{"schema_version":"1.7.5","id":"SUSE-SU-2026:21908-1","published":"2026-06-01T09:26:52Z","modified":"2026-06-03T18:24:42.151767966Z","related":["CVE-2025-54518","CVE-2026-23243","CVE-2026-23274","CVE-2026-46300","CVE-2026-46333"],"upstream":["CVE-2025-54518","CVE-2026-23243","CVE-2026-23274","CVE-2026-46300","CVE-2026-46333"],"summary":"Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0)","details":"\nThis update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues\n\nThe following security issues were fixed:\n\n- CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096).\n- CVE-2026-23243: RDMA/umad: Reject negative data_len in ib_umad_write (bsc#1259798).\n- CVE-2026-23274: netfilter: xt_IDLETIMER: reject rev0 reuse of ALARM timer labels (bsc#1260908).\n- CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224).\n- CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384).\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621908-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265224"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265384"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-54518"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23243"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23274"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46300"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46333"}]}