Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:20220-1 — kernel-64kb (CVE-2025-38704 +214 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues

The following security issues were fixed:

  • CVE-2025-38704: rcu/nocb: Fix possible invalid rdp's->nocb_cb_kthread pointer (bsc#1254408).
  • CVE-2025-39880: ceph: fix race condition validating r_parent before applying state (bsc#1250388).
  • CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046).
  • CVE-2025-40042: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (bsc#1252861).
  • CVE-2025-40123: bpf: Enforce expected_attach_type for tailcall compatibility (bsc#1253365).
  • CVE-2025-40130: scsi: ufs: core: Fix data race in CPU latency PM QoS request handling
  • CVE-2025-40160: xen/events: Cleanup find_virq() return codes (bsc#1253400).
  • CVE-2025-40167: ext4: detect invalid INLINE_DATA + EXTENTS flag combination (bsc#1253458).
  • CVE-2025-40170: net: use dst_dev_rcu() in sk_setup_caps() (bsc#1253413).
  • CVE-2025-40179: ext4: verify orphan file size is not too big (bsc#1253442).
  • CVE-2025-40190: ext4: guard against EA inode refcount underflow in xattr update (bsc#1253623).
  • CVE-2025-40214: af_unix: Initialise scc_index in unix_add_edge() (bsc#1254961).
  • CVE-2025-40215: xfrm: delete x->tunnel as we delete x (bsc#1254959).
  • CVE-2025-40218: mm/damon/vaddr: do not repeat pte_offset_map_lock() until success (bsc#1254964).
  • CVE-2025-40220: fuse: fix livelock in synchronous file put from fuseblk workers (bsc#1254520).
  • CVE-2025-40231: vsock: fix lock inversion in vsock_assign_transport() (bsc#1254815).
  • CVE-2025-40233: ocfs2: clear extent cache after moving/defragmenting extents (bsc#1254813).
  • CVE-2025-40237: fs/notify: call exportfs_encode_fid with s_umount (bsc#1254809).
  • CVE-2025-40238: net/mlx5: Fix IPsec cleanup over MPV device (bsc#1254871).
  • CVE-2025-40239: net: phy: micrel: always set shared->phydev for LAN8814 (bsc#1254868).
  • CVE-2025-40242: gfs2: Fix unlikely race in gdlm_put_lock (bsc#1255075).
  • CVE-2025-40246: xfs: fix out of bounds memory read error in symlink repair (bsc#1254861).
  • CVE-2025-40248: vsock: Ignore signal/timeout on connect() if already established (bsc#1254864).
  • CVE-2025-40250: net/mlx5: Clean up only new IRQ glue on request_irq() failure (bsc#1254854).
  • CVE-2025-40251: devlink: rate: Unset parent pointer in devl_rate_nodes_destroy (bsc#1254856).
  • CVE-2025-40252: net: qlogic/qede: fix potential out-of-bounds read in

qede_tpa_cont() and qede_tpa_end() (bsc#1254849).

  • CVE-2025-40254: net: openvswitch: remove never-working support for setting nsh fields (bsc#1254852).
  • CVE-2025-40255: net: core: prevent NULL deref in generic_hwtstamp_ioctl_lower() (bsc#1255156).
  • CVE-2025-40258: mptcp: fix race condition in mptcp_schedule_work() (bsc#1254843).
  • CVE-2025-40264: be2net: pass wrb_params in case of OS2BMC (bsc#1254835).
  • CVE-2025-40268: cifs: client: fix memory leak in smb3_fs_context_parse_param (bsc#1255082).
  • CVE-2025-40271: fs/proc: fix uaf in proc_readdir_de() (bsc#1255297).
  • CVE-2025-40274: KVM: guest_memfd: Remove bindings on memslot deletion when gmem is dying (bsc#1254830).
  • CVE-2025-40276: drm/panthor: Flush shmem writes before mapping buffers CPU-uncached (bsc#1254824).
  • CVE-2025-40278: net: sched: act_ife: initialize struct tc_ife to fix KMSAN kernel-infoleak (bsc#1254825).
  • CVE-2025-40279: net: sched: act_connmark: initialize struct tc_ife to fix kernel leak (bsc#1254846).
  • CVE-2025-40280: tipc: Fix use-after-free in tipc_mon_reinit_self() (bsc#1254847).
  • CVE-2025-40292: virtio-net: fix received length check in big packets (bsc#1255175).
  • CVE-2025-40293: iommufd: Don't overflow during division for dirty tracking (bsc#1255179).
  • CVE-2025-40297: net: bridge: fix use-after-free due to MST port state bypass (bsc#1255187).
  • CVE-2025-40319: bpf: Sync pending IRQ work before freeing ring buffer (bsc#1254794).
  • CVE-2025-40328: smb: client: fix potential UAF in smb2_close_cached_fid() (bsc#1254624).
  • CVE-2025-40330: bnxt_en: Shutdown FW DMA in bnxt_shutdown() (bsc#1254616).
  • CVE-2025-40331: sctp: Prevent TOCTOU out-of-bounds write (bsc#1254615).
  • CVE-2025-40338: ASoC: Intel: avs: Do not share the name pointer between components (bsc#1255273).
  • CVE-2025-40346: arch_topology: Fix incorrect error check in topology_parse_cpu_capacity() (bsc#1255318).
  • CVE-2025-40347: net: enetc: fix the deadlock of enetc_mdio_lock (bsc#1255262).
  • CVE-2025-40350: net/mlx5e: RX, Fix generating skb from non-linear xdp_buff for striding RQ (bsc#1255260).
  • CVE-2025-40355: sysfs: check visibility before changing group attribute ownership (bsc#1255261).
  • CVE-2025-40357: net/smc: fix general protection fault in __smc_diag_dump (bsc#1255097).
  • CVE-2025-40359: perf/x86/intel: Fix KASAN global-out-of-bounds warning (bsc#1255087).
  • CVE-2025-40362: ceph: fix multifs mds auth caps issue (bsc#1255103).
  • CVE-2025-68171: x86/fpu: Ensure XFD state on signal delivery (bsc#1255255).
  • CVE-2025-68197: bnxt_en: Fix n

Affected software

SUSE-SU-2026:20220-1 is recorded against 10 packages.

  • kernel-64kb (fixed in 6.12.0-160000.9.1)
  • kernel-azure (fixed in 6.12.0-160000.9.1)
  • kernel-default (fixed in 6.12.0-160000.9.1)
  • kernel-default-base (fixed in 6.12.0-160000.9.1.160000.2.6)
  • kernel-docs (fixed in 6.12.0-160000.9.1)
  • kernel-kvmsmall (fixed in 6.12.0-160000.9.1)
  • kernel-obs-qa (fixed in 6.12.0-160000.9.1)
  • kernel-source (fixed in 6.12.0-160000.9.1)
  • kernel-syms (fixed in 6.12.0-160000.9.1)
  • kernel-zfcpdump (fixed in 6.12.0-160000.9.1)

Timeline and source

Published on 2 February 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-02-02
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-64kb 6.12.0-160000.9.1
kernel-azure 6.12.0-160000.9.1
kernel-default 6.12.0-160000.9.1
kernel-default-base 6.12.0-160000.9.1.160000.2.6
kernel-docs 6.12.0-160000.9.1
kernel-kvmsmall 6.12.0-160000.9.1
kernel-obs-qa 6.12.0-160000.9.1
kernel-source 6.12.0-160000.9.1
kernel-syms 6.12.0-160000.9.1
kernel-zfcpdump 6.12.0-160000.9.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:20220-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:20220-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.