{"schema_version":"1.7.5","id":"SUSE-SU-2026:2840-1","published":"2026-07-10T09:24:47Z","modified":"2026-07-11T09:15:04.780635645Z","related":["CVE-2026-31771","CVE-2026-43038","CVE-2026-46090","CVE-2026-46173","CVE-2026-46197","CVE-2026-46229","CVE-2026-46253","CVE-2026-46266","CVE-2026-46274","CVE-2026-46319","CVE-2026-46320","CVE-2026-46330","CVE-2026-46331","CVE-2026-52909","CVE-2026-52918","CVE-2026-52923","CVE-2026-52924","CVE-2026-52943","CVE-2026-52955","CVE-2026-52969","CVE-2026-52972","CVE-2026-52993","CVE-2026-53016","CVE-2026-53041","CVE-2026-53053","CVE-2026-53071","CVE-2026-53072","CVE-2026-53133","CVE-2026-53253","CVE-2026-53359"],"upstream":["CVE-2026-31771","CVE-2026-43038","CVE-2026-46090","CVE-2026-46173","CVE-2026-46197","CVE-2026-46229","CVE-2026-46253","CVE-2026-46266","CVE-2026-46274","CVE-2026-46319","CVE-2026-46320","CVE-2026-46330","CVE-2026-46331","CVE-2026-52909","CVE-2026-52918","CVE-2026-52923","CVE-2026-52924","CVE-2026-52943","CVE-2026-52955","CVE-2026-52969","CVE-2026-52972","CVE-2026-52993","CVE-2026-53016","CVE-2026-53041","CVE-2026-53053","CVE-2026-53071","CVE-2026-53072","CVE-2026-53133","CVE-2026-53253","CVE-2026-53359"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).\n- CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097).\n- CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531).\n- CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).\n- CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).\n- CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).\n- CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).\n- CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).\n- CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).\n- CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).\n- CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049).\n- CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421).\n- CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).\n- CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).\n- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).\n- CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).\n- CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).\n- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).\n- CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).\n- CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).\n- CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).\n- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).\n- CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).\n- CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).\n- CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).\n- CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).\n- CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).\n- CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574).\n- CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150500.13.151.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-devel-rt":"5.14.21-150500.13.151.1","kernel-rt":"5.14.21-150500.13.151.1","kernel-source-rt":"5.14.21-150500.13.151.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2840-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.5","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150500.13.151.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-devel-rt":"5.14.21-150500.13.151.1","kernel-rt":"5.14.21-150500.13.151.1","kernel-source-rt":"5.14.21-150500.13.151.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:2840-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262840-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267381"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267567"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267635"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267684"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267722"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267918"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267993"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268022"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268049"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269022"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269033"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269036"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269159"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269193"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269195"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269310"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269398"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269574"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269678"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269681"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269821"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31771"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43038"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46090"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46173"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46266"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46319"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46320"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52909"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52923"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52924"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52943"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52955"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52969"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52972"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52993"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53016"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53071"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53133"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53253"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53359"}]}