait() kept that conditional removal,\nso the signal/timeout case remained.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80716",
          "url": "https://www.suse.com/security/cve/CVE-2026-80716"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277837 for CVE-2026-80716",
          "url": "https://bugzilla.suse.com/1277837"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1277838 for CVE-2026-80716",
          "url": "https://bugzilla.suse.com/1277838"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-80716"
    },
    {
      "cve": "CVE-2026-80737",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80737"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: amba-pl011: synchronize DMA teardown\n\ndmaengine_terminate_all() does not wait for a running callback, so the TX\ncallback can still touch the TX buffer after it is freed. The RX poll\ntimer reads the RX buffers without the port lock.\n\nSwitch to dmaengine_terminate_sync() and delete the RX timer before\nfreeing the buffers.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80737",
          "url": "https://www.suse.com/security/cve/CVE-2026-80737"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279487 for CVE-2026-80737",
          "url": "https://bugzilla.suse.com/1279487"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279488 for CVE-2026-80737",
          "url": "https://bugzilla.suse.com/1279488"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-80737"
    },
    {
      "cve": "CVE-2026-80909",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80909"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Reject UVD message with invalid number of h265 refs\n\nSame change as for h264, avoids overflow later when calculating\nmin dpb size.\n\n(cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
          "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
          "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80909",
          "url": "https://www.suse.com/security/cve/CVE-2026-80909"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279422 for CVE-2026-80909",
          "url": "https://bugzilla.suse.com/1279422"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279423 for CVE-2026-80909",
          "url": "https://bugzilla.suse.com/1279423"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Linux Enterprise Micro 5.3:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.3:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch",
            "SUSE Linux Enterprise Micro 5.4:kernel-rt-0:5.14.21-150400.15.186.1.x86_64",
            "SUSE Linux Enterprise Micro 5.4:kernel-source-rt-0:5.14.21-150400.15.186.1.noarch"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-22T08:32:05Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-80909"
    }
  ]
}