{"schema_version":"1.9.0","id":"SUSE-SU-2026:3616-1","published":"2026-08-13T18:03:59Z","modified":"2026-08-14T18:15:08.222736903Z","related":["CVE-2022-4994","CVE-2023-2058","CVE-2023-53995","CVE-2025-21710","CVE-2025-54518","CVE-2026-31431","CVE-2026-31598","CVE-2026-31628","CVE-2026-31759","CVE-2026-43033","CVE-2026-46052","CVE-2026-46056","CVE-2026-46080","CVE-2026-46109","CVE-2026-46145","CVE-2026-46174","CVE-2026-46193","CVE-2026-46243","CVE-2026-46323","CVE-2026-46333","CVE-2026-52956","CVE-2026-52958","CVE-2026-52967","CVE-2026-52986","CVE-2026-53050","CVE-2026-53131","CVE-2026-53196","CVE-2026-53224","CVE-2026-53246","CVE-2026-53256","CVE-2026-53260","CVE-2026-53267","CVE-2026-53357","CVE-2026-53375","CVE-2026-53388","CVE-2026-53391","CVE-2026-53402","CVE-2026-63794","CVE-2026-63806","CVE-2026-63807","CVE-2026-63824","CVE-2026-63829","CVE-2026-63893","CVE-2026-63917","CVE-2026-63919","CVE-2026-63921","CVE-2026-63922","CVE-2026-63924","CVE-2026-63971","CVE-2026-63975","CVE-2026-63984","CVE-2026-63994","CVE-2026-64106","CVE-2026-64189","CVE-2026-64560","CVE-2026-64561","CVE-2026-64564","CVE-2026-64600"],"upstream":["CVE-2022-4994","CVE-2023-2058","CVE-2023-53995","CVE-2025-21710","CVE-2025-54518","CVE-2026-31431","CVE-2026-31598","CVE-2026-31628","CVE-2026-31759","CVE-2026-43033","CVE-2026-46052","CVE-2026-46056","CVE-2026-46080","CVE-2026-46109","CVE-2026-46145","CVE-2026-46174","CVE-2026-46193","CVE-2026-46243","CVE-2026-46323","CVE-2026-46333","CVE-2026-52956","CVE-2026-52958","CVE-2026-52967","CVE-2026-52986","CVE-2026-53050","CVE-2026-53131","CVE-2026-53196","CVE-2026-53224","CVE-2026-53246","CVE-2026-53256","CVE-2026-53260","CVE-2026-53267","CVE-2026-53357","CVE-2026-53375","CVE-2026-53388","CVE-2026-53391","CVE-2026-53402","CVE-2026-63794","CVE-2026-63806","CVE-2026-63807","CVE-2026-63824","CVE-2026-63829","CVE-2026-63893","CVE-2026-63917","CVE-2026-63919","CVE-2026-63921","CVE-2026-63922","CVE-2026-63924","CVE-2026-63971","CVE-2026-63975","CVE-2026-63984","CVE-2026-63994","CVE-2026-64106","CVE-2026-64189","CVE-2026-64560","CVE-2026-64561","CVE-2026-64564","CVE-2026-64600"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues:\n\nThe following security issues were fixed:\n\n- CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097).\n- CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616).\n- CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).\n- CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).\n- CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715).\n- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).\n- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).\n- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).\n- CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181).\n- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).\n- CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).\n- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).\n- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).\n- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).\n- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).\n- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).\n- CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731).\n- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).\n- CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).\n- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).\n- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).\n- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).\n- CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908).\n- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).\n- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).\n- CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263).\n- CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180).\n- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).\n- CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607).\n- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904).\n- CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907).\n- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918).\n- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855).\n- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678).\n- CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694).\n- CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865).\n- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035).\n- CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242).\n- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207).\n- CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004).\n- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231).\n- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).\n- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).\n\nThe following non security issues were fixed:\n\n- hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).\n- mkspec-dtb: Skip missing DTBs.\n- pkspec-dtb: Fix dtb-al rename.\n- posix-cpu-timers: Cleanup the firing logic (bsc#1271912).\n- posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912).\n- posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).\n- posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912).\n- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912).\n- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912).\n- posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).\n- posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912).\n- posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912).\n- posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).\n- posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).\n- posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).\n- posix-timers: Add proper state tracking (bsc#1271912).\n- posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).\n- posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).\n- posix-timers: Clear overrun in common_timer_set() (bsc#1271912).\n- posix-timers: Consolidate signal queueing (bsc#1271912).\n- posix-timers: Consolidate timer setup (bsc#1271912).\n- posix-timers: Cure si_sys_private race (bsc#1271912).\n- posix-timers: Document common_clock_get() correctly (bsc#1271912).\n- posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912).\n- posix-timers: Polish coding style in a few places (bsc#1271912).\n- posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912).\n- sctp: validate embedded address parameter length (git-fixes).\n- time: Switch to hrtimer_setup() (bsc#1271912).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.181.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.181.1","kernel-source-rt":"5.14.21-150400.15.181.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3616-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.3","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.181.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.181.1","kernel-source-rt":"5.14.21-150400.15.181.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3616-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.181.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.181.1","kernel-source-rt":"5.14.21-150400.15.181.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3616-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.4","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.14.21-150400.15.181.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.14.21-150400.15.181.1","kernel-source-rt":"5.14.21-150400.15.181.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3616-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263616-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185845"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1254767"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255616"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262573"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263788"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264013"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264076"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264089"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265308"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266238"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267384"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267435"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267596"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267656"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267715"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269172"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269174"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269181"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269188"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269577"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269731"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269773"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269986"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269988"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269993"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269997"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270257"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271526"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271899"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271912"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271964"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272180"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272207"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272242"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272263"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272607"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272678"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272694"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272865"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272904"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272907"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272918"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273004"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273035"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273231"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-4994"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-2058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-53995"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-21710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-54518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31431"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31598"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46056"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46109"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46145"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46174"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46323"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46333"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52967"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-52986"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53196"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53224"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53246"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53256"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53260"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53267"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53375"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53388"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63794"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63806"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63807"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63824"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63829"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63893"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63917"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63919"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63921"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63922"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63924"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63971"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63984"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-63994"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64189"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64560"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64561"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64564"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64600"}]}