🛡️ SUSE-SU-2026:0278-1 — kernel-livepatch-sle15-sp7-rt-update-8 (CVE-2025-38321 +394 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2025-38321: smb: Log an error when close_all_cached_dirs fails (bsc#1246328).
  • CVE-2025-38728: smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256).
  • CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046).
  • CVE-2025-40006: mm/hugetlb: fix folio is still mapped when deleted (bsc#1252342).
  • CVE-2025-40024: vhost: Take a reference on the task in struct vhost_task (bsc#1252686).
  • CVE-2025-40033: remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (bsc#1252824).
  • CVE-2025-40042: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (bsc#1252861).
  • CVE-2025-40053: net: dlink: handle copy_thresh allocation failure (bsc#1252808).
  • CVE-2025-40081: perf: arm_spe: Prevent overflow in PERF_IDX2OFF() (bsc#1252776).
  • CVE-2025-40102: KVM: arm64: Prevent access to vCPU events before init (bsc#1252919).
  • CVE-2025-40134: dm: fix NULL pointer dereference in __dm_suspend() (bsc#1253386).
  • CVE-2025-40135: ipv6: use RCU in ip6_xmit() (bsc#1253342).
  • CVE-2025-40153: mm: hugetlb: avoid soft lockup when mprotect to large memory area (bsc#1253408).
  • CVE-2025-40158: ipv6: use RCU in ip6_output() (bsc#1253402).
  • CVE-2025-40160: xen/events: Cleanup find_virq() return codes (bsc#1253400).
  • CVE-2025-40167: ext4: detect invalid INLINE_DATA + EXTENTS flag combination (bsc#1253458).
  • CVE-2025-40170: net: use dst_dev_rcu() in sk_setup_caps() (bsc#1253413).
  • CVE-2025-40178: pid: Add a judgment for ns null in pid_nr_ns (bsc#1253463).
  • CVE-2025-40179: ext4: verify orphan file size is not too big (bsc#1253442).
  • CVE-2025-40187: net/sctp: fix a null dereference in sctp_disposition sctp_sf_do_5_1D_ce() (bsc#1253647).
  • CVE-2025-40190: ext4: guard against EA inode refcount underflow in xattr update (bsc#1253623).
  • CVE-2025-40215: kABI: xfrm: delete x->tunnel as we delete x (bsc#1254959).
  • CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520).
  • CVE-2025-40231: vsock: fix lock inversion in vsock_assign_transport() (bsc#1254815).
  • CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813).
  • CVE-2025-40240: sctp: avoid NULL dereference when chunk data buffer is missing (bsc#1254869).
  • CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075).
  • CVE-2025-40248: vsock: Ignore signal/timeout on connect() if already established (bsc#1254864).
  • CVE-2025-40250: net/mlx5: Clean up only new IRQ glue on request_irq() failure (bsc#1254854).
  • CVE-2025-40251: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy (bsc#1254856).
  • CVE-2025-40252: net: qlogic/qede: fix potential out-of-bounds read in qede_tpa_cont() and qede_tpa_end() (bsc#1254849).
  • CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1254843).
  • CVE-2025-40268: cifs: client: fix memory leak in smb3_fs_context_parse_param (bsc#1255082).
  • CVE-2025-40271: fs/proc: fix uaf in proc_readdir_de() (bsc#1255297).
  • CVE-2025-40274: KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying (bsc#1254830).
  • CVE-2025-40278: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak (bsc#1254825).
  • CVE-2025-40279: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak (bsc#1254846).
  • CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847).
  • CVE-2025-40287: exfat: fix improper check of dentry.stream.valid_size (bsc#1255030).
  • CVE-2025-40289: drm/amdgpu: hide VRAM sysfs attributes on GPUs without VRAM (bsc#1255042).
  • CVE-2025-40292: virtio-net: fix received length check in big packets (bsc#1255175).
  • CVE-2025-40293: iommufd: Don't overflow during division for dirty tracking (bsc#1255179).
  • CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255187).
  • CVE-2025-40307: exfat: validate cluster allocation bits of the allocation bitmap (bsc#1255039).
  • CVE-2025-40319: bpf: Sync pending IRQ work before freeing ring buffer (bsc#1254794).
  • CVE-2025-40330: bnxt_en: Shutdown FW DMA in bnxt_shutdown() (bsc#1254616).
  • CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615).
  • CVE-2025-40337: net: stmmac: Correctly handle Rx checksum offload errors (bsc#1255081).
  • CVE-2025-40338: ASoC: Intel: avs: Do not share the name pointer between components (bsc#1255273).
  • CVE-2025-40346: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (bsc#1255318).
  • CVE-2025-40357: net/smc: fix general protection fault in __smc_diag_dump (bsc#1255097).
  • CVE-2025-68197: bnxt_en: Fix null pointer dereference in bnxt_bs_trace_check_wrap() (bsc#1255242).
  • CVE-2025-68204: pmdomain: arm: scmi: Fix genpd leak on provider registration failure (bsc#1255224).
  • CVE-2025-68206: netfilter: nft_ct: add seqa

Affected software

SUSE-SU-2026:0278-1 is recorded against 4 packages.

  • kernel-livepatch-sle15-sp7-rt-update-8 (fixed in 1-150700.1.3.1)
  • kernel-rt (fixed in 6.4.0-150700.7.28.1)
  • kernel-source-rt (fixed in 6.4.0-150700.7.28.1)
  • kernel-syms-rt (fixed in 6.4.0-150700.7.28.1)

Timeline and source

Published on 23 January 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-01-23
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-livepatch-sle15-sp7-rt-update-8 1-150700.1.3.1
kernel-rt 6.4.0-150700.7.28.1
kernel-source-rt 6.4.0-150700.7.28.1
kernel-syms-rt 6.4.0-150700.7.28.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:0278-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:0278-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026