SUSE update for the Linux Kernel



Risk Low
Patch available YES
Number of vulnerabilities 72
CVE-ID CVE-2023-52924
CVE-2023-52925
CVE-2024-26708
CVE-2024-26810
CVE-2024-40980
CVE-2024-41055
CVE-2024-44974
CVE-2024-45009
CVE-2024-45010
CVE-2024-47701
CVE-2024-49884
CVE-2024-49950
CVE-2024-50029
CVE-2024-50036
CVE-2024-50073
CVE-2024-50085
CVE-2024-50115
CVE-2024-50142
CVE-2024-50185
CVE-2024-50294
CVE-2024-53123
CVE-2024-53147
CVE-2024-53173
CVE-2024-53176
CVE-2024-53177
CVE-2024-53178
CVE-2024-53226
CVE-2024-53239
CVE-2024-56539
CVE-2024-56548
CVE-2024-56568
CVE-2024-56579
CVE-2024-56605
CVE-2024-56633
CVE-2024-56647
CVE-2024-56720
CVE-2024-57889
CVE-2024-57948
CVE-2024-57994
CVE-2025-21636
CVE-2025-21637
CVE-2025-21638
CVE-2025-21639
CVE-2025-21640
CVE-2025-21647
CVE-2025-21665
CVE-2025-21667
CVE-2025-21668
CVE-2025-21673
CVE-2025-21680
CVE-2025-21681
CVE-2025-21684
CVE-2025-21687
CVE-2025-21688
CVE-2025-21689
CVE-2025-21690
CVE-2025-21692
CVE-2025-21697
CVE-2025-21699
CVE-2025-21700
CVE-2025-21705
CVE-2025-21715
CVE-2025-21716
CVE-2025-21719
CVE-2025-21724
CVE-2025-21725
CVE-2025-21728
CVE-2025-21767
CVE-2025-21790
CVE-2025-21795
CVE-2025-21799
CVE-2025-21802
CWE-ID CWE-401
CWE-399
CWE-362
CWE-667
CWE-476
CWE-416
CWE-415
CWE-682
CWE-125
CWE-20
CWE-617
CWE-369
CWE-119
CWE-388
CWE-835
CWE-908
Exploitation vector Local
Public exploit N/A
Vulnerable software
SUSE Linux Enterprise High Availability Extension 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Workstation Extension 15
Operating systems & Components / Operating system

Legacy Module
Operating systems & Components / Operating system

SUSE Linux Enterprise Live Patching
Operating systems & Components / Operating system

Development Tools Module
Operating systems & Components / Operating system

Basesystem Module
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop 15
Operating systems & Components / Operating system

kernel-64kb
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-exynos
Operating systems & Components / Operating system package or component

kernel-64kb-devel
Operating systems & Components / Operating system package or component

dtb-amlogic
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-renesas
Operating systems & Components / Operating system package or component

dtb-socionext
Operating systems & Components / Operating system package or component

dtb-nvidia
Operating systems & Components / Operating system package or component

dtb-mediatek
Operating systems & Components / Operating system package or component

dlm-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-amd
Operating systems & Components / Operating system package or component

dtb-cavium
Operating systems & Components / Operating system package or component

kernel-64kb-extra
Operating systems & Components / Operating system package or component

kernel-64kb-debugsource
Operating systems & Components / Operating system package or component

dtb-apm
Operating systems & Components / Operating system package or component

dtb-freescale
Operating systems & Components / Operating system package or component

dtb-amazon
Operating systems & Components / Operating system package or component

dtb-xilinx
Operating systems & Components / Operating system package or component

kernel-64kb-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-optional-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-qcom
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-optional
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-lg
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-broadcom
Operating systems & Components / Operating system package or component

dtb-allwinner
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb
Operating systems & Components / Operating system package or component

kernel-64kb-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-marvell
Operating systems & Components / Operating system package or component

dtb-arm
Operating systems & Components / Operating system package or component

dtb-rockchip
Operating systems & Components / Operating system package or component

dtb-apple
Operating systems & Components / Operating system package or component

dtb-hisilicon
Operating systems & Components / Operating system package or component

dlm-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-sprd
Operating systems & Components / Operating system package or component

dtb-altera
Operating systems & Components / Operating system package or component

dtb-aarch64
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debugsource
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debuginfo
Operating systems & Components / Operating system package or component

kernel-zfcpdump
Operating systems & Components / Operating system package or component

kernel-kvmsmall
Operating systems & Components / Operating system package or component

kernel-livepatch-6_4_0-150600_23_42-default
Operating systems & Components / Operating system package or component

kernel-livepatch-SLE15-SP6_Update_9-debugsource
Operating systems & Components / Operating system package or component

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-default
Operating systems & Components / Operating system package or component

ocfs2-kmp-default
Operating systems & Components / Operating system package or component

gfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-extra
Operating systems & Components / Operating system package or component

gfs2-kmp-default
Operating systems & Components / Operating system package or component

kselftests-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-livepatch
Operating systems & Components / Operating system package or component

cluster-md-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-qa
Operating systems & Components / Operating system package or component

reiserfs-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-syms
Operating systems & Components / Operating system package or component

kernel-default-optional
Operating systems & Components / Operating system package or component

kselftests-kmp-default
Operating systems & Components / Operating system package or component

kernel-default-devel
Operating systems & Components / Operating system package or component

dlm-kmp-default
Operating systems & Components / Operating system package or component

kernel-obs-build-debugsource
Operating systems & Components / Operating system package or component

reiserfs-kmp-default
Operating systems & Components / Operating system package or component

dlm-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-build
Operating systems & Components / Operating system package or component

kernel-default-optional-debuginfo
Operating systems & Components / Operating system package or component

cluster-md-kmp-default
Operating systems & Components / Operating system package or component

kernel-default-debugsource
Operating systems & Components / Operating system package or component

ocfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-base
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debugsource
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel
Operating systems & Components / Operating system package or component

kernel-default-base-rebuild
Operating systems & Components / Operating system package or component

kernel-debug-vdso-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-vdso-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-vdso
Operating systems & Components / Operating system package or component

kernel-debug-vdso
Operating systems & Components / Operating system package or component

kernel-kvmsmall-vdso
Operating systems & Components / Operating system package or component

kernel-kvmsmall-vdso-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug-devel
Operating systems & Components / Operating system package or component

kernel-debug-debugsource
Operating systems & Components / Operating system package or component

kernel-debug-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug
Operating systems & Components / Operating system package or component

kernel-source-vanilla
Operating systems & Components / Operating system package or component

kernel-devel
Operating systems & Components / Operating system package or component

kernel-source
Operating systems & Components / Operating system package or component

kernel-docs-html
Operating systems & Components / Operating system package or component

kernel-macros
Operating systems & Components / Operating system package or component

kernel-docs
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 72 vulnerabilities.

1) Memory leak

EUVDB-ID: #VU103660

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-52924

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the nft_rbtree_walk() function in net/netfilter/nft_set_rbtree.c, within the nft_rhash_walk() function in net/netfilter/nft_set_hash.c, within the nf_tables_dump_setelem() function in net/netfilter/nf_tables_api.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Resource management error

EUVDB-ID: #VU103661

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2023-52925

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the nft_pipapo_get(), nft_pipapo_activate() and nft_pipapo_remove() functions in net/netfilter/nft_set_pipapo.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Race condition

EUVDB-ID: #VU93430

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-26708

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition within the subflow_simultaneous_connect() function in net/mptcp/protocol.h. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Improper locking

EUVDB-ID: #VU91318

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-26810

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the vfio_send_intx_eventfd(), vfio_pci_intx_mask(), vfio_pci_intx_unmask_handler(), vfio_pci_set_intx_unmask() and vfio_pci_set_intx_mask() functions in drivers/vfio/pci/vfio_pci_intrs.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Improper locking

EUVDB-ID: #VU94270

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-40980

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the reset_per_cpu_data(), trace_drop_common(), net_dm_hw_reset_per_cpu_data(), net_dm_hw_summary_probe() and __net_dm_cpu_data_init() functions in net/core/drop_monitor.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) NULL pointer dereference

EUVDB-ID: #VU94979

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-41055

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the include/linux/mmzone.h. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Use-after-free

EUVDB-ID: #VU96834

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-44974

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the lookup_subflow_by_daddr(), select_local_address(), select_signal_address(), __lookup_addr() and mptcp_pm_create_subflow_or_signal_addr() functions in net/mptcp/pm_netlink.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Resource management error

EUVDB-ID: #VU97191

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-45009

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the mptcp_pm_nl_rm_addr_or_subflow() function in net/mptcp/pm_netlink.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Resource management error

EUVDB-ID: #VU97192

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-45010

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the mptcp_pm_nl_rm_addr_or_subflow(), mptcp_pm_remove_anno_addr(), mptcp_nl_remove_subflow_and_signal_addr(), mptcp_nl_remove_id_zero_address() and mptcp_pm_nl_fullmesh() functions in net/mptcp/pm_netlink.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Use-after-free

EUVDB-ID: #VU98898

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-47701

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the ext4_find_inline_entry() function in fs/ext4/inline.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Use-after-free

EUVDB-ID: #VU98867

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-49884

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the ext4_split_extent_at() and ext4_ext_dirty() functions in fs/ext4/extents.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Use-after-free

EUVDB-ID: #VU98876

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-49950

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the l2cap_connect_req() function in net/bluetooth/l2cap_core.c, within the hci_remote_features_evt() function in net/bluetooth/hci_event.c, within the hci_acldata_packet() function in net/bluetooth/hci_core.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Double free

EUVDB-ID: #VU99056

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50029

CWE-ID: CWE-415 - Double Free

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a double free error within the hci_enhanced_setup_sync() function in net/bluetooth/hci_conn.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Incorrect calculation

EUVDB-ID: #VU99185

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50036

CWE-ID: CWE-682 - Incorrect Calculation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect calculation within the dst_destroy() and dst_dev_put() functions in net/core/dst.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Use-after-free

EUVDB-ID: #VU99442

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50073

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the gsm_cleanup_mux() function in drivers/tty/n_gsm.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Use-after-free

EUVDB-ID: #VU99443

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50085

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the mptcp_pm_nl_rm_addr_or_subflow() function in net/mptcp/pm_netlink.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Out-of-bounds read

EUVDB-ID: #VU99810

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50115

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the nested_svm_get_tdp_pdptr() function in arch/x86/kvm/svm/nested.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

18) Input validation error

EUVDB-ID: #VU100081

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50142

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the verify_newsa_info() function in net/xfrm/xfrm_user.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

19) Reachable assertion

EUVDB-ID: #VU100131

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50185

CWE-ID: CWE-617 - Reachable Assertion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to reachable assertion within the skb_is_fully_mapped() function in net/mptcp/subflow.c, within the mptcp_check_data_fin() and __mptcp_move_skbs_from_subflow() functions in net/mptcp/protocol.c, within the SNMP_MIB_ITEM() function in net/mptcp/mib.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

20) Improper locking

EUVDB-ID: #VU100630

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-50294

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the rxrpc_connect_client_calls() and rxrpc_disconnect_client_call() functions in net/rxrpc/conn_client.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

21) Division by zero

EUVDB-ID: #VU101112

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53123

CWE-ID: CWE-369 - Divide By Zero

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a division by zero error within the mptcp_recvmsg() and pr_debug() functions in net/mptcp/protocol.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

22) Out-of-bounds read

EUVDB-ID: #VU101909

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53147

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the exfat_find() function in fs/exfat/namei.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

23) Use-after-free

EUVDB-ID: #VU102058

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53173

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the nfs4_open_release() function in fs/nfs/nfs4proc.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

24) Improper locking

EUVDB-ID: #VU102174

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53176

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the cifs_dentry_needs_reval() function in fs/smb/client/inode.c, within the init_cifs() and cifs_destroy_netfs() functions in fs/smb/client/cifsfs.c, within the free_cached_dir(), close_all_cached_dirs(), invalidate_all_cached_dirs(), cached_dir_lease_break(), init_cached_dir(), cfids_laundromat_worker(), init_cached_dirs() and free_cached_dirs() functions in fs/smb/client/cached_dir.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

25) Use-after-free

EUVDB-ID: #VU102056

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53177

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the SMB2_query_info_free(), invalidate_all_cached_dirs(), smb2_cached_lease_break(), cached_dir_lease_break() and cfids_laundromat_worker() functions in fs/smb/client/cached_dir.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

26) Memory leak

EUVDB-ID: #VU102007

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53178

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the find_or_create_cached_dir() and smb2_set_related() functions in fs/smb/client/cached_dir.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

27) NULL pointer dereference

EUVDB-ID: #VU102142

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53226

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the hns_roce_set_page() and hns_roce_map_mr_sg() functions in drivers/infiniband/hw/hns/hns_roce_mr.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

28) Use-after-free

EUVDB-ID: #VU102070

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53239

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the usb6fire_chip_abort(), usb6fire_chip_destroy(), usb6fire_chip_probe() and usb6fire_chip_disconnect() functions in sound/usb/6fire/chip.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

29) Buffer overflow

EUVDB-ID: #VU102236

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56539

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the drivers/net/wireless/marvell/mwifiex/fw.h. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

30) Use-after-free

EUVDB-ID: #VU102075

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56548

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the hfsplus_read_wrapper() function in fs/hfsplus/wrapper.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

31) NULL pointer dereference

EUVDB-ID: #VU102127

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56568

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the arm_smmu_probe_device() function in drivers/iommu/arm/arm-smmu/arm-smmu.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

32) Improper error handling

EUVDB-ID: #VU102205

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56579

CWE-ID: CWE-388 - Error Handling

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the vpu_add_func() function in drivers/media/platform/amphion/vpu_v4l2.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

33) Use-after-free

EUVDB-ID: #VU102020

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56605

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the l2cap_sock_alloc() function in net/bluetooth/l2cap_sock.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

34) Use-after-free

EUVDB-ID: #VU102025

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56633

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the sock_put() function in net/ipv4/tcp_bpf.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

35) Input validation error

EUVDB-ID: #VU102186

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56647

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the icmp_route_lookup() function in net/ipv4/icmp.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

36) Input validation error

EUVDB-ID: #VU102266

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-56720

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the sk_msg_shift_left() and BPF_CALL_4() functions in net/core/filter.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

37) Improper locking

EUVDB-ID: #VU102935

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-57889

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the ARRAY_SIZE(), mcp_pinconf_get() and mcp_pinconf_set() functions in drivers/pinctrl/pinctrl-mcp23s08.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

38) Improper error handling

EUVDB-ID: #VU103592

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-57948

CWE-ID: CWE-388 - Error Handling

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the ieee802154_if_remove() function in net/mac802154/iface.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

39) Improper locking

EUVDB-ID: #VU105028

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-57994

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the pfifo_fast_change_tx_queue_len() function in net/sched/sch_generic.c, within the tun_queue_resize() function in drivers/net/tun.c, within the tap_queue_resize() function in drivers/net/tap.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

40) NULL pointer dereference

EUVDB-ID: #VU103023

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21636

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the proc_sctp_do_udp_port() function in net/sctp/sysctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

41) NULL pointer dereference

EUVDB-ID: #VU103024

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21637

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the proc_sctp_do_auth() function in net/sctp/sysctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

42) NULL pointer dereference

EUVDB-ID: #VU103025

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21638

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the proc_sctp_do_alpha_beta() function in net/sctp/sysctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

43) NULL pointer dereference

EUVDB-ID: #VU103026

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21639

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the proc_sctp_do_hmac_alg() and proc_sctp_do_rto_min() functions in net/sctp/sysctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

44) NULL pointer dereference

EUVDB-ID: #VU103027

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21640

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the proc_sctp_do_hmac_alg() function in net/sctp/sysctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

45) Out-of-bounds read

EUVDB-ID: #VU103014

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21647

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the cake_ddst(), cake_enqueue() and cake_dequeue() functions in net/sched/sch_cake.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

46) Infinite loop

EUVDB-ID: #VU103594

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21665

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the folio_seek_hole_data() function in mm/filemap.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

47) Infinite loop

EUVDB-ID: #VU103595

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21667

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the iomap_write_delalloc_scan() function in fs/iomap/buffered-io.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

48) Out-of-bounds read

EUVDB-ID: #VU103512

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21668

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the imx8mp_blk_ctrl_remove() function in drivers/pmdomain/imx/imx8mp-blk-ctrl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

49) Double free

EUVDB-ID: #VU103515

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21673

CWE-ID: CWE-415 - Double Free

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a double free error within the clean_demultiplex_info() and cifs_put_tcp_session() functions in fs/smb/client/connect.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

50) Out-of-bounds read

EUVDB-ID: #VU103582

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21680

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the get_imix_entries() function in net/core/pktgen.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

51) Improper locking

EUVDB-ID: #VU103591

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21681

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the do_output() function in net/openvswitch/actions.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

52) Improper locking

EUVDB-ID: #VU103749

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21684

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the DECLARE_BITMAP(), xgpio_set(), xgpio_set_multiple(), xgpio_dir_in(), xgpio_dir_out(), xgpio_irq_mask(), xgpio_irq_unmask(), xgpio_irqhandler() and xgpio_probe() functions in drivers/gpio/gpio-xilinx.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

53) Incorrect calculation

EUVDB-ID: #VU103753

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21687

CWE-ID: CWE-682 - Incorrect Calculation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect calculation within the vfio_platform_read_mmio() and vfio_platform_write_mmio() functions in drivers/vfio/platform/vfio_platform_common.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

54) NULL pointer dereference

EUVDB-ID: #VU103744

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21688

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the v3d_irq() and v3d_hub_irq() functions in drivers/gpu/drm/v3d/v3d_irq.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

55) Out-of-bounds read

EUVDB-ID: #VU103742

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21689

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the qt2_process_read_urb() function in drivers/usb/serial/quatech2.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

56) Resource management error

EUVDB-ID: #VU103751

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21690

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the dev_warn() and storvsc_on_io_completion() functions in drivers/scsi/storvsc_drv.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

57) Out-of-bounds read

EUVDB-ID: #VU103743

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21692

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the ets_class_from_arg() function in net/sched/sch_ets.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

58) NULL pointer dereference

EUVDB-ID: #VU103920

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21697

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the v3d_irq() and v3d_hub_irq() functions in drivers/gpu/drm/v3d/v3d_irq.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

59) Resource management error

EUVDB-ID: #VU103923

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21699

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the do_gfs2_set_flags() function in fs/gfs2/file.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

60) Use-after-free

EUVDB-ID: #VU103959

Risk: Low

CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:U/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21700

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the qdisc_lookup() function in net/sched/sch_api.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

61) Improper locking

EUVDB-ID: #VU105030

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21705

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the mptcp_sendmsg_fastopen() function in net/mptcp/protocol.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

62) Use-after-free

EUVDB-ID: #VU104964

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21715

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the dm9000_drv_remove() function in drivers/net/ethernet/davicom/dm9000.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

63) Use of uninitialized resource

EUVDB-ID: #VU105044

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21716

CWE-ID: CWE-908 - Use of Uninitialized Resource

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the vxlan_vnifilter_dump() function in drivers/net/vxlan/vxlan_vnifilter.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

64) Race condition

EUVDB-ID: #VU105081

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21719

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition within the list_for_each_entry() function in net/ipv4/ipmr_base.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

65) Out-of-bounds read

EUVDB-ID: #VU104989

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21724

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the iova_bitmap_offset_to_index() function in drivers/vfio/iova_bitmap.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

66) Input validation error

EUVDB-ID: #VU105085

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21725

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the parse_server_interfaces() function in fs/smb/client/smb2ops.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

67) Resource management error

EUVDB-ID: #VU105066

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21728

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the bpf_send_signal_common() function in kernel/trace/bpf_trace.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

68) Improper locking

EUVDB-ID: #VU105021

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21767

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the clocksource_verify_percpu() function in kernel/time/clocksource.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

69) NULL pointer dereference

EUVDB-ID: #VU104991

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21790

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the vxlan_init() function in drivers/net/vxlan/vxlan_core.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

70) Input validation error

EUVDB-ID: #VU105087

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21795

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the nfsd4_run_cb_work() function in fs/nfsd/nfs4callback.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

71) Improper error handling

EUVDB-ID: #VU105152

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21799

CWE-ID: CWE-388 - Error Handling

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper error handling within the am65_cpsw_nuss_remove_tx_chns() function in drivers/net/ethernet/ti/am65-cpsw-nuss.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

72) Input validation error

EUVDB-ID: #VU105162

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-21802

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the hclgevf_init() function in drivers/net/ethernet/hisilicon/hns3/hns3vf/hclgevf_main.c, within the hclge_init() function in drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_main.c, within the module_init() function in drivers/net/ethernet/hisilicon/hns3/hns3_enet.c, within the EXPORT_SYMBOL() function in drivers/net/ethernet/hisilicon/hns3/hnae3.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise High Availability Extension 15: SP6

SUSE Linux Enterprise Workstation Extension 15: SP6

Legacy Module: 15-SP6

SUSE Linux Enterprise Live Patching: 15-SP6

Development Tools Module: 15-SP6

Basesystem Module: 15-SP6

SUSE Linux Enterprise Real Time 15: SP6

openSUSE Leap: 15.6

SUSE Linux Enterprise Server for SAP Applications 15: SP6

SUSE Linux Enterprise Server 15: SP6

SUSE Linux Enterprise Desktop 15: SP6

kernel-64kb: before 6.4.0-150600.23.42.2

reiserfs-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-exynos: before 6.4.0-150600.23.42.1

kernel-64kb-devel: before 6.4.0-150600.23.42.2

dtb-amlogic: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-renesas: before 6.4.0-150600.23.42.1

dtb-socionext: before 6.4.0-150600.23.42.1

dtb-nvidia: before 6.4.0-150600.23.42.1

dtb-mediatek: before 6.4.0-150600.23.42.1

dlm-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-amd: before 6.4.0-150600.23.42.1

dtb-cavium: before 6.4.0-150600.23.42.1

kernel-64kb-extra: before 6.4.0-150600.23.42.2

kernel-64kb-debugsource: before 6.4.0-150600.23.42.2

dtb-apm: before 6.4.0-150600.23.42.1

dtb-freescale: before 6.4.0-150600.23.42.1

dtb-amazon: before 6.4.0-150600.23.42.1

dtb-xilinx: before 6.4.0-150600.23.42.1

kernel-64kb-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-qcom: before 6.4.0-150600.23.42.1

kselftests-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-optional: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-lg: before 6.4.0-150600.23.42.1

reiserfs-kmp-64kb: before 6.4.0-150600.23.42.2

cluster-md-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

ocfs2-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-broadcom: before 6.4.0-150600.23.42.1

dtb-allwinner: before 6.4.0-150600.23.42.1

cluster-md-kmp-64kb: before 6.4.0-150600.23.42.2

kernel-64kb-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-64kb-debuginfo: before 6.4.0-150600.23.42.2

gfs2-kmp-64kb: before 6.4.0-150600.23.42.2

dtb-marvell: before 6.4.0-150600.23.42.1

dtb-arm: before 6.4.0-150600.23.42.1

dtb-rockchip: before 6.4.0-150600.23.42.1

dtb-apple: before 6.4.0-150600.23.42.1

dtb-hisilicon: before 6.4.0-150600.23.42.1

dlm-kmp-64kb-debuginfo: before 6.4.0-150600.23.42.2

dtb-sprd: before 6.4.0-150600.23.42.1

dtb-altera: before 6.4.0-150600.23.42.1

dtb-aarch64: before 6.4.0-150600.23.42.1

kernel-zfcpdump-debugsource: before 6.4.0-150600.23.42.2

kernel-zfcpdump-debuginfo: before 6.4.0-150600.23.42.2

kernel-zfcpdump: before 6.4.0-150600.23.42.2

kernel-kvmsmall: before 6.4.0-150600.23.42.2

kernel-livepatch-6_4_0-150600_23_42-default: before 1-150600.13.3.4

kernel-livepatch-SLE15-SP6_Update_9-debugsource: before 1-150600.13.3.4

kernel-livepatch-6_4_0-150600_23_42-default-debuginfo: before 1-150600.13.3.4

kernel-default-livepatch-devel: before 6.4.0-150600.23.42.2

kernel-default: before 6.4.0-150600.23.42.2

ocfs2-kmp-default: before 6.4.0-150600.23.42.2

gfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra: before 6.4.0-150600.23.42.2

gfs2-kmp-default: before 6.4.0-150600.23.42.2

kselftests-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-livepatch: before 6.4.0-150600.23.42.2

cluster-md-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-qa: before 6.4.0-150600.23.42.1

reiserfs-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-syms: before 6.4.0-150600.23.42.1

kernel-default-optional: before 6.4.0-150600.23.42.2

kselftests-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-devel: before 6.4.0-150600.23.42.2

dlm-kmp-default: before 6.4.0-150600.23.42.2

kernel-obs-build-debugsource: before 6.4.0-150600.23.42.2

reiserfs-kmp-default: before 6.4.0-150600.23.42.2

dlm-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-obs-build: before 6.4.0-150600.23.42.2

kernel-default-optional-debuginfo: before 6.4.0-150600.23.42.2

cluster-md-kmp-default: before 6.4.0-150600.23.42.2

kernel-default-debugsource: before 6.4.0-150600.23.42.2

ocfs2-kmp-default-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-extra-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-base: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-kvmsmall-debuginfo: before 6.4.0-150600.23.42.2

kernel-kvmsmall-debugsource: before 6.4.0-150600.23.42.2

kernel-kvmsmall-devel: before 6.4.0-150600.23.42.2

kernel-default-base-rebuild: before 6.4.0-150600.23.42.2.150600.12.18.4

kernel-debug-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-default-vdso: before 6.4.0-150600.23.42.2

kernel-debug-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso: before 6.4.0-150600.23.42.2

kernel-kvmsmall-vdso-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-devel: before 6.4.0-150600.23.42.2

kernel-debug-debugsource: before 6.4.0-150600.23.42.2

kernel-debug-devel-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug-debuginfo: before 6.4.0-150600.23.42.2

kernel-debug: before 6.4.0-150600.23.42.2

kernel-source-vanilla: before 6.4.0-150600.23.42.1

kernel-devel: before 6.4.0-150600.23.42.1

kernel-source: before 6.4.0-150600.23.42.1

kernel-docs-html: before 6.4.0-150600.23.42.1

kernel-macros: before 6.4.0-150600.23.42.1

kernel-docs: before 6.4.0-150600.23.42.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-20250856-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###