SUSE SLES12: cluster-md-kmp-default / dlm-kmp-default / gfs2-kmp-default / etc (SUSE-SU-2026:3594-1)

high Nessus Plugin ID 335089

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3594-1 advisory.

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues:

The following security issues were fixed:

- CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618).
- CVE-2026-31510: Bluetooth: L2CAP: Fix null-ptr-deref on l2cap_sock_ready_cb (bsc#1262603).
- CVE-2026-31624: HID: core: clamp report_size in s32ton() to avoid undefined shift (bsc#1263657).
- CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255).
- CVE-2026-43069: Bluetooth: hci_ll: Fix firmware leak on error path (bsc#1264190).
- CVE-2026-43123: fbcon: check return value of con2fb_acquire_newinfo() (bsc#1264598).
- CVE-2026-43124: pstore: ram_core: fix incorrect success return when vmap() fails (bsc#1264545).
- CVE-2026-43156: net: usb: pegasus: enable basic endpoint checking (bsc#1265092).
- CVE-2026-43168: ocfs2: fix reflink preserve cleanup issue (bsc#1264537).
- CVE-2026-43180: net: usb: kaweth: remove TX queue manipulation in kaweth_set_rx_mode (bsc#1265093).
- CVE-2026-43211: PCI: Fix pci_slot_trylock() error handling (bsc#1264387).
- CVE-2026-43216: net: Drop the lock in skb_may_tx_timestamp() (bsc#1264319).
- CVE-2026-43226: net/rds: No shortcut out of RDS_CONN_ERROR (bsc#1264544).
- CVE-2026-43230: net/rds: Clear reconnect pending bit (bsc#1264539).
- CVE-2026-43244: kcm: fix zero-frag skb in frag_list on partial sendmsg error (bsc#1264321).
- CVE-2026-43253: iommu/amd: move wait_on_sem() out of spinlock (bsc#1264419).
- CVE-2026-43266: EFI/CPER: don't go past the ARM processor CPER record buffer (bsc#1264418).
- CVE-2026-43268: hfsplus: pretend special inodes as regular files (bsc#1265083).
- CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446).
- CVE-2026-43281: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() (bsc#1264534).
- CVE-2026-43287: drm: Account property blob allocations to memcg (bsc#1265037).
- CVE-2026-43308: btrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref() (bsc#1264712).
- CVE-2026-43309: md raid: fix hang when stopping arrays with metadata through dm-raid (bsc#1264827).
- CVE-2026-43313: ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4() (bsc#1264821).
- CVE-2026-43370: drm/amdgpu: Fix use-after-free race in VM acquire (bsc#1264782).
- CVE-2026-43373: net: ncsi: fix skb leak in error paths (bsc#1265079).
- CVE-2026-43383: net/tcp-md5: Fix MAC comparison to be constant-time (bsc#1264744).
- CVE-2026-43425: usb: image: mdc800: kill download URB on timeout (bsc#1265133).
- CVE-2026-43427: usb: class: cdc-wdm: fix reordering issue in read code path (bsc#1264746).
- CVE-2026-43445: e1000/e1000e: Fix leak in DMA error cleanup (bsc#1265041).
- CVE-2026-43449: nvme-pci: Fix slab-out-of-bounds in nvme_dbbuf_set (bsc#1265023).
- CVE-2026-43450: netfilter: nfnetlink_cthelper: fix OOB read in nfnl_cthelper_dump_table() (bsc#1264794).
- CVE-2026-43451: netfilter: nfnetlink_queue: fix entry leak in bridge verdict error path (bsc#1265009).
- CVE-2026-43452: netfilter: x_tables: guard option walkers against 1-byte tail reads (bsc#1265142).
- CVE-2026-43466: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery (bsc#1264790).
- CVE-2026-43493: crypto: pcrypt - Fix handling of MAY_BACKLOG requests (bsc#1265627).
- CVE-2026-43496: net/sched: sch_red: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1266000).
- CVE-2026-45857: scsi: csiostor: Fix dereference of null pointer rn (bsc#1266458).
- CVE-2026-45858: ext4: subdivide EXT4_EXT_DATA_VALID1 (bsc#1266773).
- CVE-2026-45871: tpm: st33zp24: Fix missing cleanup on get_burstcount() error (bsc#1266755).
- CVE-2026-45877: HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients (bsc#1266468).
- CVE-2026-45899: ext4: drop extent cache when splitting extent fails (bsc#1266883).
- CVE-2026-45905: xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path (bsc#1266685).
- CVE-2026-45915: fat: avoid parent link count underflow in rmdir (bsc#1266896).
- CVE-2026-45917: ipvs: do not keep dest_dst if dev is going down (bsc#1266900).
- CVE-2026-45920: ext4: fix dirtyclusters double decrement on fs shutdown (bsc#1266893).
- CVE-2026-45923: net: usb: catc: enable basic endpoint checking (bsc#1266894).
- CVE-2026-45981: s390/cio: Fix device lifecycle handling in css_alloc_subchannel() (bsc#1267204).
- CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700).
- CVE-2026-45994: ibmasm: fix OOB reads in command_file_write due to missing size checks (bsc#1267432).
- CVE-2026-45997: scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails (bsc#1266740).
- CVE-2026-46018: ALSA: usb-audio: stop parsing UAC2 rates at MAX_NR_RATES (bsc#1266751).
- CVE-2026-46023: dm mirror: fix integer overflow in create_dirty_log() (bsc#1267449).
- CVE-2026-46027: net/smc: avoid early lgr access in smc_clc_wait_msg (bsc#1266744).
- CVE-2026-46033: crypto: authencesn - reject short ahash digests during instance creation (bsc#1266692).
- CVE-2026-46040: inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails (bsc#1267472).
- CVE-2026-46049: ALSA: ctxfi: Add fallback to default RSR for S/PDIF (bsc#1267448).
- CVE-2026-46051: md/raid5: fix soft lockup in retry_aligned_read() (bsc#1267360).
- CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).
- CVE-2026-46064: ibmasm: fix heap over-read in ibmasm_send_i2o_message() (bsc#1267497).
- CVE-2026-46068: crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx (bsc#1267592).
- CVE-2026-46086: net: bridge: use a stable FDB dst snapshot in RCU readers (bsc#1267524).
- CVE-2026-46088: ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() (bsc#1267226).
- CVE-2026-46102: net: strparser: fix skb_head leak in strp_abort_strp() (bsc#1267502).
- CVE-2026-46146: ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() (bsc#1267571).
- CVE-2026-46149: scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() (bsc#1267648).
- CVE-2026-46161: md/raid10: fix divide-by-zero in setup_geo() with zero far_copies (bsc#1266838).
- CVE-2026-46167: usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl (bsc#1266832).
- CVE-2026-46177: ipmi: Add limits to event and receive message requests (bsc#1267725).
- CVE-2026-46178: RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() (bsc#1267493).
- CVE-2026-46180: wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task (bsc#1266813).
- CVE-2026-46184: sound: ua101: fix division by zero at probe (bsc#1266864).
- CVE-2026-46189: RDMA/vmw_pvrdma: Fix double free on pvrdma_alloc_ucontext() error path (bsc#1266918).
- CVE-2026-46191: fbcon: Avoid OOB font access if console rotation fails (bsc#1267690).
- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
- CVE-2026-46220: drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission (bsc#1267704).
- CVE-2026-46245: drm/amd/display: Fix dc_link NULL handling in HPD init (bsc#1267678).
- CVE-2026-46252: regulator: core: fix locking in regulator_resolve_supply() error path (bsc#1267676).
- CVE-2026-46294: dm: fix a buffer overflow in ioctl processing (bsc#1267939).
- CVE-2026-46307: wifi: ath5k: do not access array OOB (bsc#1267987).
- CVE-2026-46321: tun: free page on short-frame rejection in tun_xdp_one() (bsc#1268024).
- CVE-2026-46322: tun: free page on build_skb failure in tun_xdp_one() (bsc#1267994).
- CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
- CVE-2026-52915: netfilter: ip6t_hbh: reject oversized option lists (bsc#1269001).
- CVE-2026-52927: netfilter: ebtables: fix OOB read in compat_mtw_from_user (bsc#1269027).
- CVE-2026-52930: ipc/shm: serialize orphan cleanup with shm_nattch updates (bsc#1269003).
- CVE-2026-52942: netfilter: nf_log: validate MAC header was set before dumping it (bsc#1268967).
- CVE-2026-52948: i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (bsc#1269116).
- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
- CVE-2026-52981: neigh: let neigh_xmit take skb ownership (bsc#1269254).
- CVE-2026-52982: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() (bsc#1269258).
- CVE-2026-52984: net/sched: netem: fix queue limit check to include reordered packets (bsc#1269272).
- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).
- CVE-2026-52995: net/rds: zero per-item info buffer before handing it to visitors (bsc#1269124).
- CVE-2026-52998: netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check (bsc#1269118).
- CVE-2026-53002: netfilter: conntrack: remove sprintf usage (bsc#1269112).
- CVE-2026-53004: sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks (bsc#1269106).
- CVE-2026-53006: ipv6: fix possible UAF in icmpv6_rcv() (bsc#1269104).
- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
- CVE-2026-53021: scsi: target: core: Fix integer overflow in UNMAP bounds check (bsc#1269151).
- CVE-2026-53036: bpf, arm64: Reject out-of-range B.cond targets (bsc#1269389).
- CVE-2026-53039: ocfs2: validate group add input before caching (bsc#1269392).
- CVE-2026-53060: dm cache metadata: fix memory leak on metadata abort retry (bsc#1269164).
- CVE-2026-53062: dm cache policy smq: fix missing locks in invalidating cache blocks (bsc#1269658).
- CVE-2026-53063: dm cache: fix write hang in passthrough mode (bsc#1269659).
- CVE-2026-53064: dm cache: fix null-deref with concurrent writes in passthrough mode (bsc#1269132).
- CVE-2026-53093: wifi: brcmfmac: Fix error pointer dereference (bsc#1269414).
- CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633).
- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
- CVE-2026-53134: netfilter: nft_fib: fix stale stack leak via the OIFNAME register (bsc#1269819).
- CVE-2026-53146: thunderbolt: Limit XDomain response copy to actual frame size (bsc#1269826).
- CVE-2026-53147: thunderbolt: Validate XDomain request packet size before type cast (bsc#1269709).
- CVE-2026-53149: thunderbolt: Bound root directory content to block size (bsc#1269733).
- CVE-2026-53167: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios (bsc#1269768).
- CVE-2026-53176: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN (bsc#1269710).
- CVE-2026-53181: vsock/vmci: fix sk_ack_backlog leak on failed handshake (bsc#1269886).
- CVE-2026-53186: RDMA/srp: bound SRP_RSP sense copy by the received length (bsc#1269663).
- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
- CVE-2026-53208: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (bsc#1269899).
- CVE-2026-53213: drm/vc4: fix krealloc() memory leak (bsc#1269283).
- CVE-2026-53218: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag (bsc#1269273).
- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
- CVE-2026-53225: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() (bsc#1269711).
- CVE-2026-53227: net: openvswitch: fix possible kfree_skb of ERR_PTR (bsc#1269877).
- CVE-2026-53236: tcp: restrict SO_ATTACH_FILTER to priv users (bsc#1269994).
- CVE-2026-53242: ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (bsc#1269236).
- CVE-2026-53245: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr (bsc#1269675).
- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
- CVE-2026-53249: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options (bsc#1269992).
- CVE-2026-53252: adaption to srcu change of hci_dev in hci_sysfs (bsc#1269307).
- CVE-2026-53254: Bluetooth: RFCOMM: validate skb length in MCC handlers (bsc#1269996).
- CVE-2026-53255: Bluetooth: MGMT: validate advertising TLV before type checks (bsc#1269378).
- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
- CVE-2026-53262: l2tp: remove pppol2tp_session_close() (bsc#1270000).
- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
- CVE-2026-53268: netfilter: conntrack_irc: fix possible out-of-bounds read (bsc#1269257).
- CVE-2026-53270: ipvs: clear the svc scheduler ptr early on edit (bsc#1269240).
- CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713).
- CVE-2026-53275: ipv6: mcast: Fix use-after-free when processing MLD queries (bsc#1269810).
- CVE-2026-53306: tty: hvc_iucv: fix off-by-one in number of supported devices (bsc#1269814).
- CVE-2026-53325: agp/amd64: Fix broken error propagation in agp_amd64_probe() (bsc#1269726).
- CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230).
- CVE-2026-53355: net: rds: clear i_sends on setup unwind (bsc#1270249).
- CVE-2026-53369: udf: reject descriptors with oversized CRC length (bsc#1271818).
- CVE-2026-53374: drm/amdgpu: zero-initialize GART table on allocation (bsc#1271827).
- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
- CVE-2026-53376: drm/amdkfd: Add upper bound check for num_of_nodes (bsc#1271831).
- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).
- CVE-2026-53392: NFSv4/flexfiles: reject zero filehandle version count (bsc#1271826).
- CVE-2026-53397: nfsd: fix posix_acl leak on SETACL decode failure (bsc#1271869).
- CVE-2026-53399: nfsd: release layout stid on setlease failure (bsc#1271832).
- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).
- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).
- CVE-2026-63826: fbdev: fix use-after-free in store_modes() (bsc#1272183).
- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).
- CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607).
- CVE-2026-63899: USB: serial: mxuport: fix memory corruption with small endpoint (bsc#1272494).
- CVE-2026-63901: USB: serial: digi_acceleport: fix memory corruption with small endpoints (bsc#1272501).
- CVE-2026-63915: nfc: hci: fix out-of-bounds read in HCP header parsing (bsc#1272897).
- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855).
- CVE-2026-63927: usb: dwc2: Fix use after free in debug code (bsc#1272892).
- CVE-2026-63928: USB: serial: omninet: fix memory corruption with small endpoint (bsc#1272891).
- CVE-2026-63958: usb: typec: ucsi: validate connector number in ucsi_connector_change() (bsc#1272467).
- CVE-2026-64298: NFSv4: include MAY_WRITE in open permission mask for O_TRUNC (bsc#1273550).
- CVE-2026-64330: usb: typec: tcpm: Validate SVID index in svdm_consume_modes() (bsc#1272681).
- CVE-2026-64465: usb: xhci: Fix sleep in atomic context in xhci_free_streams() (bsc#1272843).
- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).

The following non security issues were fixed:

- ACPI: processor: Fix previous acpi_processor_errata_piix4() fix (bsc#1264821).
- dm cache policy smq: check allocation under invalidate lock (git-fixes).
- dm cache: fix missing return in invalidate_committed's error path (git-fixes).
- HID: Intel-ish-hid: Ishtp: Fix sensor reads after ACPI S3 suspend (bsc#1266468).
- KVM: nVMX: use vm_exit_controls_init() to write exit controls for vmcs02 (bsc#1249414).
- kvm: vmx: Fix entry number check for add_atomic_switch_msr() (git-fixes).
- mkspec-dtb: Skip missing DTBs.
- pkspec-dtb: Fix dtb-al rename.
- sctp: validate embedded address parameter length (git-fixes).
- tee: fix possible error pointer ctx dereferencing (git-fixes).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1185845

https://bugzilla.suse.com/1240183

https://bugzilla.suse.com/1243603

https://bugzilla.suse.com/1246182

https://bugzilla.suse.com/1249414

https://bugzilla.suse.com/1258718

https://bugzilla.suse.com/1260593

https://bugzilla.suse.com/1262573

https://bugzilla.suse.com/1262603

https://bugzilla.suse.com/1262618

https://bugzilla.suse.com/1263562

https://bugzilla.suse.com/1263657

https://bugzilla.suse.com/1263718

https://bugzilla.suse.com/1263788

https://bugzilla.suse.com/1264013

https://bugzilla.suse.com/1264076

https://bugzilla.suse.com/1264089

https://bugzilla.suse.com/1264190

https://bugzilla.suse.com/1264255

https://bugzilla.suse.com/1264319

https://bugzilla.suse.com/1264321

https://bugzilla.suse.com/1264387

https://bugzilla.suse.com/1264418

https://bugzilla.suse.com/1264419

https://bugzilla.suse.com/1264446

https://bugzilla.suse.com/1264473

https://bugzilla.suse.com/1264534

https://bugzilla.suse.com/1264537

https://bugzilla.suse.com/1264539

https://bugzilla.suse.com/1264544

https://bugzilla.suse.com/1264545

https://bugzilla.suse.com/1264598

https://bugzilla.suse.com/1264712

https://bugzilla.suse.com/1264744

https://bugzilla.suse.com/1264746

https://bugzilla.suse.com/1264782

https://bugzilla.suse.com/1264790

https://bugzilla.suse.com/1264794

https://bugzilla.suse.com/1264821

https://bugzilla.suse.com/1264827

https://bugzilla.suse.com/1265009

https://bugzilla.suse.com/1265023

https://bugzilla.suse.com/1265037

https://bugzilla.suse.com/1265041

https://bugzilla.suse.com/1265079

https://bugzilla.suse.com/1265083

https://bugzilla.suse.com/1265092

https://bugzilla.suse.com/1265093

https://bugzilla.suse.com/1265133

https://bugzilla.suse.com/1265142

https://bugzilla.suse.com/1265627

https://bugzilla.suse.com/1266000

https://bugzilla.suse.com/1266238

https://bugzilla.suse.com/1266458

https://bugzilla.suse.com/1266468

https://bugzilla.suse.com/1266685

https://bugzilla.suse.com/1266692

https://bugzilla.suse.com/1266700

https://bugzilla.suse.com/1266740

https://bugzilla.suse.com/1266744

https://bugzilla.suse.com/1266751

https://bugzilla.suse.com/1266755

https://bugzilla.suse.com/1266773

https://bugzilla.suse.com/1266813

https://bugzilla.suse.com/1266832

https://bugzilla.suse.com/1266836

https://bugzilla.suse.com/1266838

https://bugzilla.suse.com/1266850

https://bugzilla.suse.com/1266864

https://bugzilla.suse.com/1266883

https://bugzilla.suse.com/1266893

https://bugzilla.suse.com/1266894

https://bugzilla.suse.com/1266896

https://bugzilla.suse.com/1266900

https://bugzilla.suse.com/1266918

https://bugzilla.suse.com/1267204

https://bugzilla.suse.com/1267226

https://bugzilla.suse.com/1267360

https://bugzilla.suse.com/1267384

https://bugzilla.suse.com/1267432

https://bugzilla.suse.com/1267435

https://bugzilla.suse.com/1267448

https://bugzilla.suse.com/1267449

https://bugzilla.suse.com/1267472

https://bugzilla.suse.com/1267493

https://bugzilla.suse.com/1267497

https://bugzilla.suse.com/1267502

https://bugzilla.suse.com/1267524

https://bugzilla.suse.com/1267571

https://bugzilla.suse.com/1267592

https://bugzilla.suse.com/1267596

https://bugzilla.suse.com/1267648

https://bugzilla.suse.com/1267656

https://bugzilla.suse.com/1267676

https://bugzilla.suse.com/1267678

https://bugzilla.suse.com/1267690

https://bugzilla.suse.com/1267704

https://bugzilla.suse.com/1267725

https://bugzilla.suse.com/1267939

https://bugzilla.suse.com/1267987

https://bugzilla.suse.com/1267994

https://bugzilla.suse.com/1268024

https://bugzilla.suse.com/1268659

https://bugzilla.suse.com/1268967

https://bugzilla.suse.com/1269001

https://bugzilla.suse.com/1269003

https://bugzilla.suse.com/1269027

https://bugzilla.suse.com/1269090

https://bugzilla.suse.com/1269104

https://bugzilla.suse.com/1269106

https://bugzilla.suse.com/1269112

https://bugzilla.suse.com/1269116

https://bugzilla.suse.com/1269118

https://bugzilla.suse.com/1269124

https://bugzilla.suse.com/1269132

https://bugzilla.suse.com/1269141

https://bugzilla.suse.com/1269151

https://bugzilla.suse.com/1269164

https://bugzilla.suse.com/1269172

https://bugzilla.suse.com/1269174

https://bugzilla.suse.com/1269236

https://bugzilla.suse.com/1269240

https://bugzilla.suse.com/1269254

https://bugzilla.suse.com/1269257

https://bugzilla.suse.com/1269258

https://bugzilla.suse.com/1269272

https://bugzilla.suse.com/1269273

https://bugzilla.suse.com/1269283

https://bugzilla.suse.com/1269289

https://bugzilla.suse.com/1269307

https://bugzilla.suse.com/1269378

https://bugzilla.suse.com/1269389

https://bugzilla.suse.com/1269392

https://bugzilla.suse.com/1269414

https://bugzilla.suse.com/1269577

https://bugzilla.suse.com/1269633

https://bugzilla.suse.com/1269658

https://bugzilla.suse.com/1269659

https://bugzilla.suse.com/1269663

https://bugzilla.suse.com/1269675

https://bugzilla.suse.com/1269709

https://bugzilla.suse.com/1269710

https://bugzilla.suse.com/1269711

https://bugzilla.suse.com/1269713

https://bugzilla.suse.com/1269726

https://bugzilla.suse.com/1269733

https://bugzilla.suse.com/1269768

https://bugzilla.suse.com/1269773

https://bugzilla.suse.com/1269810

https://bugzilla.suse.com/1269814

https://bugzilla.suse.com/1269819

https://bugzilla.suse.com/1269826

https://bugzilla.suse.com/1269877

https://bugzilla.suse.com/1269886

https://bugzilla.suse.com/1269899

https://bugzilla.suse.com/1269986

https://bugzilla.suse.com/1269988

https://bugzilla.suse.com/1269991

https://bugzilla.suse.com/1269992

https://bugzilla.suse.com/1269993

https://bugzilla.suse.com/1269994

https://bugzilla.suse.com/1269996

https://bugzilla.suse.com/1269997

https://bugzilla.suse.com/1270000

https://bugzilla.suse.com/1270059

https://bugzilla.suse.com/1270230

https://bugzilla.suse.com/1270249

https://bugzilla.suse.com/1271526

https://bugzilla.suse.com/1271546

https://bugzilla.suse.com/1271818

https://bugzilla.suse.com/1271825

https://bugzilla.suse.com/1271826

https://bugzilla.suse.com/1271827

https://bugzilla.suse.com/1271831

https://bugzilla.suse.com/1271832

https://bugzilla.suse.com/1271869

https://bugzilla.suse.com/1271899

https://bugzilla.suse.com/1271904

https://bugzilla.suse.com/1271964

https://bugzilla.suse.com/1272176

https://bugzilla.suse.com/1272183

https://bugzilla.suse.com/1272268

https://bugzilla.suse.com/1272467

https://bugzilla.suse.com/1272494

https://bugzilla.suse.com/1272501

https://bugzilla.suse.com/1272607

https://bugzilla.suse.com/1272681

https://bugzilla.suse.com/1272843

https://bugzilla.suse.com/1272855

https://bugzilla.suse.com/1272891

https://bugzilla.suse.com/1272892

https://bugzilla.suse.com/1272897

https://bugzilla.suse.com/1273550

https://bugzilla.suse.com/1274072

https://www.suse.com/security/cve/CVE-2023-2058

https://www.suse.com/security/cve/CVE-2025-38250

https://www.suse.com/security/cve/CVE-2025-54518

https://www.suse.com/security/cve/CVE-2026-31431

https://www.suse.com/security/cve/CVE-2026-31450

https://www.suse.com/security/cve/CVE-2026-31510

https://www.suse.com/security/cve/CVE-2026-31598

https://www.suse.com/security/cve/CVE-2026-31624

https://www.suse.com/security/cve/CVE-2026-31628

https://www.suse.com/security/cve/CVE-2026-31678

https://www.suse.com/security/cve/CVE-2026-31759

https://www.suse.com/security/cve/CVE-2026-43033

https://www.suse.com/security/cve/CVE-2026-43068

https://www.suse.com/security/cve/CVE-2026-43069

https://www.suse.com/security/cve/CVE-2026-43123

https://www.suse.com/security/cve/CVE-2026-43124

https://www.suse.com/security/cve/CVE-2026-43156

https://www.suse.com/security/cve/CVE-2026-43168

https://www.suse.com/security/cve/CVE-2026-43180

https://www.suse.com/security/cve/CVE-2026-43211

https://www.suse.com/security/cve/CVE-2026-43216

https://www.suse.com/security/cve/CVE-2026-43226

https://www.suse.com/security/cve/CVE-2026-43230

https://www.suse.com/security/cve/CVE-2026-43244

https://www.suse.com/security/cve/CVE-2026-43253

https://www.suse.com/security/cve/CVE-2026-43255

https://www.suse.com/security/cve/CVE-2026-43266

https://www.suse.com/security/cve/CVE-2026-43268

https://www.suse.com/security/cve/CVE-2026-43273

https://www.suse.com/security/cve/CVE-2026-43281

https://www.suse.com/security/cve/CVE-2026-43287

https://www.suse.com/security/cve/CVE-2026-43308

https://www.suse.com/security/cve/CVE-2026-43309

https://www.suse.com/security/cve/CVE-2026-43313

https://www.suse.com/security/cve/CVE-2026-43370

https://www.suse.com/security/cve/CVE-2026-43373

https://www.suse.com/security/cve/CVE-2026-43383

https://www.suse.com/security/cve/CVE-2026-43425

https://www.suse.com/security/cve/CVE-2026-43427

https://www.suse.com/security/cve/CVE-2026-43445

https://www.suse.com/security/cve/CVE-2026-43449

https://www.suse.com/security/cve/CVE-2026-43450

https://www.suse.com/security/cve/CVE-2026-43451

https://www.suse.com/security/cve/CVE-2026-43452

https://www.suse.com/security/cve/CVE-2026-43466

https://www.suse.com/security/cve/CVE-2026-43493

https://www.suse.com/security/cve/CVE-2026-43496

https://www.suse.com/security/cve/CVE-2026-45857

https://www.suse.com/security/cve/CVE-2026-45858

https://www.suse.com/security/cve/CVE-2026-45871

https://www.suse.com/security/cve/CVE-2026-45877

https://www.suse.com/security/cve/CVE-2026-45899

https://www.suse.com/security/cve/CVE-2026-45905

https://www.suse.com/security/cve/CVE-2026-45915

https://www.suse.com/security/cve/CVE-2026-45917

https://www.suse.com/security/cve/CVE-2026-45920

https://www.suse.com/security/cve/CVE-2026-45923

https://www.suse.com/security/cve/CVE-2026-45981

https://www.suse.com/security/cve/CVE-2026-45985

https://www.suse.com/security/cve/CVE-2026-45994

https://www.suse.com/security/cve/CVE-2026-45997

https://www.suse.com/security/cve/CVE-2026-46018

https://www.suse.com/security/cve/CVE-2026-46023

https://www.suse.com/security/cve/CVE-2026-46027

https://www.suse.com/security/cve/CVE-2026-46033

https://www.suse.com/security/cve/CVE-2026-46040

https://www.suse.com/security/cve/CVE-2026-46049

https://www.suse.com/security/cve/CVE-2026-46051

https://www.suse.com/security/cve/CVE-2026-46056

https://www.suse.com/security/cve/CVE-2026-46064

https://www.suse.com/security/cve/CVE-2026-46068

https://www.suse.com/security/cve/CVE-2026-46080

https://www.suse.com/security/cve/CVE-2026-46086

https://www.suse.com/security/cve/CVE-2026-46088

https://www.suse.com/security/cve/CVE-2026-46102

https://www.suse.com/security/cve/CVE-2026-46109

https://www.suse.com/security/cve/CVE-2026-46146

https://www.suse.com/security/cve/CVE-2026-46149

https://www.suse.com/security/cve/CVE-2026-46161

https://www.suse.com/security/cve/CVE-2026-46165

https://www.suse.com/security/cve/CVE-2026-46167

https://www.suse.com/security/cve/CVE-2026-46174

https://www.suse.com/security/cve/CVE-2026-46177

https://www.suse.com/security/cve/CVE-2026-46178

https://www.suse.com/security/cve/CVE-2026-46180

https://www.suse.com/security/cve/CVE-2026-46184

https://www.suse.com/security/cve/CVE-2026-46189

https://www.suse.com/security/cve/CVE-2026-46191

https://www.suse.com/security/cve/CVE-2026-46193

https://www.suse.com/security/cve/CVE-2026-46220

https://www.suse.com/security/cve/CVE-2026-46243

https://www.suse.com/security/cve/CVE-2026-46245

https://www.suse.com/security/cve/CVE-2026-46252

https://www.suse.com/security/cve/CVE-2026-46294

https://www.suse.com/security/cve/CVE-2026-46307

https://www.suse.com/security/cve/CVE-2026-46321

https://www.suse.com/security/cve/CVE-2026-46322

https://www.suse.com/security/cve/CVE-2026-52910

https://www.suse.com/security/cve/CVE-2026-52915

https://www.suse.com/security/cve/CVE-2026-52927

https://www.suse.com/security/cve/CVE-2026-52930

https://www.suse.com/security/cve/CVE-2026-52942

https://www.suse.com/security/cve/CVE-2026-52948

https://www.suse.com/security/cve/CVE-2026-52956

https://www.suse.com/security/cve/CVE-2026-52958

https://www.suse.com/security/cve/CVE-2026-52981

https://www.suse.com/security/cve/CVE-2026-52982

https://www.suse.com/security/cve/CVE-2026-52984

https://www.suse.com/security/cve/CVE-2026-52986

https://www.suse.com/security/cve/CVE-2026-52995

https://www.suse.com/security/cve/CVE-2026-52998

https://www.suse.com/security/cve/CVE-2026-53002

https://www.suse.com/security/cve/CVE-2026-53004

https://www.suse.com/security/cve/CVE-2026-53006

https://www.suse.com/security/cve/CVE-2026-53016

https://www.suse.com/security/cve/CVE-2026-53021

https://www.suse.com/security/cve/CVE-2026-53036

https://www.suse.com/security/cve/CVE-2026-53039

https://www.suse.com/security/cve/CVE-2026-53060

https://www.suse.com/security/cve/CVE-2026-53062

https://www.suse.com/security/cve/CVE-2026-53063

https://www.suse.com/security/cve/CVE-2026-53064

https://www.suse.com/security/cve/CVE-2026-53080

https://www.suse.com/security/cve/CVE-2026-53093

https://www.suse.com/security/cve/CVE-2026-53107

https://www.suse.com/security/cve/CVE-2026-53129

https://www.suse.com/security/cve/CVE-2026-53131

https://www.suse.com/security/cve/CVE-2026-53134

https://www.suse.com/security/cve/CVE-2026-53146

https://www.suse.com/security/cve/CVE-2026-53147

https://www.suse.com/security/cve/CVE-2026-53149

https://www.suse.com/security/cve/CVE-2026-53167

https://www.suse.com/security/cve/CVE-2026-53176

https://www.suse.com/security/cve/CVE-2026-53181

https://www.suse.com/security/cve/CVE-2026-53186

https://www.suse.com/security/cve/CVE-2026-53196

https://www.suse.com/security/cve/CVE-2026-53208

https://www.suse.com/security/cve/CVE-2026-53213

https://www.suse.com/security/cve/CVE-2026-53218

https://www.suse.com/security/cve/CVE-2026-53224

https://www.suse.com/security/cve/CVE-2026-53225

https://www.suse.com/security/cve/CVE-2026-53227

https://www.suse.com/security/cve/CVE-2026-53236

https://www.suse.com/security/cve/CVE-2026-53242

https://www.suse.com/security/cve/CVE-2026-53245

https://www.suse.com/security/cve/CVE-2026-53246

https://www.suse.com/security/cve/CVE-2026-53249

https://www.suse.com/security/cve/CVE-2026-53252

https://www.suse.com/security/cve/CVE-2026-53254

https://www.suse.com/security/cve/CVE-2026-53255

https://www.suse.com/security/cve/CVE-2026-53256

https://www.suse.com/security/cve/CVE-2026-53262

https://www.suse.com/security/cve/CVE-2026-53267

https://www.suse.com/security/cve/CVE-2026-53268

https://www.suse.com/security/cve/CVE-2026-53270

https://www.suse.com/security/cve/CVE-2026-53273

https://www.suse.com/security/cve/CVE-2026-53275

https://www.suse.com/security/cve/CVE-2026-53306

https://www.suse.com/security/cve/CVE-2026-53325

https://www.suse.com/security/cve/CVE-2026-53354

https://www.suse.com/security/cve/CVE-2026-53355

https://www.suse.com/security/cve/CVE-2026-53359

https://www.suse.com/security/cve/CVE-2026-53369

https://www.suse.com/security/cve/CVE-2026-53374

https://www.suse.com/security/cve/CVE-2026-53375

https://www.suse.com/security/cve/CVE-2026-53376

https://www.suse.com/security/cve/CVE-2026-53388

https://www.suse.com/security/cve/CVE-2026-53391

https://www.suse.com/security/cve/CVE-2026-53392

https://www.suse.com/security/cve/CVE-2026-53397

https://www.suse.com/security/cve/CVE-2026-53399

https://www.suse.com/security/cve/CVE-2026-63794

https://www.suse.com/security/cve/CVE-2026-63806

https://www.suse.com/security/cve/CVE-2026-63826

https://www.suse.com/security/cve/CVE-2026-63829

https://www.suse.com/security/cve/CVE-2026-63893

https://www.suse.com/security/cve/CVE-2026-63899

https://www.suse.com/security/cve/CVE-2026-63901

https://www.suse.com/security/cve/CVE-2026-63915

https://www.suse.com/security/cve/CVE-2026-63922

https://www.suse.com/security/cve/CVE-2026-63924

https://www.suse.com/security/cve/CVE-2026-63927

https://www.suse.com/security/cve/CVE-2026-63928

https://www.suse.com/security/cve/CVE-2026-63958

https://www.suse.com/security/cve/CVE-2026-64298

https://www.suse.com/security/cve/CVE-2026-64330

https://www.suse.com/security/cve/CVE-2026-64465

https://www.suse.com/security/cve/CVE-2026-64564

https://www.suse.com/security/cve/CVE-2026-64600

http://www.nessus.org/u?56bbca1e

Plugin Details

Severity: High

ID: 335089

File Name: suse_SU-2026-3594-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

Percentile: 99.86

CVSS v2

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS2#AV:N/AC:L/Au:M/C:N/I:P/A:N

CVSS Score Source: CVE-2023-2058

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

CVSS Score Source: CVE-2026-63794

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 7.3

Threat Vector: CVSS:4.0/E:A

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2025-54518

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:cluster-md-kmp-default, p-cpe:/a:novell:suse_linux:dlm-kmp-default, p-cpe:/a:novell:suse_linux:gfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:kernel-default-kgraft, p-cpe:/a:novell:suse_linux:kernel-default-man, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kgraft-patch-4_12_14-122_323-default, p-cpe:/a:novell:suse_linux:ocfs2-kmp-default

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 4/14/2023

CISA Known Exploited Vulnerability Due Dates: 5/15/2026

Reference Information

CVE: CVE-2023-2058, CVE-2025-38250, CVE-2025-54518, CVE-2026-31431, CVE-2026-31450, CVE-2026-31510, CVE-2026-31598, CVE-2026-31624, CVE-2026-31628, CVE-2026-31678, CVE-2026-31759, CVE-2026-43033, CVE-2026-43068, CVE-2026-43069, CVE-2026-43123, CVE-2026-43124, CVE-2026-43156, CVE-2026-43168, CVE-2026-43180, CVE-2026-43211, CVE-2026-43216, CVE-2026-43226, CVE-2026-43230, CVE-2026-43244, CVE-2026-43253, CVE-2026-43255, CVE-2026-43266, CVE-2026-43268, CVE-2026-43273, CVE-2026-43281, CVE-2026-43287, CVE-2026-43308, CVE-2026-43309, CVE-2026-43313, CVE-2026-43370, CVE-2026-43373, CVE-2026-43383, CVE-2026-43425, CVE-2026-43427, CVE-2026-43445, CVE-2026-43449, CVE-2026-43450, CVE-2026-43451, CVE-2026-43452, CVE-2026-43466, CVE-2026-43493, CVE-2026-43496, CVE-2026-45857, CVE-2026-45858, CVE-2026-45871, CVE-2026-45877, CVE-2026-45899, CVE-2026-45905, CVE-2026-45915, CVE-2026-45917, CVE-2026-45920, CVE-2026-45923, CVE-2026-45981, CVE-2026-45985, CVE-2026-45994, CVE-2026-45997, CVE-2026-46018, CVE-2026-46023, CVE-2026-46027, CVE-2026-46033, CVE-2026-46040, CVE-2026-46049, CVE-2026-46051, CVE-2026-46056, CVE-2026-46064, CVE-2026-46068, CVE-2026-46080, CVE-2026-46086, CVE-2026-46088, CVE-2026-46102, CVE-2026-46109, CVE-2026-46146, CVE-2026-46149, CVE-2026-46161, CVE-2026-46165, CVE-2026-46167, CVE-2026-46174, CVE-2026-46177, CVE-2026-46178, CVE-2026-46180, CVE-2026-46184, CVE-2026-46189, CVE-2026-46191, CVE-2026-46193, CVE-2026-46220, CVE-2026-46243, CVE-2026-46245, CVE-2026-46252, CVE-2026-46294, CVE-2026-46307, CVE-2026-46321, CVE-2026-46322, CVE-2026-52910, CVE-2026-52915, CVE-2026-52927, CVE-2026-52930, CVE-2026-52942, CVE-2026-52948, CVE-2026-52956, CVE-2026-52958, CVE-2026-52981, CVE-2026-52982, CVE-2026-52984, CVE-2026-52986, CVE-2026-52995, CVE-2026-52998, CVE-2026-53002, CVE-2026-53004, CVE-2026-53006, CVE-2026-53016, CVE-2026-53021, CVE-2026-53036, CVE-2026-53039, CVE-2026-53060, CVE-2026-53062, CVE-2026-53063, CVE-2026-53064, CVE-2026-53080, CVE-2026-53093, CVE-2026-53107, CVE-2026-53129, CVE-2026-53131, CVE-2026-53134, CVE-2026-53146, CVE-2026-53147, CVE-2026-53149, CVE-2026-53167, CVE-2026-53176, CVE-2026-53181, CVE-2026-53186, CVE-2026-53196, CVE-2026-53208, CVE-2026-53213, CVE-2026-53218, CVE-2026-53224, CVE-2026-53225, CVE-2026-53227, CVE-2026-53236, CVE-2026-53242, CVE-2026-53245, CVE-2026-53246, CVE-2026-53249, CVE-2026-53252, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53262, CVE-2026-53267, CVE-2026-53268, CVE-2026-53270, CVE-2026-53273, CVE-2026-53275, CVE-2026-53306, CVE-2026-53325, CVE-2026-53354, CVE-2026-53355, CVE-2026-53359, CVE-2026-53369, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53388, CVE-2026-53391, CVE-2026-53392, CVE-2026-53397, CVE-2026-53399, CVE-2026-63794, CVE-2026-63806, CVE-2026-63826, CVE-2026-63829, CVE-2026-63893, CVE-2026-63899, CVE-2026-63901, CVE-2026-63915, CVE-2026-63922, CVE-2026-63924, CVE-2026-63927, CVE-2026-63928, CVE-2026-63958, CVE-2026-64298, CVE-2026-64330, CVE-2026-64465, CVE-2026-64564, CVE-2026-64600

SuSE: SUSE-SU-2026:3594-1