{"id":"SUSE-SU-2026:2068-1","summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues\n\nThe following security issues were fixed:\n\n- CVE-2022-50053: iavf: Fix reset error handling (bsc#1245038).\n- CVE-2023-20585: x86/CPU: Fix FPDSS on Zen1. (bsc#1243603).\n- CVE-2024-50082: blk-rq-qos: fix crash on rq_qos_wait vs. rq_qos_wake_function race (bsc#1232500 bsc#1262778).\n- CVE-2025-68185: nfs4_setup_readdir(): insufficient locking for -\u003ed_parent-\u003ed_inode dereferencing (bsc#1255135).\n- CVE-2025-71118: ACPICA: Avoid walking the Namespace if start_node is NULL (bsc#1256763).\n- CVE-2025-71238: scsi: qla2xxx: Fix bsg_done() causing double free (bsc#1259186).\n- CVE-2026-23193: scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count() (bsc#1258414).\n- CVE-2026-23216: scsi: target: iscsi: Fix use-after-free in iscsit_dec_conn_usage_count() (bsc#1258447).\n- CVE-2026-23276: net: add xmit recursion limit to tunnel xmit functions (bsc#1260012).\n- CVE-2026-23290: net: usb: pegasus: validate USB endpoints (bsc#1260533).\n- CVE-2026-23292: scsi: target: Fix recursive locking in __configfs_open_file() (bsc#1260500).\n- CVE-2026-23293: net: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled (bsc#1260486).\n- CVE-2026-23312: net: usb: kaweth: validate USB endpoints (bsc#1260561).\n- CVE-2026-23340: net: sched: avoid qdisc_reset_all_tx_gt() vs dequeue race for lockless qdiscs (bsc#1260523).\n- CVE-2026-23378: act_ife: load meta modules before tcf_idr_check_alloc() (bsc#1260546).\n- CVE-2026-23391: netfilter: xt_CT: drop pending enqueued packets on template removal (bsc#1260566).\n- CVE-2026-23442: ipv6: add NULL checks for idev in SRv6 paths (bsc#1261581).\n- CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1261779).\n- CVE-2026-23455: netfilter: nf_conntrack_h323: check for zero length in DecodeQ931() (bsc#1261687).\n- CVE-2026-23456: netfilter: nf_conntrack_h323: fix OOB read in decode_int() CONS case (bsc#1261703).\n- CVE-2026-23457: netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp() (bsc#1261686).\n- CVE-2026-23458: netfilter: ctnetlink: fix use-after-free in ctnetlink_dump_exp_ct() (bsc#1261781).\n- CVE-2026-23461: Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user (bsc#1261707).\n- CVE-2026-23462: Bluetooth: HIDP: Fix possible UAF (bsc#1261710).\n- CVE-2026-23468: drm/amdgpu: Limit BO list entry count to prevent resource exhaustion (bsc#1261692).\n- CVE-2026-23472: serial: core: fix infinite loop in handle_tx() for PORT_UNKNOWN (bsc#1261636).\n- CVE-2026-31393: Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access (bsc#1261719).\n- CVE-2026-31400: sunrpc: fix cache_request leak in cache_release (bsc#1261645).\n- CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261638).\n- CVE-2026-31403: NFSD: Hold net reference for the lifetime of /proc/fs/nfs/exports fd (bsc#1261796).\n- CVE-2026-31407: netfilter: conntrack: add missing netlink policy validations (bsc#1261632).\n- CVE-2026-31408: Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold (bsc#1261797).\n- CVE-2026-31411: net: atm: fix crash due to unvalidated vcc pointer in sigd_send() (bsc#1261752).\n- CVE-2026-31416: netfilter: nfnetlink_log: account for netlink header size (bsc#1262100).\n- CVE-2026-31422: net/sched: cls_flow: fix NULL pointer dereference on shared blocks (bsc#1262054).\n- CVE-2026-31423: net/sched: sch_hfsc: fix divide-by-zero in rtsc_min() (bsc#1262063).\n- CVE-2026-31424: netfilter: x_tables: restrict xt_check_match/xt_check_target extensions for NFPROTO_ARP (bsc#1262053).\n- CVE-2026-31425: rds: ib: reject FRMR registration before IB connection is established (bsc#1262074).\n- CVE-2026-31427: netfilter: nf_conntrack_sip: fix use of uninitialized rtp_addr in process_sdp (bsc#1262086).\n- CVE-2026-31428: netfilter: nfnetlink_log: fix uninitialized padding leak in NFULA_PAYLOAD (bsc#1262087).\n- CVE-2026-31496: netfilter: nf_conntrack_expect: skip expectations in other netns via proc (bsc#1262673).\n- CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263085).\n- CVE-2026-31507: net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer (bsc#1263095).\n- CVE-2026-31512: Bluetooth: L2CAP: Validate PDU length before reading SDU length in l2cap_ecred_data_rcv()\n  (bsc#1262734).\n- CVE-2026-31524: HID: asus: avoid memory leak in asus_report_fixup() (bsc#1262605).\n- CVE-2026-31602: ALSA: ctxfi: Limit PTP to a single page (bsc#1263723).\n- CVE-2026-31607: usbip: validate number_of_packets in usbip_pack_ret_submit() (bsc#1263600).\n- CVE-2026-31649: net: stmmac: fix integer underflow in chain mode (bsc#1263582).\n- CVE-2026-31667: Input: uinput - fix circular locking dependency with ff-core (bsc#1263139).\n- CVE-2026-31675: net/sched: sch_netem: fix out-of-bounds access in packet corruption (bsc#1263556).\n- CVE-2026-31681: netfilter: xt_multiport: validate range encoding in checkentry (bsc#1263593).\n- CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263668).\n- CVE-2026-31700: net/packet: fix TOCTOU race on mmap'd vnet_hdr in tpacket_snd() (bsc#1263882).\n- CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264059).\n- CVE-2026-31787: xen/privcmd: fix double free via VMA splitting (bsc#1262181).\n- CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1263931).\n- CVE-2026-43088: net: af_key: zero aligned sockaddr tail in PF_KEY exports (bsc#1264469).\n- CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264482).\n- CVE-2026-43126: ALSA: mixer: oss: Add card disconnect checkpoints (bsc#1264634).\n- CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264848).\n- CVE-2026-43255: wifi: libertas: fix WARNING in usb_tx_block (bsc#1264473).\n- CVE-2026-43264: fbdev: of: display_timing: fix refcount leak in of_get_display_timings() (bsc#1264424).\n- CVE-2026-43334: Bluetooth: SMP: force responder MITM requirements before building the pairing response (bsc#1265090).\n- CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265126).\n\nThe following non security issues were fixed:\n\n- list: add 'list_del_init_careful()' to go with 'list_empty_careful()' (bsc#1262778).\n- ocfs2: fix possible deadlock between unlink and dio_end_io_write (bsc#1258718).\n- ocfs2: split transactions in dio completion to avoid credit exhaustion (bsc#1258718).\n","modified":"2026-05-27T08:16:17.767716825Z","published":"2026-05-26T07:29:48Z","related":["CVE-2022-50053","CVE-2023-20585","CVE-2024-50082","CVE-2025-68185","CVE-2025-71108","CVE-2025-71118","CVE-2025-71238","CVE-2026-23193","CVE-2026-23209","CVE-2026-23216","CVE-2026-23268","CVE-2026-23269","CVE-2026-23273","CVE-2026-23276","CVE-2026-23290","CVE-2026-23292","CVE-2026-23293","CVE-2026-23312","CVE-2026-23340","CVE-2026-23378","CVE-2026-23391","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23408","CVE-2026-23442","CVE-2026-23449","CVE-2026-23455","CVE-2026-23456","CVE-2026-23457","CVE-2026-23458","CVE-2026-23461","CVE-2026-23462","CVE-2026-23468","CVE-2026-23472","CVE-2026-31393","CVE-2026-31400","CVE-2026-31402","CVE-2026-31403","CVE-2026-31407","CVE-2026-31408","CVE-2026-31411","CVE-2026-31416","CVE-2026-31422","CVE-2026-31423","CVE-2026-31424","CVE-2026-31425","CVE-2026-31427","CVE-2026-31428","CVE-2026-31496","CVE-2026-31504","CVE-2026-31507","CVE-2026-31512","CVE-2026-31524","CVE-2026-31602","CVE-2026-31607","CVE-2026-31649","CVE-2026-31667","CVE-2026-31675","CVE-2026-31681","CVE-2026-31685","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43025","CVE-2026-43088","CVE-2026-43110","CVE-2026-43126","CVE-2026-43190","CVE-2026-43255","CVE-2026-43264","CVE-2026-43334","CVE-2026-43437","CVE-2026-46333"],"upstream":["CVE-2022-50053","CVE-2023-20585","CVE-2024-50082","CVE-2025-68185","CVE-2025-71108","CVE-2025-71118","CVE-2025-71238","CVE-2026-23193","CVE-2026-23209","CVE-2026-23216","CVE-2026-23268","CVE-2026-23269","CVE-2026-23273","CVE-2026-23276","CVE-2026-23290","CVE-2026-23292","CVE-2026-23293","CVE-2026-23312","CVE-2026-23340","CVE-2026-23378","CVE-2026-23391","CVE-2026-23403","CVE-2026-23404","CVE-2026-23405","CVE-2026-23408","CVE-2026-23442","CVE-2026-23449","CVE-2026-23455","CVE-2026-23456","CVE-2026-23457","CVE-2026-23458","CVE-2026-23461","CVE-2026-23462","CVE-2026-23468","CVE-2026-23472","CVE-2026-31393","CVE-2026-31400","CVE-2026-31402","CVE-2026-31403","CVE-2026-31407","CVE-2026-31408","CVE-2026-31411","CVE-2026-31416","CVE-2026-31422","CVE-2026-31423","CVE-2026-31424","CVE-2026-31425","CVE-2026-31427","CVE-2026-31428","CVE-2026-31496","CVE-2026-31504","CVE-2026-31507","CVE-2026-31512","CVE-2026-31524","CVE-2026-31602","CVE-2026-31607","CVE-2026-31649","CVE-2026-31667","CVE-2026-31675","CVE-2026-31681","CVE-2026-31685","CVE-2026-31700","CVE-2026-31738","CVE-2026-31787","CVE-2026-43025","CVE-2026-43088","CVE-2026-43110","CVE-2026-43126","CVE-2026-43190","CVE-2026-43255","CVE-2026-43264","CVE-2026-43334","CVE-2026-43437","CVE-2026-46333"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20262068-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1232500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243603"},{"type":"REPORT","url":"https://bugzilla.suse.com/1245038"},{"type":"REPORT","url":"https://bugzilla.suse.com/1255135"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256763"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256774"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258414"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258447"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258718"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258849"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258850"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258854"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259186"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259857"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260010"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260012"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260486"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260500"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260523"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260533"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260561"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260566"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261295"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261581"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261632"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261636"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261638"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261645"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261686"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261692"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261703"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261707"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261710"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261719"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261752"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261779"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261781"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261796"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261797"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262053"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262054"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262063"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262074"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262086"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262087"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262100"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262181"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262605"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262734"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262778"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263085"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263095"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263556"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263582"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263668"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263931"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264059"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264424"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264469"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264473"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264634"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265090"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265126"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-50053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-20585"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-50082"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-68185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71108"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71118"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-71238"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23193"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23209"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23216"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23268"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23269"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23273"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23276"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23290"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23312"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23340"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23391"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23404"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23405"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23442"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23457"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23461"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23462"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23468"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23472"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31393"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31400"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31402"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31403"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31407"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31408"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31411"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31416"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31424"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31427"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31428"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31504"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31507"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31512"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31649"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31667"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31685"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31700"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31738"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-31787"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43025"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43088"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43110"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43126"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43255"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43264"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43334"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-43437"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46333"}],"schema_version":"1.7.5"}