{"schema_version":"1.7.5","id":"SUSE-SU-2026:2331-1","published":"2026-06-10T08:40:38Z","modified":"2026-06-11T12:15:17.225789694Z","related":["CVE-2026-31405","CVE-2026-31629","CVE-2026-31758","CVE-2026-43037","CVE-2026-43206","CVE-2026-43499","CVE-2026-43501","CVE-2026-45852","CVE-2026-45970","CVE-2026-46021","CVE-2026-46043","CVE-2026-46113","CVE-2026-46243"],"upstream":["CVE-2026-31405","CVE-2026-31629","CVE-2026-31758","CVE-2026-43037","CVE-2026-43206","CVE-2026-43499","CVE-2026-43501","CVE-2026-45852","CVE-2026-45970","CVE-2026-46021","CVE-2026-46043","CVE-2026-46113","CVE-2026-46243"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700).\n- CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790).\n- CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093).\n- CVE-2026-43037: ip6_tunnel: clear skb2->cb in ip4ip6_err() (bsc#1263995).\n- CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551).\n- CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).\n- CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009).\n- CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711).\n- CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205).\n- CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).\n- CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901).\n- CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969).\n- CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238).\n\nThe following non security issues were fixed:\n\n- arm64: tlb: Allow XZR argument to TLBI ops (git-fixes).\n- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.170.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.170.1","kernel-source-rt":"5.14.21-150400.15.170.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2331-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.170.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.170.1","kernel-source-rt":"5.14.21-150400.15.170.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2331-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.170.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.170.1","kernel-source-rt":"5.14.21-150400.15.170.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2331-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.170.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.170.1","kernel-source-rt":"5.14.21-150400.15.170.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2331-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262331-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263790"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264551"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267220"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43206"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46113"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46243"}]}