Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:02264-1 — kernel-64kb (CVE-2021-47557 +257 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP5 kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2021-47557: net/sched: sch_ets: do not peek at classes beyond 'nbands' (bsc#1207361 bsc#1225468).
  • CVE-2021-47595: net/sched: sch_ets: do not remove idle classes from the round-robin list (bsc#1207361 bsc#1226552).
  • CVE-2023-52924: netfilter: nf_tables: do not skip expired elements during walk (bsc#1236821).
  • CVE-2023-52925: netfilter: nf_tables: do not fail inserts if duplicate has expired (bsc#1236822).
  • CVE-2024-26808: netfilter: nft_chain_filter: handle NETDEV_UNREGISTER for inet/ingress basechain (bsc#1222634).
  • CVE-2024-26924: scsi: lpfc: Release hbalock before calling lpfc_worker_wake_up() (bsc#1225820).
  • CVE-2024-27397: kabi: place tstamp needed for nftables set in a hole (bsc#1224095).
  • CVE-2024-36978: net: sched: sch_multiq: fix possible OOB write in multiq_tune() (bsc#1226514).
  • CVE-2024-46800: sch/netem: fix use after free in netem_dequeue (bsc#1230827).
  • CVE-2024-53125: bpf: sync_linked_regs() must preserve subreg_def (bsc#1234156).
  • CVE-2024-53141: netfilter: ipset: add missing range check in bitmap_ip_uadt (bsc#1234381).
  • CVE-2024-53197: ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (bsc#1235464).
  • CVE-2024-56770: sch/netem: fix use after free in netem_dequeue (bsc#1235637).
  • CVE-2025-21700: net: sched: Disallow replacing of child qdisc from one parent to another (bsc#1237159).
  • CVE-2025-21702: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 (bsc#1237312).
  • CVE-2025-21703: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() (bsc#1237313).
  • CVE-2025-21756: vsock: Orphan socket after transport release (bsc#1238876).
  • CVE-2025-23141: KVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses (bsc#1242782).
  • CVE-2025-37752: net_sched: sch_sfq: move the limit validation (bsc#1242504).
  • CVE-2025-37823: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (bsc#1242924).
  • CVE-2025-37890: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (bsc#1243330).
  • CVE-2025-37997: netfilter: ipset: fix region locking in hash types (bsc#1243832).
  • CVE-2025-38000: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (bsc#1244277).
  • CVE-2025-38001: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (bsc#1244234).
  • CVE-2025-38014: dmaengine: idxd: Refactor remove call with idxd_cleanup() helper (bsc#1244732).
  • CVE-2025-38060: bpf: abort verification if env->cur_state->loop_entry != NULL (bsc#1245155).
  • CVE-2025-38083: net_sched: prio: fix a race in prio_tune() (bsc#1245183).

The following non-security bugs were fixed:

  • ALSA: usb-audio: Fix a DMA to stack memory bug (git-fixes).
  • Fix reference in 'net_sched: sch_sfq: use a temporary work area for validating configuration' (bsc#1242504)
  • MyBS: Correctly generate build flags for non-multibuild package limit (bsc# 1244241) Fixes: 0999112774fc ('MyBS: Use buildflags to set which package to build')
  • MyBS: Do not build kernel-obs-qa with limit_packages Fixes: 58e3f8c34b2b ('bs-upload-kernel: Pass limit_packages also on multibuild')
  • MyBS: Simplify qa_expr generation Start with a 0 which makes the expression valid even if there are no QA repositories (currently does not happen). Then separator is always needed.
  • bs-upload-kernel: Pass limit_packages also on multibuild Fixes: 0999112774fc ('MyBS: Use buildflags to set which package to build') Fixes: 747f601d4156 ('bs-upload-kernel, MyBS, Buildresults: Support multibuild (JSC-SLE#5501, boo#1211226, bsc#1218184)')
  • hugetlb: unshare some PMDs when splitting VMAs (bsc#1245431).
  • kernel-source: Do not use multiple -r in sed parameters
  • kernel-source: Remove log.sh from sources
  • mkspec: Exclude rt flavor from kernel-syms dependencies (bsc#1244337).
  • mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (bsc#1245431).
  • mm/hugetlb: unshare page tables during VMA split, not before (bsc#1245431).
  • net_sched: sch_fifo: implement lockless __fifo_dump() (bsc#1237312)
  • net_sched: sch_sfq: use a temporary work area for validating configuration (bsc#1232504)
  • ovl: fix use inode directly in rcu-walk mode (bsc#1241900).
  • powerpc/powernv/memtrace: Fix out of bounds issue in memtrace mmap (bsc#1244309 ltc#213790).
  • powerpc/vas: Return -EINVAL if the offset is non-zero in mmap() (bsc#1244309 ltc#213790).
  • scsi: storvsc: Do not report the host packet status as the hv status (git-fixes).
  • scsi: storvsc: Increase the timeouts to storvsc_timeout (bsc#1245455).

Affected software

SUSE-SU-2025:02264-1 is recorded against 9 packages.

  • kernel-64kb (fixed in 5.14.21-150500.55.113.1)
  • kernel-default (fixed in 5.14.21-150500.55.113.1)
  • kernel-default-base (fixed in 5.14.21-150500.55.113.1.150500.6.53.1)
  • kernel-docs (fixed in 5.14.21-150500.55.113.1)
  • kernel-livepatch-sle15-sp5-update-28 (fixed in 1-150500.11.3.1)
  • kernel-obs-build (fixed in 5.14.21-150500.55.113.1)
  • kernel-source (fixed in 5.14.21-150500.55.113.1)
  • kernel-syms (fixed in 5.14.21-150500.55.113.1)
  • kernel-zfcpdump (fixed in 5.14.21-150500.55.113.1)

Timeline and source

Published on 10 July 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-07-10
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-64kb 5.14.21-150500.55.113.1
kernel-default 5.14.21-150500.55.113.1
kernel-default-base 5.14.21-150500.55.113.1.150500.6.53.1
kernel-docs 5.14.21-150500.55.113.1
kernel-livepatch-sle15-sp5-update-28 1-150500.11.3.1
kernel-obs-build 5.14.21-150500.55.113.1
kernel-source 5.14.21-150500.55.113.1
kernel-syms 5.14.21-150500.55.113.1
kernel-zfcpdump 5.14.21-150500.55.113.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:02264-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:02264-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.