SUSE update for the Linux Kernel



| Updated: 2025-11-28
Risk High
Patch available YES
Number of vulnerabilities 17
CVE-ID CVE-2022-50116
CVE-2024-53177
CVE-2024-58239
CVE-2025-38180
CVE-2025-38323
CVE-2025-38352
CVE-2025-38460
CVE-2025-38498
CVE-2025-38499
CVE-2025-38546
CVE-2025-38555
CVE-2025-38560
CVE-2025-38563
CVE-2025-38608
CVE-2025-38617
CVE-2025-38618
CVE-2025-38644
CWE-ID CWE-667
CWE-416
CWE-835
CWE-362
CWE-476
CWE-269
CWE-20
CWE-401
CWE-908
Exploitation vector Local
Public exploit Public exploit code for vulnerability #3 is available.
Vulnerability #6 is being exploited in the wild.
Vulnerable software
SUSE Manager Server 4.3
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server 4.3
Operating systems & Components / Operating system

SUSE Manager Proxy 4.3
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15 SP4
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing LTSS 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing ESPOS 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro for Rancher
Operating systems & Components / Operating system

SUSE Linux Enterprise High Availability Extension 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Micro
Operating systems & Components / Operating system

SUSE Linux Enterprise Live Patching
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Server 15
Operating systems & Components / Operating system

SUSE Linux Enterprise Real Time 15
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing 15
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server
Operating systems & Components / Operating system

SUSE Manager Server
Operating systems & Components / Operating system

SUSE Manager Proxy
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

kernel-64kb
Operating systems & Components / Operating system package or component

kernel-64kb-debugsource
Operating systems & Components / Operating system package or component

kernel-64kb-optional-debuginfo
Operating systems & Components / Operating system package or component

dtb-hisilicon
Operating systems & Components / Operating system package or component

dlm-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-devel
Operating systems & Components / Operating system package or component

dtb-broadcom
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-qcom
Operating systems & Components / Operating system package or component

dtb-apple
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-freescale
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dtb-sprd
Operating systems & Components / Operating system package or component

dtb-apm
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-renesas
Operating systems & Components / Operating system package or component

dtb-lg
Operating systems & Components / Operating system package or component

dtb-amd
Operating systems & Components / Operating system package or component

dtb-socionext
Operating systems & Components / Operating system package or component

dtb-altera
Operating systems & Components / Operating system package or component

dtb-exynos
Operating systems & Components / Operating system package or component

dtb-nvidia
Operating systems & Components / Operating system package or component

dtb-allwinner
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-arm
Operating systems & Components / Operating system package or component

dtb-mediatek
Operating systems & Components / Operating system package or component

kernel-64kb-devel-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-marvell
Operating systems & Components / Operating system package or component

dtb-amlogic
Operating systems & Components / Operating system package or component

kernel-64kb-extra-debuginfo
Operating systems & Components / Operating system package or component

dtb-amazon
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-extra
Operating systems & Components / Operating system package or component

dtb-rockchip
Operating systems & Components / Operating system package or component

dtb-cavium
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-optional
Operating systems & Components / Operating system package or component

dtb-xilinx
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-debuginfo
Operating systems & Components / Operating system package or component

dlm-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-aarch64
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debugsource
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debuginfo
Operating systems & Components / Operating system package or component

kernel-zfcpdump
Operating systems & Components / Operating system package or component

kernel-kvmsmall
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-livepatch-SLE15-SP4_Update_44-debugsource
Operating systems & Components / Operating system package or component

kernel-default-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_176-default
Operating systems & Components / Operating system package or component

kernel-default
Operating systems & Components / Operating system package or component

kernel-default-optional
Operating systems & Components / Operating system package or component

dlm-kmp-default
Operating systems & Components / Operating system package or component

ocfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

cluster-md-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-syms
Operating systems & Components / Operating system package or component

kernel-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-extra
Operating systems & Components / Operating system package or component

ocfs2-kmp-default
Operating systems & Components / Operating system package or component

kernel-obs-qa
Operating systems & Components / Operating system package or component

kernel-default-devel
Operating systems & Components / Operating system package or component

dlm-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-build
Operating systems & Components / Operating system package or component

reiserfs-kmp-default
Operating systems & Components / Operating system package or component

kselftests-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-obs-build-debugsource
Operating systems & Components / Operating system package or component

gfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-default
Operating systems & Components / Operating system package or component

kernel-default-optional-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-livepatch
Operating systems & Components / Operating system package or component

kernel-default-debugsource
Operating systems & Components / Operating system package or component

cluster-md-kmp-default
Operating systems & Components / Operating system package or component

kselftests-kmp-default
Operating systems & Components / Operating system package or component

reiserfs-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debugsource
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel
Operating systems & Components / Operating system package or component

kernel-default-base
Operating systems & Components / Operating system package or component

kernel-default-base-rebuild
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-source-vanilla
Operating systems & Components / Operating system package or component

kernel-devel
Operating systems & Components / Operating system package or component

kernel-macros
Operating systems & Components / Operating system package or component

kernel-source
Operating systems & Components / Operating system package or component

kernel-docs-html
Operating systems & Components / Operating system package or component

kernel-docs
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 17 vulnerabilities.

1) Improper locking

EUVDB-ID: #VU111576

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-50116

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the gsm_queue(), gsmld_output(), gsm_stuff_frame(), gsm_data_alloc(), gsm_is_flow_ctrl_msg(), __gsm_data_queue(), gsm_dlci_modem_output(), gsm_control_message(), gsm_control_wait(), gsm_dlci_close(), gsm_dlci_open(), gsm1_receive(), gsm_cleanup_mux(), gsm_activate_mux(), gsm_alloc_mux() and gsmld_open() functions in drivers/tty/n_gsm.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Use-after-free

EUVDB-ID: #VU102056

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2024-53177

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the SMB2_query_info_free(), invalidate_all_cached_dirs(), smb2_cached_lease_break(), cached_dir_lease_break() and cfids_laundromat_worker() functions in fs/smb/client/cached_dir.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Infinite loop

EUVDB-ID: #VU114545

Risk: Low

CVSSv4.0: 5.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2024-58239

CWE-ID: CWE-835 - Loop with Unreachable Exit Condition ('Infinite Loop')

Exploit availability: Yes

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the tls_sw_recvmsg() function in net/tls/tls_sw.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Use-after-free

EUVDB-ID: #VU112282

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38180

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the lec_itf_walk(), lec_seq_start() and lec_seq_stop() functions in net/atm/lec.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Use-after-free

EUVDB-ID: #VU112743

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38323

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the DEFINE_MUTEX(), lec_vcc_attach(), lecd_attach() and lane_ioctl() functions in net/atm/lec.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Race condition

EUVDB-ID: #VU113313

Risk: High

CVSSv4.0: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber]

CVE-ID: CVE-2025-38352

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition within the run_posix_cpu_timers() function in kernel/time/posix-cpu-timers.c. A local user can escalate privileges on the system.

Note, the vulnerability is being actively exploited in the wild against Android devices.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

Yes. This vulnerability is being exploited in the wild.

7) NULL pointer dereference

EUVDB-ID: #VU113260

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38460

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the DEFINE_MUTEX(), to_atmarpd(), atmarpd_close() and atm_init_atmarp() functions in net/atm/clip.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Improper privilege management

EUVDB-ID: #VU113806

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38498

CWE-ID: CWE-269 - Improper Privilege Management

Exploit availability: No

Description

The vulnerability allows a local user to read and manipulate data.

The vulnerability exists due to improperly imposed permissions within the do_change_type() function in fs/namespace.c. A local user can read and manipulate data.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Input validation error

EUVDB-ID: #VU113807

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38499

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the clone_private_mount() function in fs/namespace.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

10) Memory leak

EUVDB-ID: #VU114130

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38546

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the atm_init_atmarp() and clip_ioctl() functions in net/atm/clip.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Use-after-free

EUVDB-ID: #VU114242

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38555

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the composite_os_desc_req_prepare() function in drivers/usb/gadget/composite.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Input validation error

EUVDB-ID: #VU114279

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38560

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the early_set_pages_state() function in arch/x86/kernel/sev.c, within the setup_cpuid_table() and pvalidate_pages() functions in arch/x86/kernel/sev-shared.c, within the get_cpuflags() function in arch/x86/boot/cpuflags.c, within the __page_state_change() function in arch/x86/boot/compressed/sev.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Memory leak

EUVDB-ID: #VU114234

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38563

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the perf_mmap_pfn_mkwrite() function in kernel/events/core.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Use of uninitialized resource

EUVDB-ID: #VU114282

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38608

CWE-ID: CWE-908 - Use of Uninitialized Resource

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the sk_psock_msg_verdict() function in net/tls/tls_sw.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Improper locking

EUVDB-ID: #VU114533

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38617

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the packet_set_ring() function in net/packet/af_packet.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Use-after-free

EUVDB-ID: #VU114500

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38618

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the __vsock_bind_connectible() function in net/vmw_vsock/af_vsock.c. A local user can escalate privileges on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Use of uninitialized resource

EUVDB-ID: #VU114540

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38644

CWE-ID: CWE-908 - Use of Uninitialized Resource

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to use of uninitialized resource within the ieee80211_tdls_oper() function in net/mac80211/tdls.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Manager Server 4.3: LTS

SUSE Manager Retail Branch Server 4.3: LTS

SUSE Manager Proxy 4.3: LTS

SUSE Linux Enterprise Server 15 SP4: LTSS

SUSE Linux Enterprise High Performance Computing LTSS 15: SP4

SUSE Linux Enterprise High Performance Computing ESPOS 15: SP4

SUSE Linux Enterprise Micro for Rancher: 5.3 - 5.4

SUSE Linux Enterprise High Availability Extension 15: SP4

SUSE Linux Enterprise Micro: 5.3 - 5.4

SUSE Linux Enterprise Live Patching: 15-SP4

SUSE Linux Enterprise Server for SAP Applications 15: SP4

SUSE Linux Enterprise Server 15: SP4

SUSE Linux Enterprise Real Time 15: SP4

SUSE Linux Enterprise High Performance Computing 15: SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

openSUSE Leap: 15.4

kernel-64kb: before 5.14.21-150400.24.176.1

kernel-64kb-debugsource: before 5.14.21-150400.24.176.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.176.1

dtb-hisilicon: before 5.14.21-150400.24.176.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-devel: before 5.14.21-150400.24.176.1

dtb-broadcom: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-qcom: before 5.14.21-150400.24.176.1

dtb-apple: before 5.14.21-150400.24.176.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-freescale: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

dtb-sprd: before 5.14.21-150400.24.176.1

dtb-apm: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-renesas: before 5.14.21-150400.24.176.1

dtb-lg: before 5.14.21-150400.24.176.1

dtb-amd: before 5.14.21-150400.24.176.1

dtb-socionext: before 5.14.21-150400.24.176.1

dtb-altera: before 5.14.21-150400.24.176.1

dtb-exynos: before 5.14.21-150400.24.176.1

dtb-nvidia: before 5.14.21-150400.24.176.1

dtb-allwinner: before 5.14.21-150400.24.176.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-arm: before 5.14.21-150400.24.176.1

dtb-mediatek: before 5.14.21-150400.24.176.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-marvell: before 5.14.21-150400.24.176.1

dtb-amlogic: before 5.14.21-150400.24.176.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.176.1

dtb-amazon: before 5.14.21-150400.24.176.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-extra: before 5.14.21-150400.24.176.1

dtb-rockchip: before 5.14.21-150400.24.176.1

dtb-cavium: before 5.14.21-150400.24.176.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-optional: before 5.14.21-150400.24.176.1

dtb-xilinx: before 5.14.21-150400.24.176.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.176.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.176.1

dlm-kmp-64kb: before 5.14.21-150400.24.176.1

dtb-aarch64: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.176.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.176.1

kernel-zfcpdump: before 5.14.21-150400.24.176.1

kernel-kvmsmall: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default-debuginfo: before 1-150400.9.3.1

kernel-livepatch-SLE15-SP4_Update_44-debugsource: before 1-150400.9.3.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.176.1

kernel-livepatch-5_14_21-150400_24_176-default: before 1-150400.9.3.1

kernel-default: before 5.14.21-150400.24.176.1

kernel-default-optional: before 5.14.21-150400.24.176.1

dlm-kmp-default: before 5.14.21-150400.24.176.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-syms: before 5.14.21-150400.24.176.1

kernel-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-extra: before 5.14.21-150400.24.176.1

ocfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-obs-qa: before 5.14.21-150400.24.176.1

kernel-default-devel: before 5.14.21-150400.24.176.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build: before 5.14.21-150400.24.176.1

reiserfs-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.176.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

gfs2-kmp-default: before 5.14.21-150400.24.176.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.176.1

kernel-default-livepatch: before 5.14.21-150400.24.176.1

kernel-default-debugsource: before 5.14.21-150400.24.176.1

cluster-md-kmp-default: before 5.14.21-150400.24.176.1

kselftests-kmp-default: before 5.14.21-150400.24.176.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.176.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.176.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.176.1

kernel-default-base: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-default-base-rebuild: before 5.14.21-150400.24.176.1.150400.24.90.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.176.1

kernel-source-vanilla: before 5.14.21-150400.24.176.1

kernel-devel: before 5.14.21-150400.24.176.1

kernel-macros: before 5.14.21-150400.24.176.1

kernel-source: before 5.14.21-150400.24.176.1

kernel-docs-html: before 5.14.21-150400.24.176.1

kernel-docs: before 5.14.21-150400.24.176.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2025/suse-su-202503314-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###