{"schema_version":"1.7.5","id":"SUSE-SU-2026:2799-1","published":"2026-07-08T14:58:16Z","modified":"2026-07-09T10:00:04.592679052Z","related":["CVE-2025-10263","CVE-2025-40216","CVE-2025-40341","CVE-2025-68822","CVE-2025-71294","CVE-2026-23451","CVE-2026-31414","CVE-2026-31429","CVE-2026-31450","CVE-2026-31452","CVE-2026-31453","CVE-2026-31462","CVE-2026-31466","CVE-2026-31469","CVE-2026-31492","CVE-2026-31495","CVE-2026-31499","CVE-2026-31500","CVE-2026-31502","CVE-2026-31555","CVE-2026-31560","CVE-2026-31592","CVE-2026-31593","CVE-2026-31647","CVE-2026-31664","CVE-2026-31665","CVE-2026-31670","CVE-2026-31674","CVE-2026-31677","CVE-2026-31680","CVE-2026-31693","CVE-2026-31697","CVE-2026-31698","CVE-2026-31699","CVE-2026-31752","CVE-2026-31759","CVE-2026-31771","CVE-2026-43010","CVE-2026-43022","CVE-2026-43023","CVE-2026-43024","CVE-2026-43028","CVE-2026-43034","CVE-2026-43035","CVE-2026-43036","CVE-2026-43049","CVE-2026-43053","CVE-2026-43074","CVE-2026-43077","CVE-2026-43079","CVE-2026-43080","CVE-2026-43081","CVE-2026-43083","CVE-2026-43085","CVE-2026-43086","CVE-2026-43089","CVE-2026-43093","CVE-2026-43094","CVE-2026-43101","CVE-2026-43107","CVE-2026-43112","CVE-2026-43119","CVE-2026-43128","CVE-2026-43139","CVE-2026-43158","CVE-2026-43171","CVE-2026-43187","CVE-2026-43198","CVE-2026-43233","CVE-2026-43238","CVE-2026-43239","CVE-2026-43284","CVE-2026-43303","CVE-2026-43336","CVE-2026-43339","CVE-2026-43345","CVE-2026-43405","CVE-2026-43420","CVE-2026-43456","CVE-2026-43469","CVE-2026-43472","CVE-2026-43491","CVE-2026-43492","CVE-2026-43502","CVE-2026-45838","CVE-2026-45840","CVE-2026-45841","CVE-2026-45848","CVE-2026-45862","CVE-2026-45870","CVE-2026-45891","CVE-2026-45894","CVE-2026-45912","CVE-2026-45940","CVE-2026-45948","CVE-2026-45961","CVE-2026-45964","CVE-2026-45965","CVE-2026-45974","CVE-2026-45985","CVE-2026-46005","CVE-2026-46028","CVE-2026-46037","CVE-2026-46053","CVE-2026-46063","CVE-2026-46065","CVE-2026-46069","CVE-2026-46071","CVE-2026-46076","CVE-2026-46101","CVE-2026-46112","CVE-2026-46116","CVE-2026-46119","CVE-2026-46120","CVE-2026-46123","CVE-2026-46124","CVE-2026-46133","CVE-2026-46150","CVE-2026-46160","CVE-2026-46162","CVE-2026-46172","CVE-2026-46173","CVE-2026-46185","CVE-2026-46197","CVE-2026-46214","CVE-2026-46227","CVE-2026-46229","CVE-2026-46244","CVE-2026-46253","CVE-2026-46254","CVE-2026-46259","CVE-2026-46266","CVE-2026-46273","CVE-2026-46274","CVE-2026-46289","CVE-2026-46291","CVE-2026-46315","CVE-2026-46319","CVE-2026-46320","CVE-2026-46328","CVE-2026-46331","CVE-2026-52908","CVE-2026-52909","CVE-2026-52918","CVE-2026-52923","CVE-2026-52943","CVE-2026-52954","CVE-2026-52957","CVE-2026-52962","CVE-2026-52969","CVE-2026-52972","CVE-2026-53016","CVE-2026-53040","CVE-2026-53041","CVE-2026-53052","CVE-2026-53053","CVE-2026-53071","CVE-2026-53072","CVE-2026-53122","CVE-2026-53133","CVE-2026-53138","CVE-2026-53182","CVE-2026-53253","CVE-2026-53266","CVE-2026-53281","CVE-2026-53287","CVE-2026-53359","CVE-2026-53362"],"upstream":["CVE-2025-10263","CVE-2025-40216","CVE-2025-40341","CVE-2025-68822","CVE-2025-71294","CVE-2026-23451","CVE-2026-31414","CVE-2026-31429","CVE-2026-31450","CVE-2026-31452","CVE-2026-31453","CVE-2026-31462","CVE-2026-31466","CVE-2026-31469","CVE-2026-31492","CVE-2026-31495","CVE-2026-31499","CVE-2026-31500","CVE-2026-31502","CVE-2026-31555","CVE-2026-31560","CVE-2026-31592","CVE-2026-31593","CVE-2026-31647","CVE-2026-31664","CVE-2026-31665","CVE-2026-31670","CVE-2026-31674","CVE-2026-31677","CVE-2026-31680","CVE-2026-31693","CVE-2026-31697","CVE-2026-31698","CVE-2026-31699","CVE-2026-31752","CVE-2026-31759","CVE-2026-31771","CVE-2026-43010","CVE-2026-43022","CVE-2026-43023","CVE-2026-43024","CVE-2026-43028","CVE-2026-43034","CVE-2026-43035","CVE-2026-43036","CVE-2026-43049","CVE-2026-43053","CVE-2026-43074","CVE-2026-43077","CVE-2026-43079","CVE-2026-43080","CVE-2026-43081","CVE-2026-43083","CVE-2026-43085","CVE-2026-43086","CVE-2026-43089","CVE-2026-43093","CVE-2026-43094","CVE-2026-43101","CVE-2026-43107","CVE-2026-43112","CVE-2026-43119","CVE-2026-43128","CVE-2026-43139","CVE-2026-43158","CVE-2026-43171","CVE-2026-43187","CVE-2026-43198","CVE-2026-43233","CVE-2026-43238","CVE-2026-43239","CVE-2026-43284","CVE-2026-43303","CVE-2026-43336","CVE-2026-43339","CVE-2026-43345","CVE-2026-43405","CVE-2026-43420","CVE-2026-43456","CVE-2026-43469","CVE-2026-43472","CVE-2026-43491","CVE-2026-43492","CVE-2026-43502","CVE-2026-45838","CVE-2026-45840","CVE-2026-45841","CVE-2026-45848","CVE-2026-45862","CVE-2026-45870","CVE-2026-45891","CVE-2026-45894","CVE-2026-45912","CVE-2026-45940","CVE-2026-45948","CVE-2026-45961","CVE-2026-45964","CVE-2026-45965","CVE-2026-45974","CVE-2026-45985","CVE-2026-46005","CVE-2026-46028","CVE-2026-46037","CVE-2026-46053","CVE-2026-46063","CVE-2026-46065","CVE-2026-46069","CVE-2026-46071","CVE-2026-46076","CVE-2026-46101","CVE-2026-46112","CVE-2026-46116","CVE-2026-46119","CVE-2026-46120","CVE-2026-46123","CVE-2026-46124","CVE-2026-46133","CVE-2026-46150","CVE-2026-46160","CVE-2026-46162","CVE-2026-46172","CVE-2026-46173","CVE-2026-46185","CVE-2026-46197","CVE-2026-46214","CVE-2026-46227","CVE-2026-46229","CVE-2026-46244","CVE-2026-46253","CVE-2026-46254","CVE-2026-46259","CVE-2026-46266","CVE-2026-46273","CVE-2026-46274","CVE-2026-46289","CVE-2026-46291","CVE-2026-46315","CVE-2026-46319","CVE-2026-46320","CVE-2026-46328","CVE-2026-46331","CVE-2026-52908","CVE-2026-52909","CVE-2026-52918","CVE-2026-52923","CVE-2026-52943","CVE-2026-52954","CVE-2026-52957","CVE-2026-52962","CVE-2026-52969","CVE-2026-52972","CVE-2026-53016","CVE-2026-53040","CVE-2026-53041","CVE-2026-53052","CVE-2026-53053","CVE-2026-53071","CVE-2026-53072","CVE-2026-53122","CVE-2026-53133","CVE-2026-53138","CVE-2026-53182","CVE-2026-53253","CVE-2026-53266","CVE-2026-53281","CVE-2026-53287","CVE-2026-53359","CVE-2026-53362"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290).\n- CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764).\n- CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029).\n- CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668).\n- CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562).\n- CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).\n- CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085).\n- CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392).\n- CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618).\n- CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620).\n- CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655).\n- CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825).\n- CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false\n  (bsc#1267816).\n- CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748).\n- CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798).\n- CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674).\n- CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993).\n- CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).\n- CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178).\n- CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057).\n- CVE-2026-31592: KVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock (bsc#1263123).\n- CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU (bsc#1263124).\n- CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581).\n- CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578).\n- CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137).\n- CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573).\n- CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568).\n- CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560).\n- CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563).\n- CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744).\n- CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).\n- CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).\n- CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).\n- CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045).\n- CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).\n- CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).\n- CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015).\n- CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001).\n- CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137).\n- CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930).\n- CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934).\n- CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998).\n- CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak\n  (bsc#1263996).\n- CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993).\n- CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080).\n- CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084).\n- CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263).\n- CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).\n- CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228).\n- CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236).\n- CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241).\n- CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266).\n- CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230).\n- CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286).\n- CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261).\n- CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254).\n- CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231).\n- CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239).\n- CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258).\n- CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437).\n- CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561).\n- CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612).\n- CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294).\n- CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595).\n- CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549).\n- CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603).\n- CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).\n- CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337).\n- CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320).\n- CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444).\n- CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974).\n- CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113).\n- CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763).\n- CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103).\n- CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741).\n- CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814).\n- CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).\n- CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143).\n- CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748).\n- CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628).\n- CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629).\n- CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008).\n- CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396).\n- CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397).\n- CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390).\n- CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734).\n- CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705).\n- CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704).\n- CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717).\n- CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895).\n- CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899).\n- CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916).\n- CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929).\n- CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933).\n- CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698).\n- CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208).\n- CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922).\n- CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700).\n- CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431).\n- CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430).\n- CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).\n- CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427).\n- CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228).\n- CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458).\n- CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437).\n- CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).\n- CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365).\n- CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878).\n- CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582).\n- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).\n- CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628).\n- CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640).\n- CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).\n- CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847).\n- CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928).\n- CVE-2026-46150: fanotify: fix false positive on permission events.\n- CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624).\n- CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840).\n- CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903).\n- CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).\n- CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830).\n- CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).\n- CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717).\n- CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697).\n- CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).\n- CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654).\n- CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).\n- CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637).\n- CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685).\n- CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).\n- CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651).\n- CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966).\n- CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937).\n- CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953).\n- CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).\n- CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).\n- CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037).\n- CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661).\n- CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).\n- CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).\n- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).\n- CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).\n- CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137).\n- CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103).\n- CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135).\n- CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).\n- CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).\n- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).\n- CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397).\n- CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).\n- CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314).\n- CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).\n- CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).\n- CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).\n- CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418).\n- CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).\n- CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281).\n- CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884).\n- CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574).\n- CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136).\n- CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519).\n- CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506).\n- CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).\n- CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493).\n\nThe following non security issues were fixed:\n\n- accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes).\n- ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes).\n- ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes).\n- ACPI: IPMI: Fix message kref handling on dead device (git-fixes).\n- ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes).\n- ACPI: resource: Amend kernel-doc style (git-fixes).\n- agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes).\n- ALSA: aloop: Drop superfluous break (git-fixes).\n- ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes).\n- ALSA: cmipci: check snd_ctl_new1() return value (git-fixes).\n- ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes).\n- ALSA: es1938: check snd_ctl_new1() return value (git-fixes).\n- ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes).\n- ALSA: gus: check snd_ctl_new1() return value (git-fixes).\n- ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes).\n- ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes).\n- ALSA: ice1712: check snd_ctl_new1() return value (git-fixes).\n- ALSA: seq: Clear variable event pointer on read (git-fixes).\n- ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes).\n- ALSA: seq: Fix partial userptr event expansion (git-fixes).\n- ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes).\n- ALSA: seq: midi: Serialize output teardown with event_input (git-fixes).\n- ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes).\n- ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes).\n- ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes).\n- ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes).\n- ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes).\n- ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes).\n- ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes).\n- ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes).\n- ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes).\n- ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes).\n- ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes).\n- ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes).\n- ASoC: cs35l56: Cleanup if component_probe fails (git-fixes).\n- ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git-fixes).\n- ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes).\n- ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes).\n- ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes).\n- ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes).\n- ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes).\n- ASoC: meson: aiu: Validate written enum values (git-fixes).\n- ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes).\n- ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes).\n- ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes).\n- ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes).\n- ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes).\n- ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes).\n- ASoC: SOF: topology: validate vendor array size before parsing (git-fixes).\n- ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes).\n- ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes).\n- ASoC: topology: Check PCM and DAI name strings before use (git-fixes).\n- ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes).\n- batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes).\n- batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes).\n- batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes).\n- batman-adv: tp_meter: avoid window underflow (git-fixes).\n- batman-adv: tp_meter: fix fast recovery precondition (git-fixes).\n- batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes).\n- batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes).\n- batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes).\n- batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes).\n- Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes).\n- Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes).\n- Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes).\n- Bluetooth: btusb: fix use-after-free on registration failure (git-fixes).\n- Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes).\n- Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes).\n- Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes).\n- Bluetooth: hci: validate codec capability element length (git-fixes).\n- Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes).\n- Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes).\n- Bluetooth: vhci: validate devcoredump state before side effects (git-fixes).\n- bnxt_en: Fix NULL pointer dereference (bsc#1268307).\n- bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes).\n- bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes).\n- bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes).\n- char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes).\n- crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes).\n- crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes).\n- crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes).\n- crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes).\n- crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes).\n- crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes).\n- crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes).\n- crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes).\n- crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes).\n- crypto: drbg - Fix the fips_enabled priority boost (git-fixes).\n- crypto: ecc - Fix carry overflow in vli multiplication (git-fixes).\n- crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes).\n- crypto: hisilicon/qm - disable error report before flr (git-fixes).\n- crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes).\n- crypto: pcrypt - restore callback for non-parallel fallback (git-fixes).\n- crypto: qat - protect service table iterations with service_lock (git-fixes).\n- crypto: qat - validate RSA CRT component lengths (git-fixes).\n- crypto: rng - Free default RNG on module exit (git-fixes).\n- dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes).\n- dmaengine: Fix possible use after free (git-fixes).\n- dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes).\n- dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes).\n- dmaengine: tegra: Fix burst size calculation (git-fixes).\n- driver core: reject devices with unregistered buses (git-fixes).\n- driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git-fixes).\n- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes).\n- drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes).\n- drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes).\n- drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes).\n- drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes).\n- drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes).\n- drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes).\n- drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes).\n- drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes).\n- drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes).\n- drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes).\n- drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes).\n- drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes).\n- drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes).\n- drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes).\n- drm/amdkfd: always resume_all after suspend_all (git-fixes).\n- drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes).\n- drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes).\n- drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes).\n- drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes).\n- drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes).\n- drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes).\n- drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes).\n- drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes).\n- drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes).\n- drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes).\n- drm/dp: Add eDP 1.5 bit definition (stable-fixes).\n- drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes).\n- drm/gpuvm: Do not prepare NULL objects (git-fixes).\n- drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes).\n- drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes).\n- drm/hyperv: use VMBUS_RING_SIZE() (git-fixes).\n- drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes).\n- drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes).\n- drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes).\n- drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes).\n- drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes).\n- drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes).\n- drm/msm/dp: fix HPD state status bit shift value (git-fixes).\n- drm/msm/dp: Fix the ISR_* enum values (git-fixes).\n- drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes).\n- drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes).\n- drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes).\n- drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes).\n- drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes).\n- drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes).\n- drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes).\n- drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes).\n- drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes).\n- drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes).\n- drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes).\n- drm/tidss: Fix missing drm_bridge_add() call (git-fixes).\n- drm/vc4: fix krealloc() memory leak (git-fixes).\n- drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes).\n- drm/virtio: Fix driver removal with disabled KMS (git-fixes).\n- drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes).\n- drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes).\n- ethtool: provide customized dim profile management (bsc#1261256).\n- fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git-fixes).\n- fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes).\n- fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes).\n- fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git-fixes).\n- fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes).\n- fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes).\n- fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git-fixes).\n- fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes).\n- fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes).\n- fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes).\n- fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes).\n- fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git-fixes).\n- fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes).\n- fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes).\n- firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes).\n- firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes).\n- firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes).\n- firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes).\n- fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes).\n- fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes).\n- fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes).\n- gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes).\n- gpu: host1x: Allow entries in BO caches to be freed (git-fixes).\n- gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes).\n- HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes).\n- HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes).\n- HID: wacom: stop hardware after post-start probe failures (git-fixes).\n- HID: wiimote: Fix table layout and whitespace errors (git-fixes).\n- hv: utils: handle and propagate errors in kvp_register (git-fixes).\n- hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).\n- hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes).\n- hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes).\n- hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes).\n- hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).\n- i2c: core: fix irq domain leak on adapter registration failure (git-fixes).\n- i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes).\n- i2c: mpc: Fix timeout calculations (git-fixes).\n- i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes).\n- i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes).\n- i2c: stm32f7: truncate clock period instead of rounding it (git-fixes).\n- i2c: tegra: Fix NOIRQ suspend/resume (git-fixes).\n- i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes).\n- ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251).\n- iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes).\n- iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes).\n- iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes).\n- iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes).\n- iio: chemical: scd30: fix division by zero in write_raw (git-fixes).\n- iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes).\n- iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes).\n- iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes).\n- iio: light: opt3001: fix missing state reset on timeout (git-fixes).\n- iio: light: si1133: prevent race condition on timeout (git-fixes).\n- iio: light: si1133: reset counter to prevent race condition (git-fixes).\n- iio: light: veml6030: fix channel type when pushing events (git-fixes).\n- iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes).\n- iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes).\n- iio: tcs3472: power down chip on probe failure (git-fixes).\n- iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes).\n- Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes).\n- Input: elan_i2c - validate firmware size before use (stable-fixes).\n- Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes).\n- Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes).\n- Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes).\n- Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes).\n- Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes).\n- iommu/s390: allow larger region tables (jsc#PED-15880).\n- iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880).\n- iommu/s390: handle IOAT registration based on domain (jsc#PED-15880).\n- iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880).\n- iommu/s390: set appropriate IOTA region type (jsc#PED-15880).\n- iommu/s390: support cleanup of additional table regions (jsc#PED-15880).\n- iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880).\n- iommu/s390: support map/unmap for additional table regions (jsc#PED-15880).\n- KVM: arm64: Discard PC update state on vcpu reset (git-fixes).\n- KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes).\n- KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes).\n- KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes).\n- KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes).\n- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).\n- KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes).\n- KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes).\n- KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes).\n- KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes).\n- KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes).\n- KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159).\n- KVM: SEV: Ignore MMIO requests of length '0' (git-fixes).\n- KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes).\n- KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes).\n- KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes).\n- KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes).\n- KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes).\n- KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes).\n- KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes).\n- KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes).\n- KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes).\n- KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes).\n- KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git-fixes).\n- KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes).\n- KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes).\n- KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes).\n- KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes).\n- KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes).\n- leds: uleds: Fix potential buffer overread (git-fixes).\n- linux/dim: move useful macros to .h file (bsc#1261256).\n- loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303).\n- loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303).\n- mailbox: mtk-adsp: fix UAF during device teardown (git-fixes).\n- media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes).\n- media: cec: seco: unregister adapter on IR probe failure (git-fixes).\n- media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes).\n- media: cedrus: Fix missing cleanup in error path (git-fixes).\n- media: cedrus: skip invalid H.264 reference list entries (git-fixes).\n- media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes).\n- media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes).\n- media: pci: dm1105: Free allocated workqueue (git-fixes).\n- media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes).\n- media: v4l2-ctrls: validate HEVC active reference counts (git-fixes).\n- media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes).\n- media: vidtv: fix reference leak on failed device registration (git-fixes).\n- media: vimc: fix reference leak on failed device registration (git-fixes).\n- media: vpif_capture: fix OF node reference imbalance (git-fixes).\n- misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes).\n- misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes).\n- misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes).\n- misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes).\n- module: fix init_module_from_file() error handling (jsc#PED-16303).\n- module: make waiting for a concurrent module loader interruptible (jsc#PED-16303).\n- module: Split modules_install compression and in-kernel decompression (jsc#PED-16303).\n- module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303).\n- module: warn about excessively long module waits (jsc#PED-16303).\n- modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303).\n- mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes).\n- mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes).\n- mtd: rawnand: pl353: fix probe resource allocation (git-fixes).\n- mtd: slram: remove failed entries from the device list (git-fixes).\n- mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes).\n- mtd: spi-nor: swp: Improve locking user experience (git-fixes).\n- net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428).\n- net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256).\n- net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256).\n- net: mana: Add support for PF device 0x00C1 (bsc#1268237).\n- net: mana: Add support for RX CQE Coalescing (bsc#1261256).\n- net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes).\n- net: mana: Create separate EQs for each vPort (git-fixes).\n- net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes).\n- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes).\n- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes).\n- net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes).\n- net: mana: Optimize irq affinity for low vcpu configs (git-fixes).\n- net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes).\n- net: mana: Use GIC functions to allocate global EQs (git-fixes).\n- nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes).\n- nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes).\n- nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes).\n- of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes).\n- page_pool: Move pp_magic check into helper functions (bsc#1261562).\n- page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562).\n- platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes).\n- platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes).\n- PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes).\n- power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes).\n- power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes).\n- power: supply: core: fix supplied_from allocations (git-fixes).\n- power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes).\n- powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes).\n- powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes).\n- RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes).\n- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes).\n- rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes).\n- rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes).\n- rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes).\n- rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes).\n- rtc: mpfs: fix counter upload completion condition (git-fixes).\n- rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes).\n- s390/pci: check for relaxed translation capability (jsc#PED-15880).\n- s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880).\n- s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880).\n- scripts/submit_branch: add SLE15-SP7 submission script.\n- scsi: storvsc: Replace symbolic permissions with octal (git-fixes).\n- scsi: target: Fix hexadecimal CHAP_I handling (git-fixes).\n- selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617).\n- selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617).\n- selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617).\n- selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617).\n- selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617).\n- selftests/bpf: Skip tests whose objects were not built (bsc#1269617).\n- selftests/bpf: Tolerate benchmark build failures (bsc#1269617).\n- selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617).\n- selftests/bpf: Tolerate missing files during install (bsc#1269617).\n- selftests/bpf: Tolerate test file compilation failures (bsc#1269617).\n- serdev: make serdev_bus_type const (stable-fixes).\n- serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes).\n- serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes).\n- slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes).\n- soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes).\n- soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes).\n- spi: at91-usart: drop dead runtime pm support (git-fixes).\n- spi: dw: fix wrong BAUDR setting after resume (git-fixes).\n- spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes).\n- spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes).\n- spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes).\n- spi: meson-spifc: fix runtime PM leak on remove (git-fixes).\n- spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes).\n- spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes).\n- spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes).\n- Split off kABI workaround for bsc#1267458 (bsc#1267458).\n- staging: most: video: avoid double free on video register failure (git-fixes).\n- staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes).\n- thermal: hwmon: Fix critical temperature attribute removal (git-fixes).\n- thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes).\n- thunderbolt: Bound root directory content to block size (git-fixes).\n- thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes).\n- thunderbolt: Limit XDomain response copy to actual frame size (git-fixes).\n- thunderbolt: Reject zero-length property entries in validator (git-fixes).\n- thunderbolt: Validate XDomain request packet size before type cast (git-fixes).\n- tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes).\n- tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes).\n- usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes).\n- usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes).\n- usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes).\n- usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes).\n- usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes).\n- USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes).\n- USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes).\n- USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes).\n- USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes).\n- USB: serial: option: add MeiG SRM813Q (stable-fixes).\n- USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes).\n- usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes).\n- usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes).\n- usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes).\n- usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes).\n- usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes).\n- usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes).\n- usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes).\n- vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes).\n- watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199).\n- watchdog: apple: Add 'apple,t8103-wdt' compatible (git-fixes).\n- watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes).\n- watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes).\n- watchdog: unregister PM notifier on watchdog unregister (git-fixes).\n- wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes).\n- wifi: ath11k: fix warning when unbinding (git-fixes).\n- wifi: cfg80211: fix grammar in MLO group key error message (git-fixes).\n- wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes).\n- wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes).\n- wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes).\n- wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes).\n- wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes).\n- wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes).\n- wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes).\n- wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes).\n- wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes).\n- wifi: rtw88: increase TX report timeout to fix race condition (git-fixes).\n- wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes).\n- wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes).\n- wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes).\n- wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes).\n- wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes).\n- x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305).\n- x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305).\n- X.509: Fix validation of ASN.1 certificate header (git-fixes).\n","affected":[{"package":{"name":"kernel-livepatch-SLE15-SP7-RT_Update_17","ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP7","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP7-RT_Update_17&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1-150700.1.3.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-6_4_0-150700_7_62-rt":"1-150700.1.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2799-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.62.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.62.1","dlm-kmp-rt":"6.4.0-150700.7.62.1","gfs2-kmp-rt":"6.4.0-150700.7.62.1","kernel-devel-rt":"6.4.0-150700.7.62.1","kernel-rt":"6.4.0-150700.7.62.1","kernel-rt-devel":"6.4.0-150700.7.62.1","kernel-source-rt":"6.4.0-150700.7.62.1","kernel-syms-rt":"6.4.0-150700.7.62.1","ocfs2-kmp-rt":"6.4.0-150700.7.62.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2799-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.62.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.62.1","dlm-kmp-rt":"6.4.0-150700.7.62.1","gfs2-kmp-rt":"6.4.0-150700.7.62.1","kernel-devel-rt":"6.4.0-150700.7.62.1","kernel-rt":"6.4.0-150700.7.62.1","kernel-rt-devel":"6.4.0-150700.7.62.1","kernel-source-rt":"6.4.0-150700.7.62.1","kernel-syms-rt":"6.4.0-150700.7.62.1","ocfs2-kmp-rt":"6.4.0-150700.7.62.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2799-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP7","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.4.0-150700.7.62.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"6.4.0-150700.7.62.1","dlm-kmp-rt":"6.4.0-150700.7.62.1","gfs2-kmp-rt":"6.4.0-150700.7.62.1","kernel-devel-rt":"6.4.0-150700.7.62.1","kernel-rt":"6.4.0-150700.7.62.1","kernel-rt-devel":"6.4.0-150700.7.62.1","kernel-source-rt":"6.4.0-150700.7.62.1","kernel-syms-rt":"6.4.0-150700.7.62.1","ocfs2-kmp-rt":"6.4.0-150700.7.62.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2799-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262799-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236743"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261604"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262392"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262620"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262655"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262674"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262748"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262993"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263057"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263072"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263123"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263124"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263137"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263178"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263560"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263563"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263568"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263573"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263578"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263879"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263930"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263934"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263993"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263996"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264015"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264045"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264076"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264080"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264084"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264116"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264137"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264230"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264236"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264239"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264241"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264258"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264261"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264266"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264320"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264337"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264437"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264444"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264470"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264549"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264562"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264610"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264612"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264741"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264748"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264763"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264814"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264974"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265103"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265113"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265143"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265211"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265628"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266290"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266390"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266698"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266700"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266704"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266717"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266830"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266840"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266847"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266878"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266895"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266899"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266903"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266916"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266922"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266928"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266929"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267208"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267251"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267361"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267365"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267369"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267381"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267387"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267430"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267431"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267437"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267458"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267567"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267582"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267591"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267621"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267624"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267628"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267635"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267637"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267640"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267651"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267654"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267682"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267685"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267697"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267717"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267744"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267816"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267918"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267966"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267993"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268022"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268037"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268159"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268237"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268335"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268661"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269022"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269103"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269135"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269136"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269137"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269199"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269281"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269314"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269397"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269493"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269519"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269574"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269617"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269678"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269681"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269884"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-10263"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-40216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-40341"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71294"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23451"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31414"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31429"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31452"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31453"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31495"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31555"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31560"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31592"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31593"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31647"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31664"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31665"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31670"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31674"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31693"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31697"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31698"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31699"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31752"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31771"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43010"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43022"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43024"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43034"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43035"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43036"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43074"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43077"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43085"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43086"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43089"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43093"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43094"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43107"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43128"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43139"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43158"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43171"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43187"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43233"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43239"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43336"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43339"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43345"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43420"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43469"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43491"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43492"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45838"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45840"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45841"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45862"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45870"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45891"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45894"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45912"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45940"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45948"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45961"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45964"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45965"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45974"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-45985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46005"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46063"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46065"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46101"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46116"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46119"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46120"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46123"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46124"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46150"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46160"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46162"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46172"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46173"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46244"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46259"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46273"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46291"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46315"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46328"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52908"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52909"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52957"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53122"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53138"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53182"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53281"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53287"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53359"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53362"}]}