{"schema_version":"1.7.3","id":"SUSE-SU-2025:1573-1","published":"2025-05-16T16:32:08Z","modified":"2026-02-04T03:47:49.619089Z","related":["CVE-2021-47671","CVE-2022-49741","CVE-2024-46784","CVE-2025-21726","CVE-2025-21785","CVE-2025-21791","CVE-2025-21812","CVE-2025-21886","CVE-2025-22004","CVE-2025-22020","CVE-2025-22029","CVE-2025-22045","CVE-2025-22055","CVE-2025-22097"],"upstream":["CVE-2021-47671","CVE-2022-49741","CVE-2024-46784","CVE-2025-21726","CVE-2025-21785","CVE-2025-21791","CVE-2025-21812","CVE-2025-21886","CVE-2025-22004","CVE-2025-22020","CVE-2025-22029","CVE-2025-22045","CVE-2025-22055","CVE-2025-22097"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP4 RT kernel was updated to receive various security bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2025-21726: padata: avoid UAF for reorder_work (bsc#1238865).\n- CVE-2025-21785: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array (bsc#1238747).\n- CVE-2025-21791: vrf: use RCU protection in l3mdev_l3_out() (bsc#1238512).\n- CVE-2025-21812: ax25: rcu protect dev->ax25_ptr (bsc#1238471).\n- CVE-2025-22004: net: atm: fix use after free in lec_send() (bsc#1240835).\n- CVE-2025-22020: memstick: rtsx_usb_ms: Fix slab-use-after-free in rtsx_usb_ms_drv_remove (bsc#1241280).\n- CVE-2025-22029: exec: fix the racy usage of fs_struct->in_exec (bsc#1241378).\n- CVE-2025-22045: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs (bsc#1241433).\n- CVE-2025-22055: net: fix geneve_opt length integer overflow (bsc#1241371).\n- CVE-2025-22097: drm/vkms: Fix use after free and double free on init error (bsc#1241541).\n\nThe following non-security bugs were fixed:\n\n- scsi: smartpqi: Add ctrl ready timeout module parameter (jsc#PED-1557, bsc#1201855, bsc#1240553).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.118.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.118.1","kernel-source-rt":"5.14.21-150400.15.118.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1573-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.118.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.118.1","kernel-source-rt":"5.14.21-150400.15.118.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1573-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.118.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.118.1","kernel-source-rt":"5.14.21-150400.15.118.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1573-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.118.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.118.1","kernel-source-rt":"5.14.21-150400.15.118.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2025:1573-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-20251573-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230771"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238471"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238512"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1238865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1239968"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240188"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240553"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240747"},{"type":"REPORT","url":"https://bugzilla.suse.com/1240835"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241280"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241371"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241378"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241433"},{"type":"REPORT","url":"https://bugzilla.suse.com/1241541"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-47671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-49741"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-46784"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21785"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21791"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21812"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21886"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22004"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22020"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22029"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22055"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22097"}]}