{"id":"SUSE-SU-2026:4256-1","summary":"Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5)","details":"\nThis update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.121 fixes various security issues:\n\nThe following security issues were fixed:\n\n- CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388).\n- CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458).\n- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (Zapscape) (bsc#1273232).\n- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074).\n- CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942).\n","modified":"2026-09-18T10:00:05.405986160Z","published":"2026-09-17T19:33:53Z","related":["CVE-2026-46150","CVE-2026-64423","CVE-2026-64561","CVE-2026-64564","CVE-2026-68138"],"upstream":["CVE-2026-46150","CVE-2026-64423","CVE-2026-64561","CVE-2026-64564","CVE-2026-68138"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264256-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267388"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273232"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274074"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275458"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46150"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64423"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64561"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64564"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-68138"}],"affected":[{"package":{"name":"kernel-livepatch-SLE15-SP4_Update_55","ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP4","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP4_Update_55&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5-150400.2.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-5_14_21-150400_24_222-default":"5-150400.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4256-1.json"}},{"package":{"name":"kernel-livepatch-SLE15-SP5_Update_30","ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP5","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP5_Update_30&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"18-150500.2.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-5_14_21-150500_55_121-default":"18-150500.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4256-1.json"}}],"schema_version":"1.9.0"}