{"schema_version":"1.7.5","id":"SUSE-SU-2026:2591-1","published":"2026-06-23T14:31:51Z","modified":"2026-06-24T09:00:17.492290835Z","related":["CVE-2025-38549","CVE-2025-68324","CVE-2026-23303","CVE-2026-23327","CVE-2026-23359","CVE-2026-23438","CVE-2026-23444","CVE-2026-31396","CVE-2026-31446","CVE-2026-31448","CVE-2026-31454","CVE-2026-31455","CVE-2026-31464","CVE-2026-31473","CVE-2026-31480","CVE-2026-31493","CVE-2026-3150","CVE-2026-31516","CVE-2026-31518","CVE-2026-31546","CVE-2026-31590","CVE-2026-31591","CVE-2026-31596","CVE-2026-31613","CVE-2026-31614","CVE-2026-31629","CVE-2026-31655","CVE-2026-31671","CVE-2026-31673","CVE-2026-31678","CVE-2026-31703","CVE-2026-31758","CVE-2026-31767","CVE-2026-31774","CVE-2026-43009","CVE-2026-43013","CVE-2026-43026","CVE-2026-43030","CVE-2026-43040","CVE-2026-43052","CVE-2026-43054","CVE-2026-43059","CVE-2026-43065","CVE-2026-43066","CVE-2026-43068","CVE-2026-43109","CVE-2026-43150","CVE-2026-43206","CVE-2026-43234","CVE-2026-43249","CVE-2026-43252","CVE-2026-43261","CVE-2026-43284","CVE-2026-43296","CVE-2026-43325","CVE-2026-43333","CVE-2026-43338","CVE-2026-43341","CVE-2026-43359","CVE-2026-43360","CVE-2026-43361","CVE-2026-43362","CVE-2026-43406","CVE-2026-43407","CVE-2026-43411","CVE-2026-43413","CVE-2026-43414","CVE-2026-43455","CVE-2026-43470","CVE-2026-43483","CVE-2026-43499","CVE-2026-43501","CVE-2026-45842","CVE-2026-45843","CVE-2026-45846","CVE-2026-45852","CVE-2026-45856","CVE-2026-45878","CVE-2026-45886","CVE-2026-45898","CVE-2026-45910","CVE-2026-45932","CVE-2026-45970","CVE-2026-45983","CVE-2026-45984","CVE-2026-46004","CVE-2026-46021","CVE-2026-46024","CVE-2026-46043","CVE-2026-46079","CVE-2026-46083","CVE-2026-46090","CVE-2026-46094","CVE-2026-46110","CVE-2026-46111","CVE-2026-46113","CVE-2026-46114","CVE-2026-46157","CVE-2026-46159","CVE-2026-46176","CVE-2026-46181","CVE-2026-46209"],"upstream":["CVE-2025-38549","CVE-2025-68324","CVE-2026-23303","CVE-2026-23327","CVE-2026-23359","CVE-2026-23438","CVE-2026-23444","CVE-2026-31396","CVE-2026-31446","CVE-2026-31448","CVE-2026-31454","CVE-2026-31455","CVE-2026-31464","CVE-2026-31473","CVE-2026-31480","CVE-2026-31493","CVE-2026-3150","CVE-2026-31516","CVE-2026-31518","CVE-2026-31546","CVE-2026-31590","CVE-2026-31591","CVE-2026-31596","CVE-2026-31613","CVE-2026-31614","CVE-2026-31629","CVE-2026-31655","CVE-2026-31671","CVE-2026-31673","CVE-2026-31678","CVE-2026-31703","CVE-2026-31758","CVE-2026-31767","CVE-2026-31774","CVE-2026-43009","CVE-2026-43013","CVE-2026-43026","CVE-2026-43030","CVE-2026-43040","CVE-2026-43052","CVE-2026-43054","CVE-2026-43059","CVE-2026-43065","CVE-2026-43066","CVE-2026-43068","CVE-2026-43109","CVE-2026-43150","CVE-2026-43206","CVE-2026-43234","CVE-2026-43249","CVE-2026-43252","CVE-2026-43261","CVE-2026-43284","CVE-2026-43296","CVE-2026-43325","CVE-2026-43333","CVE-2026-43338","CVE-2026-43341","CVE-2026-43359","CVE-2026-43360","CVE-2026-43361","CVE-2026-43362","CVE-2026-43406","CVE-2026-43407","CVE-2026-43411","CVE-2026-43413","CVE-2026-43414","CVE-2026-43455","CVE-2026-43470","CVE-2026-43483","CVE-2026-43499","CVE-2026-43501","CVE-2026-45842","CVE-2026-45843","CVE-2026-45846","CVE-2026-45852","CVE-2026-45856","CVE-2026-45878","CVE-2026-45886","CVE-2026-45898","CVE-2026-45910","CVE-2026-45932","CVE-2026-45970","CVE-2026-45983","CVE-2026-45984","CVE-2026-46004","CVE-2026-46021","CVE-2026-46024","CVE-2026-46043","CVE-2026-46079","CVE-2026-46083","CVE-2026-46090","CVE-2026-46094","CVE-2026-46110","CVE-2026-46111","CVE-2026-46113","CVE-2026-46114","CVE-2026-46157","CVE-2026-46159","CVE-2026-46176","CVE-2026-46181","CVE-2026-46209"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235).\n- CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416).\n- CVE-2026-3150: bcache: fix cached_dev.sb_bio use-after-free and crash (bsc#1263169).\n- CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502).\n- CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()\n  (bsc#1260548).\n- CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584).\n- CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619).\n- CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307).\n- CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791).\n- CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619).\n- CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622).\n- CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624).\n- CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615).\n- CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656).\n- CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663).\n- CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634).\n- CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668).\n- CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755).\n- CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606).\n- CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006).\n- CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152).\n- CVE-2026-31591: KVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish (bsc#1263122).\n- CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319).\n- CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769).\n- CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774).\n- CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790).\n- CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724).\n- CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115).\n- CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143).\n- CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562).\n- CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883).\n- CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093).\n- CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124).\n- CVE-2026-31774: io_uring/net: fix slab-out-of-bounds read in io_bundle_nbufs() (bsc#1264040).\n- CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011).\n- CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932).\n- CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000).\n- CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-\n  leak (bsc#1264091).\n- CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945).\n- CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063).\n- CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184).\n- CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243).\n- CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245).\n- CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255).\n- CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484).\n- CVE-2026-43150: perf/arm-cmn: Ensure dtm_idx is big enough (bsc#1264415).\n- CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551).\n- CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409).\n- CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476).\n- CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300).\n- CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430).\n- CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805).\n- CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110).\n- CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726).\n- CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716).\n- CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044).\n- CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719).\n- CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720).\n- CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722).\n- CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989).\n- CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073).\n- CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020).\n- CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672).\n- CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671).\n- CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669).\n- CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765).\n- CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128).\n- CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240).\n- CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001).\n- CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009).\n- CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400).\n- CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395).\n- CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394).\n- CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711).\n- CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720).\n- CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767).\n- CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810).\n- CVE-2026-45898: RDMA/iwcm: Fix workqueue list corruption by removing work_list (bsc#1266888).\n- CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889).\n- CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827).\n- CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205).\n- CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697).\n- CVE-2026-45984: gfs2: Add metapath_dibh helper (bsc#1267214).\n- CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222).\n- CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).\n- CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218).\n- CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901).\n- CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452).\n- CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696).\n- CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531).\n- CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access (bsc#1266927).\n- CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759).\n- CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626).\n- CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969).\n- CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972).\n- CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726).\n- CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652).\n- CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816).\n- CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826).\n- CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663).\n- CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (bsc#1266238).\n\nThe following non security issues were fixed:\n\n- accel/ivpu: Add buffer overflow check in MS get_info_ioctl (git-fixes).\n- ACPI: x86: cmos_rtc: Clean up address space handler driver (stable-fixes).\n- ACPI: x86: cmos_rtc: Improve coordination with ACPI TAD driver (git-fixes).\n- ALSA: asihpi: Fix potential OOB array access at reading cache (stable-fixes).\n- ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes).\n- ALSA: pcm: Don't setup bogus iov_iter for silencing (git-fixes).\n- ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes).\n- ALSA: pcm: oss: Fix setup list UAF on proc write error (git-fixes).\n- ALSA: sc6000: Keep the programmed board state in card-private data (git-fixes).\n- ALSA: sc6000: Use standard print API (stable-fixes).\n- ALSA: scarlett2: Fix 2i2 Gen 4 direct monitor gain on firmware 2417 (git-fixes).\n- ALSA: seq: avoid past-the-end iterator in snd_seq_create_port() (git-fixes).\n- ALSA: seq: dummy: fix UMP event stack overread (git-fixes).\n- ALSA: seq: Serialize UMP output teardown with event_input (git-fixes).\n- ALSA: timer: avoid past-the-end iterator in snd_timer_dev_register() (git-fixes).\n- ALSA: ua101: Reject too-short USB descriptors (git-fixes).\n- ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes).\n- ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes).\n- arm64: tlb: Allow XZR argument to TLBI ops (git-fixes).\n- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes).\n- ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes).\n- ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes).\n- ASoC: Intel: bytcht_es8316: Fix MCLK leak on init errors (git-fixes).\n- ASoC: qcom: q6asm-dai: close stream only when running (git-fixes).\n- ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes).\n- ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git-fixes).\n- ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes).\n- ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes).\n- ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes).\n- auxdisplay: line-display: fix OOB read on zero-length message_store() (git-fixes).\n- batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes).\n- batman-adv: clear current gateway during teardown (git-fixes).\n- batman-adv: dat: handle forward allocation error (git-fixes).\n- batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes).\n- batman-adv: fix fragment reassembly length accounting (git-fixes).\n- batman-adv: fix tp_meter counter underflow during shutdown (git-fixes).\n- batman-adv: frag: disallow unicast fragment in fragment (git-fixes).\n- batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes).\n- batman-adv: tt: fix negative last_changeset_len (git-fixes).\n- batman-adv: tt: fix negative tt_buff_len (git-fixes).\n- bcache: fix uninitialized closure object (git-fixes).\n- Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git-fixes).\n- Bluetooth: bnep: Fix UAF read of dev->name (git-fixes).\n- Bluetooth: bnep: reject short frames before parsing (git-fixes).\n- Bluetooth: btmtk: fix urb->setup_packet leak in error paths (git-fixes).\n- Bluetooth: btusb: Allow firmware re-download when version matches (git-fixes).\n- Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git-fixes).\n- Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (git-fixes).\n- Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git-fixes).\n- Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git-fixes).\n- Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes).\n- Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git-fixes).\n- Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git-fixes).\n- Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes).\n- Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes).\n- Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git-fixes).\n- Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer (git-fixes).\n- Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git-fixes).\n- Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes).\n- Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git-fixes).\n- Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes).\n- Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes).\n- Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes).\n- Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes).\n- Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes).\n- Bluetooth: serialize accept_q access (git-fixes).\n- cgroup: Increment nr_dying_subsys_* from rmdir context (git-fixes).\n- comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes).\n- comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes).\n- device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes).\n- dm: fix a buffer overflow in ioctl processing (git-fixes).\n- drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes).\n- drm/amd/display: Bound VBIOS record-chain walk loops (git-fixes).\n- drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git-fixes).\n- drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes).\n- drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git-fixes).\n- drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes).\n- drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes).\n- drm/amd/display: Validate GPIO pin LUT table size before iterating (stable-fixes).\n- drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes).\n- drm/amd/pm/si: Disregard vblank time when no displays are connected (git-fixes).\n- drm/amdgpu/uvd3.1: Don't validate the firmware when already validated (git-fixes).\n- drm/amdgpu/uvd4.2: Don't initialize UVD 4.2 when DPM is disabled (git-fixes).\n- drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes).\n- drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes).\n- drm/amdgpu/vpe: Force collaborate sync after TRAP (stable-fixes).\n- drm/amdgpu: add amdgpu_device reference in ip block (stable-fixes).\n- drm/amdgpu: fix spelling typos (stable-fixes).\n- drm/amdgpu: update the handle ptr in dump_ip_state (stable-fixes).\n- drm/amdgpu: update the handle ptr in early_init (stable-fixes).\n- drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes).\n- drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes).\n- drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git-fixes).\n- drm/bridge: it66121: acquire reset GPIO in probe (git-fixes).\n- drm/bridge: megachips: remove bridge when irq request fails (git-fixes).\n- drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes).\n- drm/hyperv: validate VMBus packet size in receive callback (git-fixes).\n- drm/i915/dp: Fix readback for target_rr in Adaptive Sync SDP (git-fixes).\n- drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes).\n- drm/i915: Fix potential UAF in TTM object purge (git-fixes).\n- drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable-fixes).\n- drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes).\n- drm/msm/dsi: don't dump registers past the mapped region (git-fixes).\n- drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes).\n- drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes).\n- drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups (git-fixes).\n- drm/virtio: use uninterruptible resv lock for plane updates (git-fixes).\n- drm/xe/gsc: Fix double-free of managed BO in error path (git-fixes).\n- drm/xe/oa: Fix exec_queue leak on width check in stream open (git-fixes).\n- drm/xe/pf: Fix CFI failure in debugfs access (git-fixes).\n- drm/xe/vf: Fix signature of print functions (git-fixes).\n- drm/xe: Clear pending_disable before signaling suspend fence (git-fixes).\n- drm/xe: Define CACHE_MODE_1 as MCR register (git-fixes).\n- efi: Allocate runtime workqueue before ACPI init (git-fixes).\n- firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes).\n- firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes).\n- gve: Add RSS cache for non RSS device option scenario (bsc#1265925).\n- gve: add XDP DROP and PASS support for DQ (bsc#1265925).\n- gve: Enable reading max ring size from the device in DQO-QPL mode (bsc#1265925).\n- gve: introduce config-based allocation for XDP (bsc#1265925).\n- gve: merge packet buffer size fields (bsc#1265925).\n- gve: process XSK TX descriptors as part of RX NAPI (bsc#1265925).\n- gve: remove xdp_xsk_done and xdp_xsk_wakeup statistics (bsc#1265925).\n- gve: trigger RX NAPI instead of TX NAPI in gve_xsk_wakeup (bsc#1265925).\n- gve: update GQ RX to use buf_size (bsc#1265925).\n- gve: Update QPL page registration logic (bsc#1265925).\n- gve: update XDP allocation path support RX buffer posting (bsc#1265925).\n- HID: quirks: really enable the intended work around for appledisplay (git-fixes).\n- HID: uclogic: Fix regression of input name assignment (git-fixes).\n- HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes).\n- hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes).\n- hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes).\n- hwmon: (pmbus/adm1266) don't clobber GPIO bits before PDIO read in get_multiple (git-fixes).\n- hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git-fixes).\n- hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes).\n- hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git-fixes).\n- hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes).\n- hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes).\n- hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes).\n- hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes).\n- hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes).\n- iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes).\n- iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git-fixes).\n- iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes).\n- iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes).\n- iio: dac: ad5686: fix input raw value check (git-fixes).\n- iio: dac: max5821: fix return value check in powerdown sync (git-fixes).\n- iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes).\n- iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes).\n- iio: light: cm3323: fix reg_conf not being initialized correctly (git-fixes).\n- iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git-fixes).\n- iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes).\n- iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes).\n- Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git-fixes).\n- Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes).\n- Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes).\n- Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git-fixes).\n- Input: xpad - fix out-of-bounds access for Share button (git-fixes).\n- KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git-fixes).\n- KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes).\n- KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes).\n- KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes).\n- mmc: core: Fix host controller programming for fixed driver type (git-fixes).\n- mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes).\n- mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git-fixes).\n- mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes).\n- mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes).\n- net: gro: don't merge zcopy skbs (git-fixes).\n- net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes).\n- net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414).\n- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928).\n- net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes).\n- net: mana: Skip redundant detach on already-detached port (git-fixes).\n- net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765).\n- net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765).\n- net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402).\n- net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes).\n- nvme-pci: add NVME_QUIRK_DISABLE_WRITE_ZEROES for Kingston OM3SGP4 (git-fixes).\n- parport: Fix race between port and client registration (git-fixes).\n- phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes).\n- platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes).\n- platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes).\n- platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes).\n- platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes).\n- r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes).\n- RDMA/efa: Check stored completion CTX command ID with received one (git-fixes).\n- RDMA/efa: Extend admin timeout error print (git-fixes).\n- RDMA/efa: Fix possible deadlock (git-fixes).\n- RDMA/efa: Improve admin completion context state machine (git-fixes).\n- RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes).\n- s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1261591).\n- s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068).\n- s390/entry: Scrub r12 register on kernel entry (bsc#1261591).\n- s390/entry: Scrub r12 register on kernel entry (bsc#1263068).\n- s390/mm: Add missing secure storage access fixups for donated memory (bsc#1264835).\n- s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1261591).\n- s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068).\n- sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649).\n- scsi: qla2xxx: Add support to report MPI FW state (git-fixes).\n- scsi: ses: Handle positive SCSI error from ses_recv_diag() (git-fixes).\n- security/keys: fix missed RCU read section on lookup (stable-fixes).\n- serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git-fixes).\n- serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes).\n- smb: client: correctly handle ErrorContextData as a flexible array (git-fixes).\n- soundwire: debugfs: initialize firmware_file to empty string (git-fixes).\n- spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes).\n- spi: sprd: fix error pointer deref after DMA setup failure (git-fixes).\n- spi: st-ssc4: switch to use modern name (stable-fixes).\n- spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes).\n- string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes).\n- thermal: core: Free thermal zone ID later during removal (git-fixes).\n- thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes).\n- thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git-fixes).\n- tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634).\n- tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes).\n- USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git-fixes).\n- usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes).\n- usb: chipidea: core: convert ci_role_switch to local variable (git-fixes).\n- usb: dwc2: Fix use after free in debug code (git-fixes).\n- usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes).\n- usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes).\n- usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes).\n- usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes).\n- usb: gadget: net2280: Fix double free in probe error path (git-fixes).\n- USB: serial: belkin_sa: validate interrupt status length (git-fixes).\n- USB: serial: cypress_m8: validate interrupt packet headers (git-fixes).\n- USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes).\n- USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git-fixes).\n- USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes).\n- USB: serial: omninet: fix memory corruption with small endpoint (git-fixes).\n- USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git-fixes).\n- USB: serial: safe_serial: fix memory corruption with small endpoint (git-fixes).\n- usb: typec: tcpm: improve handling of DISCOVER_MODES failures (git-fixes).\n- usb: usbtmc: check URB actual_length for interrupt-IN notifications (git-fixes).\n- usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git-fixes).\n- usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes).\n- wifi: ath10k: skip WMI and beacon transmission when device is wedged (git-fixes).\n- wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes).\n- wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes).\n- wifi: ath11k: fix error path leaks in some WMI calls (git-fixes).\n- wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes).\n- wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes).\n- wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git-fixes).\n- wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes).\n- wifi: mac80211: consume only present negotiated TTLM maps (git-fixes).\n- wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes).\n- wifi: nl80211: reject oversized EMA RNR lists (git-fixes).\n","affected":[{"package":{"name":"kernel-livepatch-SLE15-SP7-RT_Update_16","ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP7","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP7-RT_Update_16&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1-150700.1.5.2"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-6_4_0-150700_7_59-rt":"1-150700.1.5.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2591-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.59.2"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.59.2","dlm-kmp-rt":"6.4.0-150700.7.59.2","gfs2-kmp-rt":"6.4.0-150700.7.59.2","kernel-devel-rt":"6.4.0-150700.7.59.2","kernel-rt":"6.4.0-150700.7.59.2","kernel-rt-devel":"6.4.0-150700.7.59.2","kernel-source-rt":"6.4.0-150700.7.59.2","kernel-syms-rt":"6.4.0-150700.7.59.1","ocfs2-kmp-rt":"6.4.0-150700.7.59.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2591-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.59.2"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.59.2","dlm-kmp-rt":"6.4.0-150700.7.59.2","gfs2-kmp-rt":"6.4.0-150700.7.59.2","kernel-devel-rt":"6.4.0-150700.7.59.2","kernel-rt":"6.4.0-150700.7.59.2","kernel-rt-devel":"6.4.0-150700.7.59.2","kernel-source-rt":"6.4.0-150700.7.59.2","kernel-syms-rt":"6.4.0-150700.7.59.1","ocfs2-kmp-rt":"6.4.0-150700.7.59.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2591-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.59.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.59.2","dlm-kmp-rt":"6.4.0-150700.7.59.2","gfs2-kmp-rt":"6.4.0-150700.7.59.2","kernel-devel-rt":"6.4.0-150700.7.59.2","kernel-rt":"6.4.0-150700.7.59.2","kernel-rt-devel":"6.4.0-150700.7.59.2","kernel-source-rt":"6.4.0-150700.7.59.2","kernel-syms-rt":"6.4.0-150700.7.59.1","ocfs2-kmp-rt":"6.4.0-150700.7.59.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2591-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262591-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248235"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255416"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258538"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260502"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260548"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260584"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261791"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262615"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262622"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262624"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262649"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262663"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263006"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263068"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263115"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263122"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263143"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263152"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263169"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263319"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263724"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263769"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263774"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263790"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263883"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263932"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264011"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264014"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264040"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264063"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264091"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264093"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264124"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264243"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264245"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264300"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264409"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264415"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264476"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264551"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264669"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264671"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264716"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264720"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264765"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264805"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264835"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264989"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265020"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265044"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265073"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265110"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265128"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265240"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265579"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265928"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266214"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266394"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266395"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266400"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266402"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266452"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266696"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266697"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266711"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266720"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266759"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266765"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266767"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266810"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266816"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266826"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266827"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266889"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266969"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266972"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267214"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267218"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267220"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267222"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267626"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267652"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267663"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267732"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-38549"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68324"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23327"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23438"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23444"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31396"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31446"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31448"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31473"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31480"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31493"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-3150"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31546"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31590"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31591"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31596"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31613"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31614"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31655"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31671"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31673"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31758"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31767"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31774"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43013"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43026"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43030"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43054"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43065"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43066"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43068"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43109"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43150"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43206"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43234"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43249"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43252"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43261"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43296"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43325"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43333"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43341"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43360"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43361"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43362"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43413"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43414"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43470"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43483"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45842"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45843"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45878"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45886"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45898"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45910"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45932"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45970"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45983"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46004"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46021"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46111"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46113"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46114"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46159"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46181"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46209"}]}