{"schema_version":"1.7.5","id":"SUSE-SU-2026:2202-1","published":"2026-06-01T10:02:06Z","modified":"2026-06-02T08:45:05.865590439Z","related":["CVE-2021-47103","CVE-2023-20585","CVE-2026-23209","CVE-2026-23239","CVE-2026-23240","CVE-2026-23268","CVE-2026-23269","CVE-2026-23271","CVE-2026-23273","CVE-2026-23351","CVE-2026-23393","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23406","CVE-2026-23407","CVE-2026-23408","CVE-2026-23409","CVE-2026-23410","CVE-2026-23411","CVE-2026-23449","CVE-2026-23458","CVE-2026-23462","CVE-2026-31402","CVE-2026-31403","CVE-2026-31408","CVE-2026-31436","CVE-2026-31504","CVE-2026-31507","CVE-2026-31512","CVE-2026-31533","CVE-2026-31570","CVE-2026-31586","CVE-2026-31588","CVE-2026-31602","CVE-2026-31607","CVE-2026-31649","CVE-2026-31656","CVE-2026-31662","CVE-2026-31669","CVE-2026-31685","CVE-2026-31694","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43025","CVE-2026-43027","CVE-2026-43050","CVE-2026-43110","CVE-2026-43126","CVE-2026-43190","CVE-2026-43214","CVE-2026-43329","CVE-2026-43334","CVE-2026-43365","CVE-2026-43437","CVE-2026-43494","CVE-2026-43500","CVE-2026-43503","CVE-2026-46333"],"upstream":["CVE-2021-47103","CVE-2023-20585","CVE-2026-23209","CVE-2026-23239","CVE-2026-23240","CVE-2026-23268","CVE-2026-23269","CVE-2026-23271","CVE-2026-23273","CVE-2026-23351","CVE-2026-23393","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23406","CVE-2026-23407","CVE-2026-23408","CVE-2026-23409","CVE-2026-23410","CVE-2026-23411","CVE-2026-23449","CVE-2026-23458","CVE-2026-23462","CVE-2026-31402","CVE-2026-31403","CVE-2026-31408","CVE-2026-31436","CVE-2026-31504","CVE-2026-31507","CVE-2026-31512","CVE-2026-31533","CVE-2026-31570","CVE-2026-31586","CVE-2026-31588","CVE-2026-31602","CVE-2026-31607","CVE-2026-31649","CVE-2026-31656","CVE-2026-31662","CVE-2026-31669","CVE-2026-31685","CVE-2026-31694","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43025","CVE-2026-43027","CVE-2026-43050","CVE-2026-43110","CVE-2026-43126","CVE-2026-43190","CVE-2026-43214","CVE-2026-43329","CVE-2026-43334","CVE-2026-43365","CVE-2026-43437","CVE-2026-43494","CVE-2026-43500","CVE-2026-43503","CVE-2026-46333"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2021-47103: inet: fully convert sk->sk_rx_dst to RCU rules (bsc#1221010).\n- CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1 (bsc#1243603).\n- CVE-2026-23239: espintcp: Fix race condition in espintcp_close() (bsc#1259485).\n- CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1259484).\n- CVE-2026-23271: perf: Fix __perf_event_overflow() vs perf_remove_from_context() race (bsc#1260018).\n- CVE-2026-23351: netfilter: nft_set_pipapo: split gc into unlink and reclaim phase (bsc#1260526).\n- CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260522).\n- CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779).\n- CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781).\n- CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710).\n- CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638).\n- CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796).\n- CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (bsc#1261797).\n- CVE-2026-31436: dmaengine: idxd: fix possible wrong descriptor completion in llist_abort_desc() (bsc#1262602).\n- CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085).\n- CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095).\n- CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv()\n  (bsc#1262734).\n- CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262758).\n- CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263065).\n- CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263176).\n- CVE-2026-31588: KVM: x86: Use scratch field in MMIO fragment to hold small write values (bsc#1263165).\n- CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723).\n- CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600).\n- CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582).\n- CVE-2026-31656: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat (bsc#1263170).\n- CVE-2026-31662: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG (bsc#1263131).\n- CVE-2026-31669: mptcp: fix slab-use-after-free in __inet_lookup_established (bsc#1263141).\n- CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668).\n- CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263901).\n- CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882).\n- CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059).\n- CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181).\n- CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931).\n- CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1263933).\n- CVE-2026-43050: atm: lec: fix use-after-free in sock_def_readable() (bsc#1264082).\n- CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482).\n- CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634).\n- CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848).\n- CVE-2026-43214: KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2() (bsc#1264651).\n- CVE-2026-43329: netfilter: flowtable: strictly check for maximum number of actions (bsc#1265085).\n- CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090).\n- CVE-2026-43365: xfs: fix undersized l_iclog_roundoff values (bsc#1265119).\n- CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126).\n- CVE-2026-43494: net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626).\n- CVE-2026-43500: supported.conf: drop rxrpc and af_kfs (bsc#1264450).\n- CVE-2026-43503: net: skbuff: propagate shared-frag marker through frag-transfer helpers (bsc#1265960).\n- CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265308).\n\nThe following non security issues were fixed:\n\n- check-for-config-changes: Exclude CC_MS_EXTENSIONS.\n- check-for-config-changes: Exclude HAVE_CFI_ICALL_NORMALIZE_INTEGERS{,_RUSTC}.\n- crypto: qat - fix ring to service map for QAT GEN4 (bsc#1258248).\n- crypto: qat - refactor fw config related functions (bsc#1258248).\n- crypto: qat - use masks for AE groups (bsc#1258248).\n- dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes).\n- mkspec: Add signature to source list only when it exists.\n- net/rds: reset op_nents when zerocopy page pin fails (bsc#1265626).\n- net: gro: don't merge zcopy skbs (git-fixes).\n- nvmet-rdma: fix possible bad dereference when freeing rsps (bsc#1260983).\n- ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718).\n- ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).\n- xfrm: esp: avoid in-place decrypt on shared skb frags.\n","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262202-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1221010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258248"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258854"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258856"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259484"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259485"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260018"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260522"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260526"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260983"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261295"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261779"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261781"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261797"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262179"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262181"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262602"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262758"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263095"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263131"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263141"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263165"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263170"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263176"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263582"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263931"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264082"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264450"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264651"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265119"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265308"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265456"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265626"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265960"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-47103"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20585"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23239"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23240"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23271"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23273"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23351"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23406"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23409"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23410"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31436"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31512"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31533"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31570"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31586"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31656"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31662"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31669"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31694"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31738"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43027"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43126"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43214"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43329"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43365"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43500"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43503"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46333"}]}