Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:20756-1 — kernel-rt (CVE-2024-46733 +95 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2024-46733: btrfs: fix qgroup reserve leaks in cow_file_range (bsc#1230708).
  • CVE-2025-38006: net: mctp: Do not access ifa_index when missing (bsc#1244930).
  • CVE-2025-38075: scsi: target: iscsi: Fix timeout on deleted connection (bsc#1244734).
  • CVE-2025-38103: HID: usbhid: Eliminate recurrent out-of-bounds bug in usbhid_parse() (bsc#1245663).
  • CVE-2025-38125: net: stmmac: make sure that ptp_rate is not 0 before configuring EST (bsc#1245710).
  • CVE-2025-38146: net: openvswitch: Fix the dead loop of MPLS parse (bsc#1245767).
  • CVE-2025-38160: clk: bcm: rpi: Add NULL check in raspberrypi_clk_register() (bsc#1245780).
  • CVE-2025-38184: tipc: fix null-ptr-deref when acquiring remote ip of ethernet bearer (bsc#1245956).
  • CVE-2025-38185: atm: atmtcp: Free invalid length skb in atmtcp_c_send() (bsc#1246012).
  • CVE-2025-38190: atm: Revert atm_account_tx() if copy_from_iter_full() fails (bsc#1245973).
  • CVE-2025-38201: netfilter: nft_set_pipapo: clamp maximum map bucket size to INT_MAX (bsc#1245977).
  • CVE-2025-38205: drm/amd/display: Avoid divide by zero by initializing dummy pitch to 1 (bsc#1246005).
  • CVE-2025-38208: smb: client: add NULL check in automount_fullpath (bsc#1245815).
  • CVE-2025-38245: atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister() (bsc#1246193).
  • CVE-2025-38251: atm: clip: prevent NULL deref in clip_push() (bsc#1246181).
  • CVE-2025-38360: drm/amd/display: Add more checks for DSC / HUBP ONO guarantees (bsc#1247078).
  • CVE-2025-38439: bnxt_en: Set DMA unmap len correctly for XDP_REDIRECT (bsc#1247155).
  • CVE-2025-38441: netfilter: flowtable: account for Ethernet header in nf_flow_pppoe_proto() (bsc#1247167).
  • CVE-2025-38444: raid10: cleanup memleak at raid10_make_request (bsc#1247162).
  • CVE-2025-38445: md/raid1: Fix stack memory use after return in raid1_reshape (bsc#1247229).
  • CVE-2025-38458: atm: clip: Fix NULL pointer dereference in vcc_sendmsg() (bsc#1247116).
  • CVE-2025-38459: atm: clip: Fix infinite recursive call of clip_push() (bsc#1247119).
  • CVE-2025-38464: tipc: Fix use-after-free in tipc_conn_close() (bsc#1247112).
  • CVE-2025-38472: netfilter: nf_conntrack: fix crash due to removal of uninitialised entry (bsc#1247313).
  • CVE-2025-38490: net: libwx: remove duplicate page_pool_put_full_page() (bsc#1247243).
  • CVE-2025-38491: mptcp: make fallback action and fallback decision atomic (bsc#1247280).
  • CVE-2025-38499: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (bsc#1247976).
  • CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248088).
  • CVE-2025-38506: KVM: Allow CPU to reschedule while setting per-page memory attributes (bsc#1248186).
  • CVE-2025-38520: drm/amdkfd: Do not call mmput from MMU notifier callback (bsc#1248217).
  • CVE-2025-38524: rxrpc: Fix recv-recv race of completed call (bsc#1248194).
  • CVE-2025-38528: bpf: Reject %p% format string in bprintf-like helpers (bsc#1248198).
  • CVE-2025-38531: iio: common: st_sensors: Fix use of uninitialize device structs (bsc#1248205).
  • CVE-2025-38546: atm: clip: Fix memory leak of struct clip_vcc (bsc#1248223).
  • CVE-2025-38560: x86/sev: Evict cache lines during SNP memory validation (bsc#1248312).
  • CVE-2025-38585: staging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int() (bsc#1248355).
  • CVE-2025-38591: bpf: Reject narrower access to pointer ctx fields (bsc#1248363).
  • CVE-2025-38608: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls (bsc#1248338).
  • CVE-2025-38618: vsock: Do not allow binding to VMADDR_PORT_ANY (bsc#1248511).

The following non-security bugs were fixed:

  • ACPI: APEI: send SIGBUS to current task if synchronous memory error not recovered (stable-fixes).
  • ACPI: pfr_update: Fix the driver update version check (git-fixes).
  • ACPI: processor: fix acpi_object initialization (stable-fixes).
  • ACPI: processor: perflib: Move problematic pr->performance check (git-fixes).
  • ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control (stable-fixes).
  • ALSA: hda/realtek: Add Framework Laptop 13 (AMD Ryzen AI 300) to quirks (stable-fixes).
  • ALSA: hda/realtek: Add support for HP EliteBook x360 830 G6 and EliteBook 830 G6 (stable-fixes).
  • ALSA: hda/realtek: Audio disappears on HP 15-fc000 after warm boot again (git-fixes).
  • ALSA: hda/realtek: Fix headset mic on ASUS Zenbook 14 (git-fixes).
  • ALSA: hda/realtek: Fix headset mic on HONOR BRB-X (stable-fixes).
  • ALSA: hda: Disable jack polling at shutdown (stable-fixes).
  • ALSA: hda: Handle the jack polling always via a work (stable-fixes).
  • ALSA: intel8x0: Fix incorrect codec index usage in mixer for ICH4 (stable-fixes).
  • ALSA: pcm: Rewrite recalculate_boundary() to avoid costly loop (stable-fixes).
  • ALSA: scarlett2: Add retry on -EPROTO from scarlett2_

Affected software

SUSE-SU-2025:20756-1 is recorded against 2 packages.

  • kernel-rt (fixed in 6.4.0-36.1)
  • kernel-source-rt (fixed in 6.4.0-36.1)

Timeline and source

Published on 23 September 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-09-23
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-rt 6.4.0-36.1
kernel-source-rt 6.4.0-36.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20756-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20756-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.