Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update for Mageia 10 corrects the nut-scanner startup issue and refreshes nut packages to the latest version, improving functionality and maintenance.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0061.html Type: bugfix Affected Mageia releases: 10 Description: nut-scanner failed to start. This update fixes the issue and also updates the nut packages to the latest maintained release. References: - https://bugs.mageia.org/show_bug.cgi?id=35938 SRPMS: - 10/core/nut-2.8.5-1.mga10 . A security update addresses nut issues in Mageia 10, ensuring system stability and functionality improvements.. Mageia update, nut package, security patch. . LinuxSecurity.com Team
An update for Mageia 10 fixes a launch issue with warpinator caused by a grpcio module version stamp mismatch, aligning it with the distro's provided version.. Publication date: 23 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0060.html Type: bugfix Affected Mageia releases: 10 Description: warpinator uses the grpcio module, but with a stamp of the used module version. The stamp was not in accordance with the version of the provided module in the distro, preventing launch. This update fixes that. References: - https://bugs.mageia.org/show_bug.cgi?id=35891 SRPMS: - 10/core/warpinator-2.0.4-1.mga10 . This security advisory addresses an issue with warpinator in Mageia 10, ensuring it launches correctly after update.. Mageia Security Update, Warpinator Bugfix, Linux Software Advisory, Mageia Vulnerability. . Severity: moderate. LinuxSecurity.com Team
openSUSE has released a security update for trivy addressing three vulnerabilities, which includes fixes for privilege escalation and credential forwarding, available for openSUSE Leap 16.0.. openSUSE security update: security update for trivy ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21395-1 Rating: important References: * bsc#1266495 * bsc#1271658 * bsc#1271670 Cross-References: * CVE-2026-39821 * CVE-2026-50151 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for trivy fixes the following issues - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266495). - CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271658). - CVE-2026-56852: trivy: infinite loop on truncated/invalid UTF-8 input (bsc#1271670). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1305=1 Package List: - openSUSE Leap 16.0: trivy-0.72.0-160000.2.1 References: * https://www.suse.com/security/cve/CVE-2026-39821.html *https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-56852.html . This OpenSUSE advisory details important updates fixing multiple issues in Trivy, improving security and functionality.. OpenSUSE, Trivy, privilege escalation, credential forwarding, security update. . Severity: Important. LinuxSecurity.com Team
An important update for cifs-utils on Rocky Linux 8 addresses security vulnerabilities, including a local privilege escalation issue, while also providing bug fixes and enhancements.. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39575", "synopsis": "Important: cifs-utils security, bug fix, and enhancement update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for cifs-utils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The SMB/CIFS protocol is a standard file sharing protocol widely deployed on Microsoft Windows machines. The cifs-utils packages contain tools for mounting shares on Linux using the SMB/CIFS protocol. The tools in this package work in conjunction with support in the kernel to allow one to mount a SMB/CIFS share onto a client and use it as if it were a standard Linux file system.\n\nSecurity Fix(es):\n\n* cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall (CVE-2026-12505)\n\nBug Fix(es) and Enhancement(s):\n\n* add sssd method for mapping SID to UID/GID in man page of mount.cifs [rhel-8.10.z] (JIRA:Rocky Linux-41059)\n\n* Update the mount.cifs man page to match the 3*echo_interval reconnection timeout (JIRA:Rocky Linux-80397)\n\n* cifs-utils: regression with kerberos mount [rhel-8.10.z] (JIRA:Rocky Linux-192933)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2489805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2489805", "description": ""}], "cves": [{"name": "CVE-2026-12505", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12505", "cvss3ScoringVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.8", "cwe": "CWE-250"}], "references": [], "publishedAt": "2026-07-23T12:00:46.971123Z", "rpms": {"Rocky Linux 8": {"nvras": ["cifs-utils-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-0:7.0-5.el8_10.src.rpm", "cifs-utils-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-debuginfo-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-debuginfo-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.i686.rpm", "cifs-utils-debugsource-0:7.0-5.el8_10.x86_64.rpm", "cifs-utils-devel-0:7.0-5.el8_10.aarch64.rpm", "cifs-utils-devel-0:7.0-5.el8_10.i686.rpm", "cifs-utils-devel-0:7.0-5.el8_10.x86_64.rpm", "pam_cifscreds-0:7.0-5.el8_10.aarch64.rpm", "pam_cifscreds-0:7.0-5.el8_10.x86_64.rpm", "pam_cifscreds-debuginfo-0:7.0-5.el8_10.aarch64.rpm", "pam_cifscreds-debuginfo-0:7.0-5.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important update for cifs-utils addresses a local privilege escalation security issue and enhances functionality on Rocky Linux.. Rocky Linux Cifs-Utils Security Update Privilege Escalation. . Severity: Important. LinuxSecurity.com Team
openSUSE released a security update for gawk to address three vulnerabilities, including use-after-free and buffer overflow issues, which may lead to crashes or memory exhaustion.. openSUSE security update: security update for gawk ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21393-1 Rating: moderate References: * bsc#1271351 * bsc#1271352 * bsc#1271354 Cross-References: * CVE-2026-40467 * CVE-2026-40468 * CVE-2026-40553 CVSS scores: * CVE-2026-40467 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40467 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40468 ( SUSE ): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40468 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L * CVE-2026-40553 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-40553 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 3 vulnerabilities and has 3 bug fixes can now be installed. Description: This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free vulnerability within the do_getline_redir() routine could lead to a program crash (bsc#1271351). - CVE-2026-40468: use-after-free vulnerability in gawk's "io.c" file could permit heap metadata manipulation and host memory exhaustion (bsc#1271352). - CVE-2026-40553: buffer overflow in the ftype() routine of the readdir extension could trigger a program crash (bsc#1271354). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1303=1 Package List: - openSUSE Leap 16.0: gawk-5.3.2-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-40467.html * https://www.suse.com/security/cve/CVE-2026-40468.html * https://www.suse.com/security/cve/CVE-2026-40553.html . An openSUSE security update addresses three vulnerabilities in gawk, including key fixes for buffer overflows and memory issues.. openSUSE security update,gawk vulnerabilities,buffer overflow patch,use-after-free fix. . Severity: moderate. LinuxSecurity.com Team
openSUSE has released a security update for ImageMagick addressing 11 vulnerabilities, including policy bypasses and memory issues, affecting openSUSE Leap 16.0. Patch installation is recommended.. openSUSE security update: security update for imagemagick ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21391-1 Rating: moderate References: * bsc#1268640 * bsc#1270006 * bsc#1270081 * bsc#1271100 * bsc#1271293 * bsc#1271294 * bsc#1271311 * bsc#1271312 * bsc#1271313 * bsc#1271314 * bsc#1271315 * bsc#1271316 Cross-References: * CVE-2026-55628 * CVE-2026-56362 * CVE-2026-56366 * CVE-2026-56372 * CVE-2026-56373 * CVE-2026-56377 * CVE-2026-61465 * CVE-2026-61857 * CVE-2026-61858 * CVE-2026-61861 * CVE-2026-61870 CVSS scores: * CVE-2026-55628 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55628 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56362 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56362 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56366 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56366 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56372 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56372 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56373 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56373 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56377 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56377 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61465 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-61465 ( SUSE ): 4.8CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61857 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61857 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61858 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61858 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61861 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61861 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-61870 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-61870 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 11 vulnerabilities and has 12 bug fixes can now be installed. Description: This update for ImageMagick fixes the following issues - CVE-2026-55628: Policy Bypass in concatenate operation due to missing checks (bsc#1270081). - CVE-2026-56362: Heap-buffer-overflow read in GetPixelIndex due to metadata-cache desynchronization in OpenPixelCache (bsc#1271100). - CVE-2026-56366: META reader memory leak in the APP1JPEG input path (bsc#1271316). - CVE-2026-56372: heap buffer overflow read in magnify operation via unrecognized magnify:method value (bsc#1271314). - CVE-2026-56373: possible use-after-free write in PDB decoder (bsc#1268640 bsc#1271315). - CVE-2026-56377: Policy Bypass can create or truncate files (bsc#1270006). - CVE-2026-61465: Policy Bypass possible with matrix-backed operations (bsc#1271313). - CVE-2026-61857: Heap-use-after-free via XMP profile could result in a crash (bsc#1271312). - CVE-2026-61858: Policy Bypass in APNG encoder and delegates due to a missing check (bsc#1271311). - CVE-2026-61861: Use-After-Free in FormatMagickCaption when memory allocation fails (bsc#1271294). - CVE-2026-61870: Memory leak in VIFFencoder when allocation fails (bsc#1271293). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1300=1 Package List: - openSUSE Leap 16.0: ImageMagick-7.1.2.0-160000.12.1 ImageMagick-config-7-SUSE-7.1.2.0-160000.12.1 ImageMagick-config-7-upstream-limited-7.1.2.0-160000.12.1 ImageMagick-config-7-upstream-open-7.1.2.0-160000.12.1 ImageMagick-config-7-upstream-secure-7.1.2.0-160000.12.1 ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.12.1 ImageMagick-devel-7.1.2.0-160000.12.1 ImageMagick-doc-7.1.2.0-160000.12.1 ImageMagick-extra-7.1.2.0-160000.12.1 libMagick++-7_Q16HDRI5-7.1.2.0-160000.12.1 libMagick++-devel-7.1.2.0-160000.12.1 libMagickCore-7_Q16HDRI10-7.1.2.0-160000.12.1 libMagickWand-7_Q16HDRI10-7.1.2.0-160000.12.1 perl-PerlMagick-7.1.2.0-160000.12.1 References: * https://www.suse.com/security/cve/CVE-2026-55628.html * https://www.suse.com/security/cve/CVE-2026-56362.html * https://www.suse.com/security/cve/CVE-2026-56366.html * https://www.suse.com/security/cve/CVE-2026-56372.html * https://www.suse.com/security/cve/CVE-2026-56373.html * https://www.suse.com/security/cve/CVE-2026-56377.html * https://www.suse.com/security/cve/CVE-2026-61465.html * https://www.suse.com/security/cve/CVE-2026-61857.html * https://www.suse.com/security/cve/CVE-2026-61858.html * https://www.suse.com/security/cve/CVE-2026-61861.html * https://www.suse.com/security/cve/CVE-2026-61870.html . ImageMagick update for openSUSE addresses 11 issues including heap overflows and policy bypass risks with patch instructions.. imagemagick update, openSUSE security, bug fixes. . Severity: moderate. LinuxSecurity.com Team
openSUSE released a security update addressing 255 vulnerabilities in its kernel, improving system security and stability across several affected products, prompting users to apply the latest patches.. openSUSE security update: security update for the linux kernel ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21388-1 Rating: important References: * bsc#1149651 * bsc#1204315 * bsc#1236743 * bsc#1255029 * bsc#1257506 * bsc#1258538 * bsc#1259800 * bsc#1260565 * bsc#1261250 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262430 * bsc#1262618 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262765 * bsc#1262798 * bsc#1263057 * bsc#1263072 * bsc#1263133 * bsc#1263137 * bsc#1263143 * bsc#1263169 * bsc#1263178 * bsc#1263319 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263796 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264007 * bsc#1264010 * bsc#1264012 * bsc#1264015 * bsc#1264045 * bsc#1264056 * bsc#1264067 * bsc#1264084 * bsc#1264145 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264250 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264270 * bsc#1264286 * bsc#1264294 * bsc#1264295 * bsc#1264302 * bsc#1264304 * bsc#1264320 * bsc#1264328 * bsc#1264333 * bsc#1264337 * bsc#1264372 * bsc#1264386 * bsc#1264429 * bsc#1264449 * bsc#1264532 * bsc#1264544 * bsc#1264545 * bsc#1264548 * bsc#1264549 * bsc#1264556 * bsc#1264561 * bsc#1264580 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264614 * bsc#1264624 * bsc#1264643 * bsc#1264734 * bsc#1264740 * bsc#1264741 * bsc#1264744 * bsc#1264763 * bsc#1264789 * bsc#1264790 * bsc#1264794 * bsc#1264852 * bsc#1264974 * bsc#1264978 * bsc#1264997 *bsc#1265000 * bsc#1265005 * bsc#1265020 * bsc#1265023 * bsc#1265073 * bsc#1265079 * bsc#1265082 * bsc#1265084 * bsc#1265091 * bsc#1265097 * bsc#1265103 * bsc#1265112 * bsc#1265113 * bsc#1265123 * bsc#1265128 * bsc#1265129 * bsc#1265142 * bsc#1265143 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266214 * bsc#1266283 * bsc#1266284 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266398 * bsc#1266452 * bsc#1266458 * bsc#1266686 * bsc#1266693 * bsc#1266697 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266718 * bsc#1266722 * bsc#1266726 * bsc#1266734 * bsc#1266740 * bsc#1266750 * bsc#1266754 * bsc#1266761 * bsc#1266773 * bsc#1266805 * bsc#1266830 * bsc#1266838 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266883 * bsc#1266892 * bsc#1266893 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266925 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267218 * bsc#1267228 * bsc#1267238 * bsc#1267251 * bsc#1267360 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267387 * bsc#1267419 * bsc#1267427 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267493 * bsc#1267505 * bsc#1267548 * bsc#1267582 * bsc#1267591 * bsc#1267600 * bsc#1267618 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267732 * bsc#1267744 * bsc#1267816 * bsc#1267824 * bsc#1267825 * bsc#1267937 * bsc#1267966 * bsc#1267992 * bsc#1267993 * bsc#1267994 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268238 * bsc#1268276 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1268989 * bsc#1269022 * bsc#1269031 * bsc#1269033 * bsc#1269036 * bsc#1269087 * bsc#1269103 * bsc#1269135 *bsc#1269136 * bsc#1269137 * bsc#1269151 * bsc#1269159 * bsc#1269164 * bsc#1269188 * bsc#1269193 * bsc#1269199 * bsc#1269230 * bsc#1269234 * bsc#1269252 * bsc#1269262 * bsc#1269288 * bsc#1269310 * bsc#1269389 * bsc#1269392 * bsc#1269397 * bsc#1269398 * bsc#1269416 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269527 * bsc#1269531 * bsc#1269532 * bsc#1269537 * bsc#1269587 * bsc#1269617 * bsc#1269645 * bsc#1269646 * bsc#1269647 * bsc#1269651 * bsc#1269680 * bsc#1269690 * bsc#1269691 * bsc#1269700 * bsc#1269708 * bsc#1269710 * bsc#1269768 * bsc#1269795 * bsc#1269798 * bsc#1269809 * bsc#1269814 * bsc#1269821 * bsc#1269904 * bsc#1269982 * bsc#1269989 * bsc#1269992 * bsc#1270000 * bsc#1270022 * bsc#1270042 * bsc#1270059 * bsc#1270226 * bsc#1271366 Cross-References: * CVE-2025-10263 * CVE-2025-39894 * CVE-2025-40341 * CVE-2026-23248 * CVE-2026-23394 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31438 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31479 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31580 * CVE-2026-31596 * CVE-2026-31646 * CVE-2026-31647 * CVE-2026-31663 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31743 * CVE-2026-31752 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43016 * CVE-2026-43022 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43053 * CVE-2026-43057 * CVE-2026-43074 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43090 * CVE-2026-43092 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 *CVE-2026-43119 * CVE-2026-43124 * CVE-2026-43128 * CVE-2026-43130 * CVE-2026-43132 * CVE-2026-43139 * CVE-2026-43145 * CVE-2026-43157 * CVE-2026-43158 * CVE-2026-43161 * CVE-2026-43167 * CVE-2026-43171 * CVE-2026-43175 * CVE-2026-43187 * CVE-2026-43191 * CVE-2026-43194 * CVE-2026-43198 * CVE-2026-43199 * CVE-2026-43205 * CVE-2026-43213 * CVE-2026-43226 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43240 * CVE-2026-43248 * CVE-2026-43260 * CVE-2026-43283 * CVE-2026-43284 * CVE-2026-43298 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43337 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43351 * CVE-2026-43373 * CVE-2026-43374 * CVE-2026-43383 * CVE-2026-43384 * CVE-2026-43386 * CVE-2026-43403 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43415 * CVE-2026-43449 * CVE-2026-43450 * CVE-2026-43452 * CVE-2026-43456 * CVE-2026-43457 * CVE-2026-43458 * CVE-2026-43465 * CVE-2026-43466 * CVE-2026-43468 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43471 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45837 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45857 * CVE-2026-45858 * CVE-2026-45861 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45884 * CVE-2026-45888 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45899 * CVE-2026-45901 * CVE-2026-45912 * CVE-2026-45920 * CVE-2026-45922 * CVE-2026-45933 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45985 * CVE-2026-45997 * CVE-2026-45999 * CVE-2026-46005 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46046 * CVE-2026-46050 * CVE-2026-46051 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46078 * CVE-2026-46079 * CVE-2026-46091 * CVE-2026-46093 * CVE-2026-46099 *CVE-2026-46101 * CVE-2026-46111 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46161 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46178 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46242 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46314 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46322 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52919 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52933 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52975 * CVE-2026-52980 * CVE-2026-52993 * CVE-2026-53015 * CVE-2026-53021 * CVE-2026-53036 * CVE-2026-53039 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53049 * CVE-2026-53050 * CVE-2026-53053 * CVE-2026-53060 * CVE-2026-53075 * CVE-2026-53078 * CVE-2026-53081 * CVE-2026-53086 * CVE-2026-53090 * CVE-2026-53103 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53139 * CVE-2026-53156 * CVE-2026-53167 * CVE-2026-53168 * CVE-2026-53176 * CVE-2026-53178 * CVE-2026-53194 * CVE-2026-53215 * CVE-2026-53216 * CVE-2026-53217 * CVE-2026-53229 * CVE-2026-53249 * CVE-2026-53258 * CVE-2026-53262 * CVE-2026-53263 * CVE-2026-53266 * CVE-2026-53272 * CVE-2026-53274 * CVE-2026-53281 * CVE-2026-53285 * CVE-2026-53286 * CVE-2026-53287 * CVE-2026-53306 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-39894 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39894 ( SUSE ): 6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23248 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23394 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31479 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31646 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31646 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( SUSE ): 2 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N *CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31743 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43016 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43057 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( SUSE ): 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43090 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43130 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43145 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43157 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43161 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43175 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43191 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43198 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43226 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43240 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43260 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43283 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43298 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43298 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43336 ( SUSE ): 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43351 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43374 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43383 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43384 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-43384 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43415 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43449 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43452 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43457 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43458 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43465 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43468 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45837 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45837 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45857 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45857 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45858 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45858 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45861 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( SUSE ): 6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45884 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45884 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45888 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45888 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45899 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45899 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45901 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45901 ( SUSE ): 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45920 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45920 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45922 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45922 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45997 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45999 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46046 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46051 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46093 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46099 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46161 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46178 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46178 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46319 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46322 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46322 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52919 ( SUSE ):7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52919 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52943 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52980 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53036 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53039 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53049 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53050 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53050 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53060 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53060 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53078 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53081 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53086 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53086 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53090 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53090 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53103 ( SUSE ): 4.8 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53103 ( SUSE ): 5.9 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53156 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53167 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53167 ( SUSE ): 6.8CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53178 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53216 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53217 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53217 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53229 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53249 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53258 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53262 ( SUSE ): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53262 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53272 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53272 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53285 ( SUSE ): 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53306 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 255 vulnerabilities and has 285 bug fixes can now be installed. Description: The SUSE Linux Enterprise 16.0 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-10263: arm64: cputype: Add C1-Premium definitions (bsc#1266290). - CVE-2025-39894: netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm (bsc#1262430). - CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). - CVE-2026-23248: perf: Make perf_pmu_unregister() useable (bsc#1259800). - CVE-2026-23394: Revert: "af_unix: Remove lock dance in unix_peek_fds()." (bsc#1260565). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31414: netfilter: nf_conntrack_expect: use expect-> helper (bsc#1262085). - CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). - CVE-2026-31438: netfs: Fix kernel BUG in netfs_limit_iter() for ITER_KVEC iterators (bsc#1267824). - CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). - CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inlinesize (bsc#1262620). - CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). - CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). - CVE-2026-31479: drm/xe: always keep track of remap prev/next (bsc#1262765). - CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). - CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). - CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). - CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). - CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). - CVE-2026-31646: net: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool() (bsc#1263796). - CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). - CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). - CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). - CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). - CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). - CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). - CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). - CVE-2026-31743: nvmem: zynqmp_nvmem: Fix buffer size in DMA and memcpy (bsc#1264067). - CVE-2026-31752: bridge: br_nd_send: validate NDoption lengths (bsc#1264045). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). - CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). - CVE-2026-43016: bpf: sockmap: Fix use-after-free of sk-> sk_socket in sk_psock_verdict_data_ready() (bsc#1264007). - CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). - CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). - CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). - CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). - CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). - CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). - CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). - CVE-2026-43057: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback (bsc#1264056). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). - CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). - CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). - CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43090: xfrm: fix refcount leak in xfrm_migrate_policy_find (bsc#1264250). - CVE-2026-43092: xsk: validate MTU against usable frame size on bind (bsc#1264270). - CVE-2026-43093: xsk: tighten UMEM headroom validationto account for tailroom and min frame (bsc#1264254). - CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). - CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). - CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). - CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev-> req_status (bsc#1264561). - CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545). - CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). - CVE-2026-43130: iommu/vt-d: Flush dev-IOTLB only when PCIe device is accessible in scalable mode (bsc#1264532). - CVE-2026-43132: dm-verity: correctly handle dm_bufio_client_create() failure (bsc#1264614). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43145: remoteproc: imx_rproc: Fix invalid loaded resource table detection (bsc#1265091). - CVE-2026-43157: octeontx2-af: CGX: fix bitmap leaks (bsc#1264624). - CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). - CVE-2026-43161: iommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode (bsc#1264333). - CVE-2026-43167: xfrm: always flush state and policy upon NETDEV_UNREGISTER event (bsc#1264580). - CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). - CVE-2026-43175: clk: rs9: Reserve 8 struct clk_hw slots for for 9FGV0841 (bsc#1264372). - CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). - CVE-2026-43191: drm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35 (bsc#1264548). - CVE-2026-43194: net: consume xmit errors of GSO frames (bsc#1264304). - CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). - CVE-2026-43199: net/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query (bsc#1264556). - CVE-2026-43205:dpaa2-switch: validate num_ifs to prevent out-of-bounds write (bsc#1264328). - CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). - CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). - CVE-2026-43240: ima: verify the previous kernel's IMA buffer lies in addressable RAM (bsc#1264386). - CVE-2026-43248: vhost: move vdpa group bound check to vhost_vdpa (bsc#1264302). - CVE-2026-43260: bnxt_en: Fix RSS context delete logic (bsc#1264429). - CVE-2026-43283: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle (bsc#1264295). - CVE-2026-43298: drm/amdgpu: Skip vcn poison irq release on VF (bsc#1264852). - CVE-2026-43303: mm/page_alloc: clear page-> private in free_pages_prepare() (bsc#1264974). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43337: drm/amd/display: Fix NULL pointer dereference in dcn401_init_hw() (bsc#1265112). - CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). - CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). - CVE-2026-43351: KVM: arm64: gic: Set vgic_model before initing private IRQs (bsc#1265082). - CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079). - CVE-2026-43374: net: nexthop: fix percpu use-after-free in remove_nh_grp_entry (bsc#1265084). - CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744). - CVE-2026-43384: net/tcp-ao: Fix MAC comparison to be constant-time (bsc#1265097). - CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). - CVE-2026-43403: nsfs: tighten permission checks for ns iteration ioctls (bsc#1265129). - CVE-2026-43405: libceph: Use u32 for non-negative values inceph_monmap_decode() (bsc#1264741). - CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). - CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). - CVE-2026-43415: scsi: ufs: core: Fix SError in ufshcd_rtc_work() during UFS suspend (bsc#1265123). - CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023). - CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794). - CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43457: mctp: i2c: fix skb memory leak in receive path (bsc#1265000). - CVE-2026-43458: serial: caif: hold tty-> link reference in ldisc_open and ser_release (bsc#1265005). - CVE-2026-43465: net/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ (bsc#1264997). - CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790). - CVE-2026-43468: net/mlx5: Fix deadlock between devlink lock and esw-> wq (bsc#1264978). - CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). - CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). - CVE-2026-43471: scsi: ufs: core: Fix possible NULL pointer dereference in ufshcd_add_command_trace() (bsc#1264789). - CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45837: Require (reasonably) normal mappings for MADV_DOFORK (bsc#1266398). - CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). - CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies(bsc#1266397). - CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). - CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). - CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458). - CVE-2026-45858: ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 (bsc#1266773). - CVE-2026-45861: gfs2: Fix slab-use-after-free in qd_put (bsc#1266754). - CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). - CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). - CVE-2026-45884: apparmor: avoid per-cpu hold underflow in aa_get_buffer (bsc#1266718). - CVE-2026-45888: md/raid1: fix memory leak in raid1_run() (bsc#1266761). - CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). - CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). - CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883). - CVE-2026-45901: netfilter: nf_tables: revert commit_mutex usage in reset path (bsc#1266892). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893). - CVE-2026-45922: RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler (bsc#1266805). - CVE-2026-45933: bpf: Preserve id of register in sync_linked_regs() (bsc#1266693). - CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). - CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). - CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). - CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found(bsc#1266922). - CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). - CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). - CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740). - CVE-2026-45999: erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() (bsc#1266750). - CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). - CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). - CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). - CVE-2026-46046: ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() (bsc#1266726). - CVE-2026-46050: md/raid10: fix deadlock with check operation and nowait requests (bsc#1266686). - CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360). - CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). - CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). - CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). - CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). - CVE-2026-46093: mm/vmalloc: take vmap_purge_lock in shrinker (bsc#1267548). - CVE-2026-46099: net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels (bsc#1266722). - CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). - CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF increate_big_sync (bsc#1267626). - CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). - CVE-2026-46120: ip6_gre: Use cached t-> net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). - CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). - CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838). - CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). - CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493). - CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). - CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618). - CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46289: lib/scatterlist: fix lengthcalculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46291: printk: add print_hex_dump_devel() (bsc#1267937). - CVE-2026-46314: drm/v3d: Reject empty multisync extension to prevent infinite loop (bsc#1267992). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52919: batman-adv: fix tp_meter counter underflow during shutdown (bsc#1269031). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52975: bonding: 3ad: implement proper RCU rules for port-> aggregator (bsc#1269234). - CVE-2026-52980: sched/fair: Clear rel_deadline when initializing forked entities (bsc#1269252). - CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). - CVE-2026-53015: erofs: unify lcn as u64 for 32-bit platforms (bsc#1269087). - CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151). - CVE-2026-53036: bpf, arm64: Rejectout-of-range B.cond targets (bsc#1269389). - CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53049: gfs2: add some missing log locking (bsc#1269646). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164). - CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). - CVE-2026-53078: bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops (bsc#1269700). - CVE-2026-53081: bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars (bsc#1269708). - CVE-2026-53086: net: bcmgenet: move DESC_INDEX flow to ring 0 (bsc#1269537). - CVE-2026-53090: bpf: Fix ld_{abs,ind} failure path analysis in subprogs (bsc#1269532). - CVE-2026-53103: wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync (bsc#1269416). - CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes > = 4G (bsc#1269821). - CVE-2026-53139: drm/v3d: Skip CSD when it has zeroed workgroups (bsc#1269262). - CVE-2026-53156: nvmem: core: fix use-after-free bugs in error paths (bsc#1269288). - CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768). - CVE-2026-53168: fuse: reject fuse_notify() pagecache ops on directories (bsc#1269645). - CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710). - CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795). - CVE-2026-53215: net: mvpp2: refill RX buffers before XDP or skb use (bsc#1269680). -CVE-2026-53216: net: mvpp2: limit XDP frame size to the RX buffer (bsc#1269587). - CVE-2026-53217: net: mvpp2: sync RX data at the hardware packet offset (bsc#1269989). - CVE-2026-53229: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure (bsc#1269691). - CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992). - CVE-2026-53258: wifi: fix leak if split 6 GHz scanning fails (bsc#1269230). - CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000). - CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). - CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). - CVE-2026-53272: erofs: fix use-after-free on sbi-> sync_decompress (bsc#1269809). - CVE-2026-53274: net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS (bsc#1269651). - CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). - CVE-2026-53285: drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED (bsc#1269527). - CVE-2026-53286: idpf: fix double free and use-after-free in aux device error paths (bsc#1269531). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814). The following non security issues were fixed: - accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). - ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). - ACPI: IPMI: Fix message kref handling on dead device (git-fixes). - ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). - ACPI: resource: Amend kernel-doc style (git-fixes). - agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). - ALSA: aloop: Drop superfluous break (git-fixes). - ALSA: caiaq: fix out-of-bounds read in the TraktorKontrol S4 input parser (git-fixes). - ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). - ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git-fixes). - ALSA: es1938: check snd_ctl_new1() return value (git-fixes). - ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes). - ALSA: gus: check snd_ctl_new1() return value (git-fixes). - ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). - ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). - ALSA: scarlett2: Allow flash writes ending at segment boundary (git-fixes). - ALSA: scarlett2: Return ENOSPC for out-of-bounds flash writes (stable-fixes). - ALSA: seq: Clear variable event pointer on read (git-fixes). - ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). - ALSA: seq: Fix partial userptr event expansion (git-fixes). - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). - ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). - ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). - ALSA: timer: Forcibly close timer instances at closing (git-fixes). - ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). - ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). - ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). - ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). - ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). - ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). - ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). - ALSA: virtio: Validate control metadata from the device (git-fixes). - ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). - arm64: scripts/sorttable: Implement sorting mcount_loc at boot for arm64(bsc#1267600). - ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git-fixes). - ASoC: amd: acp-sdw-sof: Bound DAI link iteration (git-fixes). - ASoC: codecs: aw88261: fix incorrect masks for boost regs (git-fixes). - ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). - ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). - ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git-fixes). - ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). - ASoC: cs35l56: Fix possible uninitialized value in cs35l56_spi_system_reset() (git-fixes). - ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes). - ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). - ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). - ASoC: meson: aiu: Validate written enum values (git-fixes). - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes). - ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). - ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). - ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). - ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git-fixes). - ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). - ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). - ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes). - ASoC: topology: Check PCM and DAI name strings before use (git-fixes). - ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git-fixes). - Bluetooth: 6lowpan: hold L2CAP conn across debugfs control (git-fixes). - Bluetooth: bnep: pin L2CAP connection during netdev registration (git-fixes). - Bluetooth: bpa10x: avoid OOB read of revisionstring in bpa10x_setup() (git-fixes). - Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). - Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git-fixes). - Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() (git-fixes). - Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). - Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). - Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). - Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). - Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git-fixes). - Bluetooth: fix UAF in bt_accept_dequeue() (git-fixes). - Bluetooth: hci: validate codec capability element length (git-fixes). - Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (git-fixes). - Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device (git-fixes). - Bluetooth: hci_uart: clear HCI_UART_SENDING when write_work is canceled (git-fixes). - Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() (git-fixes). - Bluetooth: ISO: exclude RFU bits from ISO_SDU_Length (git-fixes). - Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls (git-fixes). - Bluetooth: ISO: fix malformed ISO_END/CONT handling (git-fixes). - Bluetooth: ISO: Fix not using bc_sid as advertisement SID (stable-fixes). - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes). - Bluetooth: L2CAP: validate option length before reading conf opt value (git-fixes). - Bluetooth: MGMT: Fix adv monitor add failure cleanup (git-fixes). - Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete (git-fixes). - Bluetooth: sco: Fix a race condition in sco_sock_timeout() (git-fixes). - Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - bpf: Free reuseport cBPF prog after RCU grace period (git-fixes). - bus: mhi: ep: Add missingstate_lock protection for mhi_state access (git-fixes). - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). - char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). - crypto/hmac: reject keys shorter than 128 bits in fips mode (bsc#1266284 jsc#PED-15986). - crypto/testmgr: disallow ffdhe2048 in fips mode (bsc#1266284 jsc#PED-15986). - crypto/testmgr: disallow plain ecb() usage in fips mode (bsc#1266284 jsc#PED-15986). - crypto/testmgr: disallow sha224 + sha3-224 in fips mode (bsc#1266284 jsc#PED-15986). - crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). - crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). - crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git-fixes). - crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). - crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). - crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) (git-fixes). - crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) (git-fixes). - crypto: ccp - Do not initialize SNP for SEV ioctls (git-fixes). - crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). - crypto: ccp - Treat zero-length cert chain as query for blob lengths (git-fixes). - crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). - crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). - crypto: drbg - Fix the fips_enabled priority boost (git-fixes). - crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). - crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). - crypto: hisilicon/qm - disable error report before flr (git-fixes). - crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git-fixes). - crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). - crypto: qat - protect service table iterations with service_lock (git-fixes). -crypto: qat - validate RSA CRT component lengths (git-fixes). - crypto: rng - Free default RNG on module exit (git-fixes). - crypto: tegra - Fix dma_free_coherent size error (git-fixes). - crypto: tegra - fix refcount leak in tegra_se_host1x_submit() (git-fixes). - crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm (git-fixes). - dm init: ensure device probing has finished in dm-mod.waitfor= (git-fixes). - dmaengine: dma-axi-dmac: Properly free struct axi_dmac_desc (git-fixes). - dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor (git-fixes). - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). - dmaengine: Fix possible use after free (git-fixes). - dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). - dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). - dmaengine: tegra: Fix burst size calculation (git-fixes). - driver core: reject devices with unregistered buses (git-fixes). - driver core: use READ_ONCE() for dev-> driver in dev_has_sync_state() (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes). - drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). - drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). - drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git-fixes). - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes). - drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). - drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). - drm/amdgpu: restart the CS if some parts of the VM are stillinvalidated (stable-fixes). - drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). - drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes). - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). - drm/amdkfd: always resume_all after suspend_all (git-fixes). - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). - drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes). - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). - drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). - drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). - drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). - drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). - drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git-fixes). - drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git-fixes). - drm/dp: Add eDP 1.5 bit definition (stable-fixes). - drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). - drm/gpuvm: Do not prepare NULL objects (git-fixes). - drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git-fixes). - drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). - drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). - drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). - drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). - drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). - drm/imagination: Count paired job fence as dependency in prepare_job() (git-fixes). - drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). - drm/msm/dp: fix HPD state status bit shift value (git-fixes). - drm/msm/dp: Fix the ISR_* enum values(git-fixes). - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). - drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). - drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes). - drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). - drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). - drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git-fixes). - drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git-fixes). - drm/rockchip: Test for imported buffers with drm_gem_is_imported() (git-fixes). - drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). - drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git-fixes). - drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). - drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). - drm/tidss: Fix missing drm_bridge_add() call (git-fixes). - drm/vc4: fix krealloc() memory leak (git-fixes). - drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). - drm/virtio: Fix driver removal with disabled KMS (git-fixes). - drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). - drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). - fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var (stable-fixes). - fbdev: fix use-after-free in store_modes() (stable-fixes). - fbdev: modedb: fix a possible UAF in fb_find_mode() (stable-fixes). - fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). - firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). - firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). - firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). - firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). - fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). -fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). - fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes). - ftrace: Check against is_kernel_text() instead of kaslr_offset() (bsc#1267600). - ftrace: Do not over-allocate ftrace memory (bsc#1267600). - ftrace: Have ftrace pages output reflect freed pages (bsc#1267600). - ftrace: Test mcount_loc addr before calling ftrace_call_addr() (bsc#1267600). - ftrace: Update the mcount_loc check of skipped entries (bsc#1267600). - gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). - gpio: mxc: fix irq_high handling (git-fixes). - gpio: rockchip: convert bank-> clk to devm_clk_get_enabled() (git-fixes). - gpio: virtuser: Fix uninitialized data bug in gpio_virtuser_direction_do_write() (git-fixes). - gpio: zynq: fix runtime PM leak on remove (git-fixes). - gpiolib: Extract gpiochip_choose_fwnode() for wider use (stable-fixes). - gpiolib: Remove redundant assignment of return variable (stable-fixes). - gpu: host1x: Allow entries in BO caches to be freed (git-fixes). - gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path (git-fixes). - gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). - HID: core: Add printk_ratelimited variants to hid_warn() etc (stable-fixes). - HID: hid-goodix-spi: validate report size to prevent stack buffer overflow (git-fixes). - HID: letsketch: fix UAF on inrange_timer at driver unbind (git-fixes). - HID: lg-g15: cancel pending work on remove to fix a use-after-free (git-fixes). - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). - HID: picolcd: prevent NULL pointer dereference in picolcd_send_and_wait() (git-fixes). - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). - HID: rate-limit hid_warn to prevent log flooding (stable-fixes). - HID: remove duplicate hid_warn_ratelimited definition (git-fixes). - HID: wacom: Fix OOB write in wacom_hid_set_device_mode()(git-fixes). - HID: wacom: stop hardware after post-start probe failures (git-fixes). - HID: wiimote: Fix table layout and whitespace errors (git-fixes). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv: utils: replace deprecated strcpy with strscpy in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf (git-fixes). - hwmon: (aspeed-g6-pwm-tach) Guard fan RPM calculation against divide-by-zero (git-fixes). - hwmon: (asus_atk0110) Check package count before accessing element (git-fixes). - hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). - hwmon: (ltc2992) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - hwmon: (max1619) add missing 'select REGMAP' to Kconfig (git-fixes). - hwmon: (max6697) add missing 'select REGMAP_I2C' to Kconfig (git-fixes). - hwmon: (occ) unregister sysfs devices outside occ lock (git-fixes). - hwmon: adm1275: Prevent reading uninitialized stack (git-fixes). - hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). - hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - i2c: core: disable runtime PM on adapter registration failure (git-fixes). - i2c: core: fix adapter debugfs creation (git-fixes). - i2c: core: fix adapter deregistration race (git-fixes). - i2c: core: fix adapter probe deferral loop (git-fixes). - i2c: core: fix adapter registration race (git-fixes). - i2c: core: fix hang on adapter registration failure (git-fixes). - i2c: core: fix irq domain leak on adapter registration failure (git-fixes). - i2c: core: fix NULL-deref on adapter registration failure (git-fixes). - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). - i2c: imx-lpi2c: mark I2C adapter when hardware is powered down (git-fixes). - i2c: mpc: Fix timeout calculations (git-fixes). - i2c: qcom-cci: Fix NULL pointer dereferencein cci_remove() (git-fixes). - i2c: riic: fix refcount leak in riic_i2c_resume_noirq() (git-fixes). - i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). - i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). - i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). - i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes). - i3c: master: Serialize i3c_set_hotjoin() with the maintenance lock (git-fixes). - ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). - iio: adc: ti-ads1298: add bounds check to pga_settings index (stable-fixes). - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). - iio: backend: fix uninitialized data in debugfs (git-fixes). - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). - iio: chemical: scd30: fix division by zero in write_raw (git-fixes). - iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes). - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes). - iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes). - iio: light: opt3001: fix missing state reset on timeout (git-fixes). - iio: light: si1133: prevent race condition on timeout (git-fixes). - iio: light: si1133: reset counter to prevent race condition (git-fixes). - iio: light: veml6030: fix channel type when pushing events (git-fixes). - iio: light: veml6075: add bounds check to veml6075_it_ms index (stable-fixes). - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). - iio: resolver: ad2s1210: notify trigger and clear state on fault read error (git-fixes). - iio: tcs3472: power down chip on probe failure (git-fixes). - iio: temperature: ltc2983: Fix n_wires default bypassing rotation check (git-fixes). - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start(git-fixes). - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). - Input: elan_i2c - validate firmware size before use (stable-fixes). - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes). - Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). - Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). - io_uring/cancel: de-unionize file and user_data in struct io_cancel_data (git-fixes bsc#1261250). - io_uring/filetable: clamp alloc_hint to the configured alloc range (git-fixes bsc#1261250). - io_uring/io-wq: fix incorrect io_wq_for_each_worker() termination logic (git-fixes bsc#1261250). - io_uring/poll: ensure EPOLL_ONESHOT is propagated for EPOLL_URING_WAKE (git-fixes bsc#1261250). - io_uring/wait: fix min_timeout behavior (git-fixes bsc#1261250). - io_uring/waitid: clear waitid info before copying it to userspace (git-fixes). - io_uring: fix min_wait wakeups for SQPOLL (git-fixes bsc#1261250). - ipv4: account for fraggap on the paged allocation path (git-fixes). - ipv6: account for fraggap on the paged allocation path (git-fixes). - KEYS: fix overflow in keyctl_pkey_params_get_2() (git-fixes). - KEYS: Use acquire when reading state in keyring search (git-fixes). - KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). - KVM: arm64: vgic: Free private_irqs when init fails after allocation (git-fixes). - KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying (git-fixes). - KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN (git-fixes). - KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). - KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). - KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). - KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 (git-fixes). - KVM: nSVM: Sync NextRIP to cached vmcb12 after VMRUN of L2 (git-fixes). - KVM: nVMX: Immediately refresh APICv controls as needed on nestedVM-Exit (git-fixes). - KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (git-fixes). - KVM: SEV: Add an anonymous "psc" struct to track current PSC metadata (git-fixes). - KVM: SEV: Decouple the need to sync the GHCB SA from the need to free the SA (git-fixes). - KVM: SEV: Don't terminate SNP VMs on #VMGEXIT without a registered GHCB (git-fixes). - KVM: SEV: Make it more obvious when KVM is writing back the current PSC index (git-fixes). - KVM: SEV: Move sev_free_vcpu() down below sev_es_unmap_ghcb() (git-fixes). - KVM: SEV: Read start/end indices of PSC requests exactly once per #VMGEXIT (git-fixes). - KVM: SEV: Return INVALID_EVENT for SNP-only #VMGEXIT from non-SNP guest (git-fixes). - KVM: SEV: Return INVALID_INPUT, not MISSING_INPUT, for bad GUEST_REQUEST input(s) (git-fixes). - KVM: SEV: Unmap and unpin the GHCB as needed on vCPU free (git-fixes). - KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). - KVM: SVM: check validity of VMCB controls when returning from SMM (git-fixes). - KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). - KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). - KVM: Use vCPU specific memslots in __kvm_vcpu_map() (git-fixes). - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). - KVM: VMX: Read 32-bit GPR values for ENCLS instructions outside of 64-bit mode (git-fixes). - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). - KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). - KVM: x86/xen: Bug the VM if 32-bit KVM observes a 64-bit mode hypercall (git-fixes). - KVM: x86/xen: Don't truncate RAX when handling hypercall from protected guest (git-fixes). - KVM: x86: Consolidate CPUID fault handling for emulator and interception logic (git-fixes). - KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes). - KVM: x86: hyper-v: Bound the bank index when queryingsparse banks (git-fixes). - KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). - KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). - KVM: x86: Prioritize CPUID faulting over CPUID VM-exits in nested VMX (git-fixes). - KVM: x86: Trace hypercall register *after* truncating values for 32-bit (git-fixes). - KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). - mailbox: imx: Forward the timeout/ error in imx_mu_generic_tx() (git-fixes). - mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). - misc: fastrpc: fix DMA address corruption due to find_vma misuse (git-fixes). - misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). - misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git-fixes). - misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). - mm/vmstat: defer the refresh_zone_stat_thresholds after all CPUs bringup (bsc#1270042). - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes). - mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). - mtd: rawnand: Pause continuous reads at block boundaries (git-fixes). - mtd: rawnand: pl353: fix probe resource allocation (git-fixes). - mtd: slram: remove failed entries from the device list (git-fixes). - mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). - mtd: spi-nor: macronix: Add post_sfdp fixups for Quad Input Page Program (stable-fixes). - mtd: spi-nor: macronix: add support for mx66{l2, u1}g45g (stable-fixes). - mtd: spi-nor: spansion: use die erase for multi-die devices only (git-fixes). - mtd: spi-nor: swp: Improve locking user experience (git-fixes). - net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Add support for RXCQE Coalescing (bsc#1261256). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Cache MANA_QUERY_LINK_CONFIG result to avoid repeated HWC queries (bsc#1268238). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Sync page pool RX frags for CPU (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - net: mana: Validate the packet length reported by the NIC (git-fixes). - net: phy: sfp: free mii_bus in sfp_i2c_mdiobus_destroy (git-fixes). - net: usb: lan78xx: disable VLAN filter in promiscuous mode (git-fixes). - net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (git-fixes). - net: wwan: iosm: bound device offsets in the MUX downlink decoder (git-fixes). - nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). - nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). - packaging: Add nvidia kernel description. - packaging: compute-PATCHVERSION.sh -> compute-PATCHVERSION. - page_pool: Fix PP_MAGIC_MASK to avoid crashing on some 32-bit arches (bsc#1261562). - page_pool: Move pp_magic check into helper functions (bsc#1261562). - page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). - PCI: Update saved_config_space upon resource assignment (git-fixes). - perf/x86/intel/uncore: Fix die ID init and look up bugs (bsc#1267419). - perf/x86/intel/uncore: Skip discovery table for offline dies(bsc#1267419). - platform/x86: dell-laptop: fix missing cleanups in init error path (git-fixes). - platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes). - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). - PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). - power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes). - power: supply: core: fix supplied_from allocations (git-fixes). - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). - powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). - powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes). - ppc/fadump: invoke kmsg_dump in fadump panic path (bsc#1270226 ltc#218302). - pwm: imx27: Fix variable truncation in .apply() (git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() (git-fixes). - Revert "fs: don't block i_writecount during exec" (bsc#1269982). - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). - rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes). - rtc: mpfs: fix counter upload completion condition (git-fixes). - rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). - scripts/sorttable: Add helper functions for Elf_Ehdr (bsc#1267600). - scripts/sorttable: Add helper functions for Elf_Shdr (bsc#1267600). - scripts/sorttable: Add helper functions for Elf_Sym (bsc#1267600). - scripts/sorttable: Allow matches to functions before function entry (bsc#1267600). - scripts/sorttable: Always usean array for the mcount_loc sorting (bsc#1267600). - scripts/sorttable: Convert Elf_Ehdr to union (bsc#1267600). - scripts/sorttable: Convert Elf_Sym MACRO over to a union (bsc#1267600). - scripts/sorttable: Fix endianness handling in build-time mcount sort (bsc#1267600). - scripts/sorttable: Get start/stop_mcount_loc from ELF file directly (bsc#1267600). - scripts/sorttable: Have mcount rela sort use direct values (bsc#1267600). - scripts/sorttable: Have the ORC code use the _r() functions to read (bsc#1267600). - scripts/sorttable: Make compare_extable() into two functions (bsc#1267600). - scripts/sorttable: Move code from sorttable.h into sorttable.c (bsc#1267600). - scripts/sorttable: Remove unneeded Elf_Rel (bsc#1267600). - scripts/sorttable: Remove unused macro defines (bsc#1267600). - scripts/sorttable: Remove unused write functions (bsc#1267600). - scripts/sorttable: Replace Elf_Shdr Macro with a union (bsc#1267600). - scripts/sorttable: Use a structure of function pointers for elf helpers (bsc#1267600). - scripts/sorttable: Use normal sort if theres no relocs in the mcount section (bsc#1267600). - scripts/sorttable: Use uint64_t for mcount sorting (bsc#1267600). - scripts/sorttable: Zero out weak functions in mcount_loc table (bsc#1267600). - scsi: smartpqi: Use shost_to_hba() in pqi_scan_finished() (bsc#1257506). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - selftests/bpf: Add BPF_STRICT_BUILD toggle (poo#202224). - selftests/bpf: Allow test_progs to link with a partial object set (poo#202224). - selftests/bpf: Avoid rebuilds when running emit_tests (poo#202224). - selftests/bpf: Consolidate kernel modules into common directory (poo#202224). - selftests/bpf: Copy test_kmods when installing selftest (poo#202224). - selftests/bpf: Fix runqslower cross-endian build (poo#202224). - selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (poo#202224). - selftests/bpf: make BPF_TARGET_ENDIAN non-recursive tospeed up *.bpf.o build (poo#202224). - selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (poo#202224). - selftests/bpf: Provide weak definitions for cross-test functions (poo#202224). - selftests/bpf: Skip tests whose objects were not built (poo#202224). - selftests/bpf: Support cross-endian building (poo#202224). - selftests/bpf: Tolerate benchmark build failures (poo#202224). - selftests/bpf: Tolerate BPF and skeleton generation failures (poo#202224). - selftests/bpf: Tolerate missing files during install (poo#202224). - selftests/bpf: Tolerate test file compilation failures (poo#202224). - serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git-fixes). - serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git-fixes). - serial: qcom_geni: Fix RX DMA stall when SE_DMA_RX_LEN_IN is zero (git-fixes). - slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl-> lock (git-fixes). - slimbus: qcom-ngd-ctrl: Balance pm_runtime enablement for NGD (git-fixes). - slimbus: qcom-ngd-ctrl: Correct PDR and SSR cleanup ownership (git-fixes). - slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). - slimbus: qcom-ngd-ctrl: Fix probe error path ordering (git-fixes). - slimbus: qcom-ngd-ctrl: Fix up platform_driver registration (git-fixes). - slimbus: qcom-ngd-ctrl: Initialize controller resources in controller (git-fixes). - slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd (git-fixes). - soc: qcom: ice: Fix race between qcom_ice_probe() and of_qcom_ice_get() (git-fixes). - soc: qcom: ice: Return -ENODEV if the ICE platform device is not found (git-fixes). - spi: at91-usart: drop dead runtime pm support (git-fixes). - spi: dw: fix wrong BAUDR setting after resume (git-fixes). - spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). - spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). - spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git-fixes). - spi: hisi-kunpeng: Usedev_err_probe() for host registration failure (git-fixes). - spi: meson-spifc: fix runtime PM leak on remove (git-fixes). - spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). - spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). - spi: xilinx: use FIFO occupancy register to determine buffer size (git-fixes). - Split off kABI workaround for bsc#1267458 (bsc#1267458). - staging: most: video: avoid double free on video register failure (git-fixes). - staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). - thermal: hwmon: Fix critical temperature attribute removal (git-fixes). - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). - thermal: testing: reject missing command arguments (git-fixes). - thermal: testing: zone: Flush work items during cleanup (git-fixes). - thunderbolt: Bound root directory content to block size (git-fixes). - thunderbolt: Clamp XDomain response data copy to allocation size (git-fixes). - thunderbolt: debugfs: Don't stop reading SB registers if just one fails (git-fixes). - thunderbolt: debugfs: Fix margining error counter buffer leak (git-fixes). - thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). - thunderbolt: Reject zero-length property entries in validator (git-fixes). - thunderbolt: Validate XDomain request packet size before type cast (git-fixes). - tools/power/x86/intel-speed-select: Harden daemon pidfile open (git-fixes). - tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes). - tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt (git-fixes). - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). - usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes). - usb: host: max3421: Reject hub portrequests for non-existent ports (git-fixes). - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (git-fixes). - USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). - USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). - USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). - usb: storage: Add quirks for PNY Elite Portable SSD (git-fixes). - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). - usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (stable-fixes). - usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers (stable-fixes). - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). - usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). - usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() (git-fixes). - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). - watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). - watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). - watchdog: sama5d4_wdt: Fix WDDIS detection on SAM9X60 and SAMA7G5 (git-fixes). - watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). - watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). - watchdog: unregister PM notifier on watchdog unregister (git-fixes). - wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). - wifi: ath11k: fix warning when unbinding (git-fixes). - wifi: cfg80211: fix grammar in MLO group key errormessage (git-fixes). - wifi: iwlwifi: mvm: fix race condition in PTP removal (stable-fixes). - wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). - wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). - wifi: mt76: mt76x2u: Add support for ELECOM WDC-867SU3S (stable-fixes). - wifi: mt76: mt792x: skip MLD header rewrite for 802.3 encap TX (git-fixes). - wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7921: avoid undesired changes of the preset regulatory domain (stable-fixes). - wifi: mt76: mt7921: fix a potential scan no APs (stable-fixes). - wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). - wifi: mt76: mt7925: don't disable AP BSS when removing TDLS peer (git-fixes). - wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). - wifi: mt76: mt7925: fix stale pointer comparisons in change_vif_links (git-fixes). - wifi: mt76: mt7925: keep TX BA state in the primary WCID (git-fixes). - wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). - wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). - wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). - wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). - wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). - wifi: rtw89: Correct data type for scan index to avoid infinite loop (git-fixes). - wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git-fixes). - wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). - wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git-fixes). - x86/cpu/amd: Correct the microcode table for Zenbleed (git-fixes). - x86/cpu: Disable FRED when PTI is forced on (git-fixes). - x86/cpu: Properly parse CPUID leaf 0x2 TLB descriptor 0x63 (git-fixes). - x86/cpu: Validate CPUID leaf 0x2 EDXoutput (git-fixes). - x86/irq: Ensure initial PIR loads are performed exactly once (git-fixes). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16390). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16390). - X.509: Fix validation of ASN.1 certificate header (git-fixes). - xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1295=1 Package List: - openSUSE Leap 16.0: cluster-md-kmp-64kb-6.12.0-160000.36.1 cluster-md-kmp-azure-6.12.0-160000.36.1 cluster-md-kmp-default-6.12.0-160000.36.1 cluster-md-kmp-rt-6.12.0-160000.36.1 dlm-kmp-64kb-6.12.0-160000.36.1 dlm-kmp-azure-6.12.0-160000.36.1 dlm-kmp-default-6.12.0-160000.36.1 dlm-kmp-rt-6.12.0-160000.36.1 dtb-allwinner-6.12.0-160000.36.1 dtb-altera-6.12.0-160000.36.1 dtb-amazon-6.12.0-160000.36.1 dtb-amd-6.12.0-160000.36.1 dtb-amlogic-6.12.0-160000.36.1 dtb-apm-6.12.0-160000.36.1 dtb-apple-6.12.0-160000.36.1 dtb-arm-6.12.0-160000.36.1 dtb-broadcom-6.12.0-160000.36.1 dtb-cavium-6.12.0-160000.36.1 dtb-exynos-6.12.0-160000.36.1 dtb-freescale-6.12.0-160000.36.1 dtb-hisilicon-6.12.0-160000.36.1 dtb-lg-6.12.0-160000.36.1 dtb-marvell-6.12.0-160000.36.1 dtb-mediatek-6.12.0-160000.36.1 dtb-nvidia-6.12.0-160000.36.1 dtb-qcom-6.12.0-160000.36.1 dtb-renesas-6.12.0-160000.36.1 dtb-rockchip-6.12.0-160000.36.1 dtb-socionext-6.12.0-160000.36.1 dtb-sprd-6.12.0-160000.36.1 dtb-xilinx-6.12.0-160000.36.1 gfs2-kmp-64kb-6.12.0-160000.36.1 gfs2-kmp-azure-6.12.0-160000.36.1 gfs2-kmp-default-6.12.0-160000.36.1 gfs2-kmp-rt-6.12.0-160000.36.1 kernel-64kb-6.12.0-160000.36.1 kernel-64kb-devel-6.12.0-160000.36.1 kernel-64kb-extra-6.12.0-160000.36.1 kernel-64kb-optional-6.12.0-160000.36.1 kernel-azure-6.12.0-160000.36.1 kernel-azure-devel-6.12.0-160000.36.1 kernel-azure-extra-6.12.0-160000.36.1 kernel-azure-optional-6.12.0-160000.36.1 kernel-azure-vdso-6.12.0-160000.36.1 kernel-default-6.12.0-160000.36.1 kernel-default-base-6.12.0-160000.36.1.160000.2.17 kernel-default-devel-6.12.0-160000.36.1 kernel-default-extra-6.12.0-160000.36.1 kernel-default-optional-6.12.0-160000.36.1 kernel-default-vdso-6.12.0-160000.36.1 kernel-devel-6.12.0-160000.36.1 kernel-docs-6.12.0-160000.36.1 kernel-docs-html-6.12.0-160000.36.1 kernel-kvmsmall-6.12.0-160000.36.1 kernel-kvmsmall-devel-6.12.0-160000.36.1 kernel-kvmsmall-vdso-6.12.0-160000.36.1 kernel-macros-6.12.0-160000.36.1 kernel-obs-build-6.12.0-160000.36.1 kernel-obs-qa-6.12.0-160000.36.1 kernel-rt-6.12.0-160000.36.1 kernel-rt-devel-6.12.0-160000.36.1 kernel-rt-extra-6.12.0-160000.36.1 kernel-rt-optional-6.12.0-160000.36.1 kernel-rt-vdso-6.12.0-160000.36.1 kernel-source-6.12.0-160000.36.1 kernel-source-vanilla-6.12.0-160000.36.1 kernel-syms-6.12.0-160000.36.1 kernel-zfcpdump-6.12.0-160000.36.1 kselftests-kmp-64kb-6.12.0-160000.36.1 kselftests-kmp-azure-6.12.0-160000.36.1 kselftests-kmp-default-6.12.0-160000.36.1 kselftests-kmp-rt-6.12.0-160000.36.1 ocfs2-kmp-64kb-6.12.0-160000.36.1 ocfs2-kmp-azure-6.12.0-160000.36.1 ocfs2-kmp-default-6.12.0-160000.36.1 ocfs2-kmp-rt-6.12.0-160000.36.1 References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-39894.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2026-23248.html * https://www.suse.com/security/cve/CVE-2026-23394.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31438.html *https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31479.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31646.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31743.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43016.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html *https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43057.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43090.html * https://www.suse.com/security/cve/CVE-2026-43092.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43124.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43130.html * https://www.suse.com/security/cve/CVE-2026-43132.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43145.html * https://www.suse.com/security/cve/CVE-2026-43157.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43161.html * https://www.suse.com/security/cve/CVE-2026-43167.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43175.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43191.html * https://www.suse.com/security/cve/CVE-2026-43194.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43199.html * https://www.suse.com/security/cve/CVE-2026-43205.html *https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43226.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43240.html * https://www.suse.com/security/cve/CVE-2026-43248.html * https://www.suse.com/security/cve/CVE-2026-43260.html * https://www.suse.com/security/cve/CVE-2026-43283.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43298.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43337.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43351.html * https://www.suse.com/security/cve/CVE-2026-43373.html * https://www.suse.com/security/cve/CVE-2026-43374.html * https://www.suse.com/security/cve/CVE-2026-43383.html * https://www.suse.com/security/cve/CVE-2026-43384.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43403.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43415.html * https://www.suse.com/security/cve/CVE-2026-43449.html * https://www.suse.com/security/cve/CVE-2026-43450.html * https://www.suse.com/security/cve/CVE-2026-43452.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43457.html * https://www.suse.com/security/cve/CVE-2026-43458.html * https://www.suse.com/security/cve/CVE-2026-43465.html * https://www.suse.com/security/cve/CVE-2026-43466.html * https://www.suse.com/security/cve/CVE-2026-43468.html *https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43471.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45837.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45857.html * https://www.suse.com/security/cve/CVE-2026-45858.html * https://www.suse.com/security/cve/CVE-2026-45861.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45884.html * https://www.suse.com/security/cve/CVE-2026-45888.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45899.html * https://www.suse.com/security/cve/CVE-2026-45901.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45920.html * https://www.suse.com/security/cve/CVE-2026-45922.html * https://www.suse.com/security/cve/CVE-2026-45933.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-45997.html *https://www.suse.com/security/cve/CVE-2026-45999.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46046.html * https://www.suse.com/security/cve/CVE-2026-46050.html * https://www.suse.com/security/cve/CVE-2026-46051.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46093.html * https://www.suse.com/security/cve/CVE-2026-46099.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46161.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46178.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html *https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46314.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46322.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52919.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52933.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52980.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53015.html * https://www.suse.com/security/cve/CVE-2026-53021.html * https://www.suse.com/security/cve/CVE-2026-53036.html * https://www.suse.com/security/cve/CVE-2026-53039.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53049.html *https://www.suse.com/security/cve/CVE-2026-53050.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53060.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53078.html * https://www.suse.com/security/cve/CVE-2026-53081.html * https://www.suse.com/security/cve/CVE-2026-53086.html * https://www.suse.com/security/cve/CVE-2026-53090.html * https://www.suse.com/security/cve/CVE-2026-53103.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53139.html * https://www.suse.com/security/cve/CVE-2026-53156.html * https://www.suse.com/security/cve/CVE-2026-53167.html * https://www.suse.com/security/cve/CVE-2026-53168.html * https://www.suse.com/security/cve/CVE-2026-53176.html * https://www.suse.com/security/cve/CVE-2026-53178.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53215.html * https://www.suse.com/security/cve/CVE-2026-53216.html * https://www.suse.com/security/cve/CVE-2026-53217.html * https://www.suse.com/security/cve/CVE-2026-53229.html * https://www.suse.com/security/cve/CVE-2026-53249.html * https://www.suse.com/security/cve/CVE-2026-53258.html * https://www.suse.com/security/cve/CVE-2026-53262.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53272.html * https://www.suse.com/security/cve/CVE-2026-53274.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53285.html * https://www.suse.com/security/cve/CVE-2026-53286.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53306.html * https://www.suse.com/security/cve/CVE-2026-53359.html *https://www.suse.com/security/cve/CVE-2026-53362.html . An important security update for openSUSE kernel addresses 255 vulnerabilities and 285 bug fixes.. kernel patch management, system security, opensuse vulnerabilities, software integrity. . Severity: Important. LinuxSecurity.com Team
openSUSE has released a security update for libgcrypt addressing CVE-2026-41989, which could cause a denial of service, along with one bug fix for openSUSE Leap 16.0.. openSUSE security update: security update for libgcrypt ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21387-1 Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for libgcrypt fixes the following issue - CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-1294=1 Package List: - openSUSE Leap 16.0: libgcrypt-devel-1.12.1-160000.3.1 libgcrypt-devel-x86-64-v3-1.12.1-160000.3.1 libgcrypt20-1.12.1-160000.3.1 libgcrypt20-x86-64-v3-1.12.1-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2026-41989.html . An openSUSE security update for libgcrypt addresses a moderate denial of service issue with CVE-2026-41989. Install now.. openSUSE, libgcrypt, denial of service, security advisory, system update. . Severity: moderate. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.