Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:03634-1 — kernel-azure (CVE-2023-53261 +444 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP6 Azure kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2023-53261: coresight: Fix memory leak in acpi_buffer->pointer (bsc#1249770).
  • CVE-2024-46733: btrfs: fix qgroup reserve leaks in cow_file_range (bsc#1230708).
  • CVE-2024-53125: bpf: sync_linked_regs() must preserve subreg_def (bsc#1234156).
  • CVE-2024-58090: sched/core: Prevent rescheduling when interrupts are disabled (bsc#1240324).
  • CVE-2025-22022: usb: xhci: Apply the link chain quirk on NEC isoc endpoints (bsc#1241292).
  • CVE-2025-37885: KVM: x86: Reset IRTE to host control if *new* route isn't postable (bsc#1242960).
  • CVE-2025-38006: net: mctp: Do not access ifa_index when missing (bsc#1244930).
  • CVE-2025-38075: scsi: target: iscsi: Fix timeout on deleted connection (bsc#1244734).
  • CVE-2025-38103: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() (bsc#1245663).
  • CVE-2025-38119: scsi: core: ufs: Fix a hang in the error handler (bsc#1245700).
  • CVE-2025-38125: net: stmmac: make sure that ptp_rate is not 0 before configuring EST (bsc#1245710).
  • CVE-2025-38146: net: openvswitch: Fix the dead loop of MPLS parse (bsc#1245767).
  • CVE-2025-38160: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() (bsc#1245780).
  • CVE-2025-38184: tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer (bsc#1245956).
  • CVE-2025-38185: atm: atmtcp: Free invalid length skb in atmtcp_c_send() (bsc#1246012).
  • CVE-2025-38190: atm: Revert atm_account_tx() if copy_from_iter_full() fails (bsc#1245973).
  • CVE-2025-38201: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX (bsc#1245977).
  • CVE-2025-38205: drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (bsc#1246005).
  • CVE-2025-38208: smb: client: add NULL check in automount_fullpath (bsc#1245815).
  • CVE-2025-38234: sched/rt: Fix race in push_rt_task (bsc#1246057).
  • CVE-2025-38245: atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister() (bsc#1246193).
  • CVE-2025-38251: atm: clip: prevent NULL deref in clip_push() (bsc#1246181).
  • CVE-2025-38263: bcache: fix NULL pointer in cache_set_flush() (bsc#1246248).
  • CVE-2025-38351: KVM: x86/hyper-v: Skip non-canonical addresses during PV TLB flush (bsc#1246782).
  • CVE-2025-38360: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (bsc#1247078).
  • CVE-2025-38402: idpf: return 0 size for RSS key if not supported (bsc#1247262).
  • CVE-2025-38408: genirq/irq_sim: Initialize work context pointers properly (bsc#1247126).
  • CVE-2025-38418: remoteproc: core: Release rproc->clean_table after rproc_attach() fails (bsc#1247137).
  • CVE-2025-38419: remoteproc: core: Cleanup acquired resources when rproc_handle_resources() fails in rproc_attach() (bsc#1247136).
  • CVE-2025-38439: bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (bsc#1247155).
  • CVE-2025-38441: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (bsc#1247167).
  • CVE-2025-38444: raid10: cleanup memleak at raid10_make_request (bsc#1247162).
  • CVE-2025-38445: md/raid1: Fix stack memory use after return in raid1_reshape (bsc#1247229).
  • CVE-2025-38456: ipmi:msghandler: Fix potential memory corruption in ipmi_create_user() (bsc#1247099).
  • CVE-2025-38458: atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (bsc#1247116).
  • CVE-2025-38459: atm: clip: Fix infinite recursive call of clip_push() (bsc#1247119).
  • CVE-2025-38464: tipc: Fix use-after-free in tipc_conn_close() (bsc#1247112).
  • CVE-2025-38466: perf: Revert to requiring CAP_SYS_ADMIN for uprobes (bsc#1247442).
  • CVE-2025-38472: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (bsc#1247313).
  • CVE-2025-38488: smb: client: fix use-after-free in crypt_message when using async crypto (bsc#1247239).
  • CVE-2025-38490: net: libwx: remove duplicate page_pool_put_full_page() (bsc#1247243).
  • CVE-2025-38491: mptcp: make fallback action and fallback decision atomic (bsc#1247280).
  • CVE-2025-38499: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (bsc#1247976).
  • CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248088).
  • CVE-2025-38506: KVM: Allow CPU to reschedule while setting per-page memory attributes (bsc#1248186).
  • CVE-2025-38514: rxrpc: Fix oops due to non-existence of prealloc backlog struct (bsc#1248202).
  • CVE-2025-38520: drm/amdkfd: Do not call mmput from MMU notifier callback (bsc#1248217).
  • CVE-2025-38524: rxrpc: Fix recv-recv race of completed call (bsc#1248194).
  • CVE-2025-38526: ice: add NULL check in eswitch lag check (bsc#1248192).
  • CVE-2025-38527: smb: client: fix use-after-free in cifs_oplock_break (bsc#1248199).
  • CVE-2025-38528: bpf: Reject %p% format string in bprintf-like helpers (bsc#1248198).
  • CVE-2025-38531: iio: common: st_sensors: Fix use of uninitialize device structs (bsc#1248205).
  • CVE-20

Affected software

SUSE-SU-2025:03634-1 is recorded against 3 packages.

  • kernel-azure (fixed in 6.4.0-150600.8.52.1)
  • kernel-source-azure (fixed in 6.4.0-150600.8.52.1)
  • kernel-syms-azure (fixed in 6.4.0-150600.8.52.1)

Timeline and source

Published on 17 October 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-10-17
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-azure 6.4.0-150600.8.52.1
kernel-source-azure 6.4.0-150600.8.52.1
kernel-syms-azure 6.4.0-150600.8.52.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:03634-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:03634-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.