Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:4521-1 — kernel-livepatch-sle15-sp6-rt-update-18 (CVE-2022-50253 +64 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP6 RT kernel was updated to receive various security bugfixes.

The following security bugs were fixed:

  • CVE-2022-50253: bpf: make sure skb->len != 0 when redirecting to a tunneling device (bsc#1249912).
  • CVE-2023-53676: scsi: target: iscsi: Fix buffer overflow in lio_target_nacl_info_show() (bsc#1251786).
  • CVE-2025-21710: tcp: correct handling of extreme memory squeeze (bsc#1237888).
  • CVE-2025-37916: pds_core: remove write-after-free of client_id (bsc#1243474).
  • CVE-2025-38359: s390/mm: Fix in_atomic() handling in do_secure_storage_access() (bsc#1247076).
  • CVE-2025-38361: drm/amd/display: Check dce_hwseq before dereferencing it (bsc#1247079).
  • CVE-2025-39788: scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE (bsc#1249547).
  • CVE-2025-39805: net: macb: fix unregister_netdev call order in macb_remove() (bsc#1249982).
  • CVE-2025-39819: fs/smb: Fix inconsistent refcnt update (bsc#1250176).
  • CVE-2025-39859: ptp: ocp: fix use-after-free bugs causing by ptp_ocp_watchdog (bsc#1250252).
  • CVE-2025-39944: octeontx2-pf: Fix use-after-free bugs in otx2_sync_tstamp() (bsc#1251120).
  • CVE-2025-39980: nexthop: Forbid FDB status change while nexthop is in a group (bsc#1252063).
  • CVE-2025-40001: scsi: mvsas: Fix use-after-free bugs in mvs_work_queue (bsc#1252303).
  • CVE-2025-40021: tracing: dynevent: Add a missing lockdown check on dynevent (bsc#1252681).
  • CVE-2025-40027: net/9p: fix double req put in p9_fd_cancelled (bsc#1252763).
  • CVE-2025-40030: pinctrl: check the return value of pinmux_ops::get_function_name() (bsc#1252773).
  • CVE-2025-40038: KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid (bsc#1252817).
  • CVE-2025-40040: mm/ksm: fix flag-dropping behavior in ksm_madvise (bsc#1252780).
  • CVE-2025-40048: uio_hv_generic: Let userspace take care of interrupt mask (bsc#1252862).
  • CVE-2025-40055: ocfs2: fix double free in user_cluster_connect() (bsc#1252821).
  • CVE-2025-40059: coresight: Fix incorrect handling for return value of devm_kzalloc (bsc#1252809).
  • CVE-2025-40064: smc: Fix use-after-free in __pnet_find_base_ndev() (bsc#1252845).
  • CVE-2025-40070: pps: fix warning in pps_register_cdev when register device fail (bsc#1252836).
  • CVE-2025-40074: ipv4: start using dst_dev_rcu() (bsc#1252794).
  • CVE-2025-40075: tcp_metrics: use dst_dev_net_rcu() (bsc#1252795).
  • CVE-2025-40083: net/sched: sch_qfq: Fix null-deref in agg_dequeue (bsc#1252912).
  • CVE-2025-40098: ALSA: hda: cs35l41: Fix NULL pointer dereference in cs35l41_get_acpi_mute_state() (bsc#1252917).
  • CVE-2025-40105: vfs: Don't leak disconnected dentries on umount (bsc#1252928).
  • CVE-2025-40139: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set() (bsc#1253409).
  • CVE-2025-40149: tls: Use __sk_dst_get() and dst_dev_rcu() in get_netdev_for_sock() (bsc#1253355).
  • CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation (bsc#1253403).
  • CVE-2025-40168: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match() (bsc#1253427).
  • CVE-2025-40169: bpf: Reject negative offsets for ALU ops (bsc#1253416).
  • CVE-2025-40173: net/ip6_tunnel: Prevent perpetual tunnel growth (bsc#1253421).
  • CVE-2025-40176: tls: wait for pending async decryptions if tls_strp_msg_hold fails (bsc#1253425).
  • CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253436).

The following non-security bugs were fixed:

  • ACPI: CPPC: Check _CPC validity for only the online CPUs (git-fixes).
  • ACPI: CPPC: Limit perf ctrs in PCC check only to online CPUs (git-fixes).
  • ACPI: CPPC: Perform fast check switch only for online CPUs (git-fixes).
  • ACPI: PRM: Skip handlers with NULL handler_address or NULL VA (stable-fixes).
  • ACPI: SBS: Fix present test in acpi_battery_read() (git-fixes).
  • ACPI: property: Return present device nodes only on fwnode interface (stable-fixes).
  • ACPI: scan: Add Intel CVS ACPI HIDs to acpi_ignore_dep_ids (stable-fixes).
  • ACPICA: Update dsmethod.c to get rid of unused variable warning (stable-fixes).
  • ACPICA: dispatcher: Use acpi_ds_clear_operands() in acpi_ds_call_control_method() (stable-fixes).
  • ALSA: hda: Fix missing pointer check in hda_component_manager_init function (git-fixes).
  • ALSA: serial-generic: remove shared static buffer (stable-fixes).
  • ALSA: usb-audio: Add validation of UAC2/UAC3 effect units (stable-fixes).
  • ALSA: usb-audio: Fix NULL pointer dereference in snd_usb_mixer_controls_badd (git-fixes).
  • ALSA: usb-audio: Fix potential overflow of PCM transfer buffer (stable-fixes).
  • ALSA: usb-audio: add mono main switch to Presonus S1824c (stable-fixes).
  • ALSA: usb-audio: apply quirk for MOONDROP Quark2 (stable-fixes).
  • ALSA: usb-audio: do not log messages meant for 1810c when initializing 1824c (git-fixes).
  • ALSA: usb-audio: fix uac2 clock source at terminal parser (git-fixes).
  • ASoC: codecs: va-macro: fix resource leak in probe error path (git-fixes).
  • ASoC: cs4271: Fix regulator leak on probe failure (g

Affected software

SUSE-SU-2025:4521-1 is recorded against 5 packages.

  • kernel-livepatch-sle15-sp6-rt-update-18 (fixed in 1-150600.1.3.1)
  • kernel-rt (fixed in 6.4.0-150600.10.61.1)
  • kernel-rt-debug (fixed in 6.4.0-150600.10.61.1)
  • kernel-source-rt (fixed in 6.4.0-150600.10.61.1)
  • kernel-syms-rt (fixed in 6.4.0-150600.10.61.1)

Timeline and source

Published on 24 December 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-12-24
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-livepatch-sle15-sp6-rt-update-18 1-150600.1.3.1
kernel-rt 6.4.0-150600.10.61.1
kernel-rt-debug 6.4.0-150600.10.61.1
kernel-source-rt 6.4.0-150600.10.61.1
kernel-syms-rt 6.4.0-150600.10.61.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:4521-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:4521-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.