🛡️ SUSE-SU-2026:1131-1 — kernel-rt (CVE-2024-46854 +43 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2024-46854: net: dpaa: Pad packets to ETH_ZLEN (bsc#1231084).
  • CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the allocated buffer (bsc#1238917).
  • CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075).
  • CVE-2025-68312: usbnet: Prevents free active kevent (bsc#1255171).
  • CVE-2025-71066: net/sched: ets: Always remove class from active list before deleting in ets_qdisc_change

(bsc#1256645).

  • CVE-2025-71085: ipv6: BUG() in pskb_expand_head() as part of calipso_skbuff_setattr() (bsc#1256623).
  • CVE-2025-71112: net: hns3: add VLAN id validation before using (bsc#1256726).
  • CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257236).
  • CVE-2026-23001: macvlan: fix possible UAF in macvlan_forward_source() (bsc#1257232).
  • CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231).
  • CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec (bsc#1257735).
  • CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1257749).
  • CVE-2026-23089: ALSA: usb-audio: Fix use-after-free in snd_usb_mixer_free() (bsc#1257790).
  • CVE-2026-23191: ALSA: aloop: Fix racy access at PCM trigger (bsc#1258395).
  • CVE-2026-23204: net: add skb_header_pointer_careful() helper (bsc#1258340).
  • CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258518).
  • CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1258850).
  • CVE-2026-23269: apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1259857).

The following non security issues were fixed:

  • apparmor: fix differential encoding verification (bsc#1258849).
  • apparmor: Fix double free of ns_name in aa_replace_profiles() (bsc#1258849).
  • apparmor: fix memory leak in verify_header (bsc#1258849).
  • apparmor: fix missing bounds check on DEFAULT table in verify_dfa() (bsc#1258849).
  • apparmor: fix race between freeing data and fs accessing it (bsc#1258849).
  • apparmor: fix race on rawdata dereference (bsc#1258849).
  • apparmor: fix side-effect bug in match_char() macro usage (bsc#1258849).
  • apparmor: fix unprivileged local user can do privileged policy management (bsc#1258849).
  • apparmor: fix: limit the number of levels of policy namespaces (bsc#1258849).
  • apparmor: replace recursive profile removal with iterative approach (bsc#1258849).
  • apparmor: validate DFA start states are in bounds in unpack_pdb (bsc#1258849).
  • net: hv_netvsc: reject RSS hash key programming without RX indirection table (bsc#1257473).
  • net: tcp: allow zero-window ACK update the window (bsc#1254767).
  • net: tcp: send zero-window ACK when no memory (bsc#1254767).
  • scsi: storvsc: Process unsupported MODE_SENSE_10 (bsc#1257296).
  • tcp: correct handling of extreme memory squeeze (bsc#1254767).
  • x86/its: Fix crash during dynamic its initialization (bsc#1257771).
  • x86/modules: Set VM_FLUSH_RESET_PERMS in module_alloc() (bsc#1257771).

Affected software

SUSE-SU-2026:1131-1 is recorded against 2 packages.

  • kernel-rt (fixed in 5.14.21-150400.15.145.1)
  • kernel-source-rt (fixed in 5.14.21-150400.15.145.1)

Timeline and source

Published on 27 March 2026 and last revised on 31 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-03-27
Updated 2026-08-20
Modified 2026-03-31
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-rt 5.14.21-150400.15.145.1
kernel-source-rt 5.14.21-150400.15.145.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:1131-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:1131-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2026