Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2026:20931-1 — kernel-64kb (CVE-2025-39753 +175 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues.

The following security issues were fixed:

  • CVE-2025-39753: gfs2: Set .migrate_folio in gfs2_{rgrp,meta}_aops (bsc#1249590).
  • CVE-2025-39964: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg (bsc#1251966).
  • CVE-2025-40099: cifs: parse_dfs_referrals: prevent oob on malformed input (bsc#1252911).
  • CVE-2025-40103: smb: client: Fix refcount leak for cifs_sb_tlink (bsc#1252924).
  • CVE-2025-40230: mm: prevent poison consumption when splitting THP (bsc#1254817).
  • CVE-2025-68173: ftrace: Fix softlockup in ftrace_module_enable (bsc#1255311).
  • CVE-2025-68186: ring-buffer: Do not warn in ring_buffer_map_get_reader() when reader catches up (bsc#1255144).
  • CVE-2025-68292: mm/memfd: fix information leak in hugetlb folios (bsc#1255148).
  • CVE-2025-68295: smb: client: fix memory leak in cifs_construct_tcon() (bsc#1255129).
  • CVE-2025-68329: tracing: Fix WARN_ON in tracing_buffers_mmap_close for split VMAs (bsc#1255490).
  • CVE-2025-68371: scsi: smartpqi: Fix device resources accessed after device removal (bsc#1255572).
  • CVE-2025-68745: scsi: qla2xxx: Clear cmds after chip reset (bsc#1255721).
  • CVE-2025-68785: net: openvswitch: fix middle attribute validation in push_nsh() action (bsc#1256640).
  • CVE-2025-68810: KVM: Disallow toggling KVM_MEM_GUEST_MEMFD on an existing memslot (bsc#1256679).
  • CVE-2025-71071: iommu/mediatek: fix use-after-free on probe deferral (bsc#1256802).
  • CVE-2025-71104: KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (bsc#1256708).
  • CVE-2025-71125: tracing: Do not register unsupported perf events (bsc#1256784).
  • CVE-2025-71134: mm/page_alloc: change all pageblocks migrate type on coalescing (bsc#1256732).
  • CVE-2025-71161: dm-verity: disable recursive forward error correction (bsc#1257174).
  • CVE-2025-71184: btrfs: tracepoints: use btrfs_root_id() to get the id of a root (bsc#1257635).
  • CVE-2025-71193: phy: qcom-qusb2: Fix NULL pointer dereference on early suspend (bsc#1257686).
  • CVE-2025-71225: md: suspend array while updating raid_disks via sysfs (bsc#1258411).
  • CVE-2026-22979: net: fix memory leak in skb_segment_list for GRO packets (bsc#1257228).
  • CVE-2026-22998: nvme-tcp: fix NULL pointer dereferences in nvmet_tcp_build_pdu_iovec (bsc#1257209).
  • CVE-2026-23003: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() (bsc#1257246).
  • CVE-2026-23004: dst: fix races in rt6_uncached_list_del() and rt_del_uncached_list() (bsc#1257231).
  • CVE-2026-23010: ipv6: Fix use-after-free in inet6_addr_del() (bsc#1257332).
  • CVE-2026-23017: idpf: fix error handling in the init_task on load (bsc#1257552).
  • CVE-2026-23022: idpf: fix memory leak in idpf_vc_core_deinit() (bsc#1257581).
  • CVE-2026-23023: idpf: fix memory leak in idpf_vport_rel() (bsc#1257556).
  • CVE-2026-23024: idpf: fix memory leak of flow steer list on rmmod (bsc#1257572).
  • CVE-2026-23035: net/mlx5e: Pass netdev to mlx5e_destroy_netdev instead of priv (bsc#1257559).
  • CVE-2026-23042: idpf: fix aux device unplugging when rdma is not supported by vport (bsc#1257705).
  • CVE-2026-23047: libceph: make calc_target() set t->paused, not just clear it (bsc#1257682).
  • CVE-2026-23053: NFS: Fix a deadlock involving nfs_release_folio() (bsc#1257718).
  • CVE-2026-23057: vsock/virtio: Coalesce only linear skb (bsc#1257740).
  • CVE-2026-23064: net/sched: act_ife: avoid possible NULL deref (bsc#1257765).
  • CVE-2026-23066: rxrpc: Fix recvmsg() unconditional requeue (bsc#1257726).
  • CVE-2026-23068: spi: spi-sprd-adi: Fix double free in probe error path (bsc#1257805).
  • CVE-2026-23069: vsock/virtio: fix potential underflow in virtio_transport_get_credit() (bsc#1257755).
  • CVE-2026-23070: Octeontx2-af: Add proper checks for fwdata (bsc#1257709).
  • CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1257749).
  • CVE-2026-23083: tools: ynl-gen: use big-endian netlink attribute types (bsc#1257745).
  • CVE-2026-23084: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list (bsc#1257830).
  • CVE-2026-23085: irqchip/gic-v3-its: Avoid truncating memory addresses (bsc#1257758).
  • CVE-2026-23086: vsock/virtio: cap TX credit to local buffer size (bsc#1257757).
  • CVE-2026-23088: tracing: Fix crash on synthetic stacktrace field usage (bsc#1257814).
  • CVE-2026-23095: gue: Fix skb memleak with inner IP protocol 0 (bsc#1257808).
  • CVE-2026-23097: migrate: correct lock ordering for hugetlb file folios (bsc#1257815).
  • CVE-2026-23099: bonding: limit BOND_MODE_8023AD to Ethernet devices (bsc#1257816).
  • CVE-2026-23100: mm/hugetlb: fix hugetlb_pmd_shared() (bsc#1257817).
  • CVE-2026-23102: arm64/fpsimd: signal: Fix restoration of SVE context (bsc#1257772).
  • CVE-2026-23104: ice: fix devlink reload call trace (bsc#1257763).
  • CVE-2026-23105: net/sched: qfq: Use cl_is_active to determine whether class is active in qfq_rm_from_ag (bsc#1257775).
  • CVE-2026-23107: arm64/fpsimd:

Affected software

SUSE-SU-2026:20931-1 is recorded against 10 packages.

  • kernel-64kb (fixed in 6.12.0-160000.27.1)
  • kernel-azure (fixed in 6.12.0-160000.27.1)
  • kernel-default (fixed in 6.12.0-160000.27.1)
  • kernel-default-base (fixed in 6.12.0-160000.27.1.160000.2.8)
  • kernel-docs (fixed in 6.12.0-160000.27.1)
  • kernel-kvmsmall (fixed in 6.12.0-160000.27.1)
  • kernel-obs-qa (fixed in 6.12.0-160000.27.1)
  • kernel-source (fixed in 6.12.0-160000.27.1)
  • kernel-syms (fixed in 6.12.0-160000.27.1)
  • kernel-zfcpdump (fixed in 6.12.0-160000.27.1)

Timeline and source

Published on 25 March 2026 and last revised on 2 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2026-03-25
Updated 2026-08-20
Modified 2026-04-02
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-64kb 6.12.0-160000.27.1
kernel-azure 6.12.0-160000.27.1
kernel-default 6.12.0-160000.27.1
kernel-default-base 6.12.0-160000.27.1.160000.2.8
kernel-docs 6.12.0-160000.27.1
kernel-kvmsmall 6.12.0-160000.27.1
kernel-obs-qa 6.12.0-160000.27.1
kernel-source 6.12.0-160000.27.1
kernel-syms 6.12.0-160000.27.1
kernel-zfcpdump 6.12.0-160000.27.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2026:20931-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:20931-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.