SUSE SLES15: cluster-md-kmp-default / dlm-kmp-default / gfs2-kmp-default / etc (SUSE-SU-2026:4369-1)

high Nessus Plugin ID 350940

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4369-1 advisory.

The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues:

The following security issues were fixed:

- CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731).
- CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225).
- CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604).
- CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072).
- CVE-2026-43147: Revert 'PCI/IOV: Add PCI rescan-remove locking when enabling/disabling SR-IOV' (bsc#1264642).
- CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734).
- CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023).
- CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659).
- CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).
- CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004).
- CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242).
- CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126).
- CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).
- CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985).
- CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
- CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).
- CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365).
- CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830).
- CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230).
- CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182).
- CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179).
- CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569).
- CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571).
- CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
- CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).
- CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).
- CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662).
- CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673).
- CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868).
- CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030).
- CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).
- CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).
- CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).
- CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).
- CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).
- CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766).
- CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484).
- CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488).
- CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).
- CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).
- CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).
- CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743).
- CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798).
- CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276).
- CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).
- CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968).
- CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422).
- CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426).
- CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541).
- CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539).
- CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543).
- CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545).
- CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).
- CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523).
- CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547).
- CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).
- CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311).
- CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).
- CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995).
- CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014).
- CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031).
- CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).
- CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497).
- CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
- CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474).
- CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941).
- CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304).
- CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307).
- CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470).
- CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472).
- CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
- CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).
- CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).
- CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696).
- CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705).
- CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).
- CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).
- CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528).
- CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155).
- CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535).
- CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540).
- CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523).
- CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).
- CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665).
- CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669).
- CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).
- CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678).
- CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886).
- CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905).
- CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925).
- CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006).
- CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
- CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285).
- CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).
- CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).
- CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088).
- CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408).
- CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).
- CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).
- CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).
- CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797).
- CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798).
- CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).
- CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696).
- CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782).
- CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784).
- CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277505).
- CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).
- CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931).
- CVE-2026-80722: wifi: mac80211: validate individual TWT params before driver setup (bsc#1277860).

The following non security issues were fixed:

- ibmvnic: Only record tx completed bytes once per handler (bsc#1274620).
- KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git-fixes).
- KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes).
- mkspec-dtb: Move DTS prefix into package list.
- mkspec-dtb: Move provides-obsoletes to package list.
- mkspec-dtb: Put per-architecture package lists into a hash.
- mkspec-dtb: re-indent.
- net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes).
- net: mana: Add handler for sriov configure (bsc#1272756).
- net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes).
- net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes).
- net: mana: Fall back to scattered pages for GDMA queues (git-fixes).
- net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792).
- net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792).
- net: mana: Route ring-buffer access through offset-based helpers (git-fixes).
- net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).
- PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git-fixes).
- powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290).
- RDMA/mana_ib: drain QP references after partial table insertion (git-fixes).
- RDMA/mana_ib: unify QP lookup table (git-fixes).
- scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes).
- smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).
- x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1230238

https://bugzilla.suse.com/1235944

https://bugzilla.suse.com/1247455

https://bugzilla.suse.com/1250748

https://bugzilla.suse.com/1251966

https://bugzilla.suse.com/1252682

https://bugzilla.suse.com/1254306

https://bugzilla.suse.com/1255225

https://bugzilla.suse.com/1255250

https://bugzilla.suse.com/1256708

https://bugzilla.suse.com/1257154

https://bugzilla.suse.com/1258430

https://bugzilla.suse.com/1258517

https://bugzilla.suse.com/1260522

https://bugzilla.suse.com/1261604

https://bugzilla.suse.com/1261780

https://bugzilla.suse.com/1263072

https://bugzilla.suse.com/1264642

https://bugzilla.suse.com/1264734

https://bugzilla.suse.com/1265449

https://bugzilla.suse.com/1265928

https://bugzilla.suse.com/1266402

https://bugzilla.suse.com/1267023

https://bugzilla.suse.com/1268659

https://bugzilla.suse.com/1269000

https://bugzilla.suse.com/1269004

https://bugzilla.suse.com/1269126

https://bugzilla.suse.com/1269238

https://bugzilla.suse.com/1269242

https://bugzilla.suse.com/1269306

https://bugzilla.suse.com/1269655

https://bugzilla.suse.com/1269731

https://bugzilla.suse.com/1269792

https://bugzilla.suse.com/1269981

https://bugzilla.suse.com/1269985

https://bugzilla.suse.com/1271365

https://bugzilla.suse.com/1271366

https://bugzilla.suse.com/1271825

https://bugzilla.suse.com/1271830

https://bugzilla.suse.com/1272179

https://bugzilla.suse.com/1272182

https://bugzilla.suse.com/1272230

https://bugzilla.suse.com/1272381

https://bugzilla.suse.com/1272385

https://bugzilla.suse.com/1272390

https://bugzilla.suse.com/1272569

https://bugzilla.suse.com/1272571

https://bugzilla.suse.com/1272662

https://bugzilla.suse.com/1272673

https://bugzilla.suse.com/1272680

https://bugzilla.suse.com/1272682

https://bugzilla.suse.com/1272756

https://bugzilla.suse.com/1272798

https://bugzilla.suse.com/1272868

https://bugzilla.suse.com/1272877

https://bugzilla.suse.com/1273030

https://bugzilla.suse.com/1273053

https://bugzilla.suse.com/1273054

https://bugzilla.suse.com/1273105

https://bugzilla.suse.com/1273276

https://bugzilla.suse.com/1273303

https://bugzilla.suse.com/1273311

https://bugzilla.suse.com/1273422

https://bugzilla.suse.com/1273426

https://bugzilla.suse.com/1273484

https://bugzilla.suse.com/1273488

https://bugzilla.suse.com/1273523

https://bugzilla.suse.com/1273555

https://bugzilla.suse.com/1273578

https://bugzilla.suse.com/1273742

https://bugzilla.suse.com/1273743

https://bugzilla.suse.com/1273745

https://bugzilla.suse.com/1273748

https://bugzilla.suse.com/1273762

https://bugzilla.suse.com/1273766

https://bugzilla.suse.com/1273774

https://bugzilla.suse.com/1273869

https://bugzilla.suse.com/1273882

https://bugzilla.suse.com/1273891

https://bugzilla.suse.com/1273903

https://bugzilla.suse.com/1273930

https://bugzilla.suse.com/1273944

https://bugzilla.suse.com/1273968

https://bugzilla.suse.com/1273995

https://bugzilla.suse.com/1274014

https://bugzilla.suse.com/1274031

https://bugzilla.suse.com/1274041

https://bugzilla.suse.com/1274208

https://bugzilla.suse.com/1274226

https://bugzilla.suse.com/1274274

https://bugzilla.suse.com/1274497

https://bugzilla.suse.com/1274539

https://bugzilla.suse.com/1274541

https://bugzilla.suse.com/1274543

https://bugzilla.suse.com/1274545

https://bugzilla.suse.com/1274547

https://bugzilla.suse.com/1274550

https://bugzilla.suse.com/1274620

https://bugzilla.suse.com/1274696

https://bugzilla.suse.com/1274699

https://bugzilla.suse.com/1274705

https://bugzilla.suse.com/1274752

https://bugzilla.suse.com/1274753

https://bugzilla.suse.com/1274754

https://bugzilla.suse.com/1274888

https://bugzilla.suse.com/1274898

https://bugzilla.suse.com/1274902

https://bugzilla.suse.com/1274908

https://bugzilla.suse.com/1274941

https://bugzilla.suse.com/1275161

https://bugzilla.suse.com/1275304

https://bugzilla.suse.com/1275307

https://bugzilla.suse.com/1275470

https://bugzilla.suse.com/1275472

https://bugzilla.suse.com/1275474

https://bugzilla.suse.com/1275506

https://bugzilla.suse.com/1275528

https://bugzilla.suse.com/1275535

https://bugzilla.suse.com/1275540

https://bugzilla.suse.com/1275555

https://bugzilla.suse.com/1275665

https://bugzilla.suse.com/1275669

https://bugzilla.suse.com/1275687

https://bugzilla.suse.com/1275696

https://bugzilla.suse.com/1275782

https://bugzilla.suse.com/1275784

https://bugzilla.suse.com/1275797

https://bugzilla.suse.com/1275798

https://bugzilla.suse.com/1275827

https://bugzilla.suse.com/1275867

https://bugzilla.suse.com/1275886

https://bugzilla.suse.com/1275905

https://bugzilla.suse.com/1275925

https://bugzilla.suse.com/1276006

https://bugzilla.suse.com/1276350

https://bugzilla.suse.com/1276665

https://bugzilla.suse.com/1276931

https://bugzilla.suse.com/1277073

https://bugzilla.suse.com/1277155

https://bugzilla.suse.com/1277254

https://bugzilla.suse.com/1277285

https://bugzilla.suse.com/1277391

https://bugzilla.suse.com/1277408

https://bugzilla.suse.com/1277505

https://bugzilla.suse.com/1277523

https://bugzilla.suse.com/1277571

https://bugzilla.suse.com/1277678

https://bugzilla.suse.com/1277860

https://bugzilla.suse.com/1278088

https://bugzilla.suse.com/1278233

https://bugzilla.suse.com/1278236

https://bugzilla.suse.com/1279813

https://www.suse.com/security/cve/CVE-2024-44981

https://www.suse.com/security/cve/CVE-2024-57841

https://www.suse.com/security/cve/CVE-2025-38469

https://www.suse.com/security/cve/CVE-2025-39964

https://www.suse.com/security/cve/CVE-2025-40022

https://www.suse.com/security/cve/CVE-2025-68179

https://www.suse.com/security/cve/CVE-2025-68214

https://www.suse.com/security/cve/CVE-2025-71104

https://www.suse.com/security/cve/CVE-2026-23210

https://www.suse.com/security/cve/CVE-2026-23230

https://www.suse.com/security/cve/CVE-2026-23451

https://www.suse.com/security/cve/CVE-2026-23454

https://www.suse.com/security/cve/CVE-2026-31502

https://www.suse.com/security/cve/CVE-2026-43147

https://www.suse.com/security/cve/CVE-2026-43456

https://www.suse.com/security/cve/CVE-2026-45968

https://www.suse.com/security/cve/CVE-2026-52910

https://www.suse.com/security/cve/CVE-2026-52912

https://www.suse.com/security/cve/CVE-2026-52929

https://www.suse.com/security/cve/CVE-2026-52977

https://www.suse.com/security/cve/CVE-2026-52994

https://www.suse.com/security/cve/CVE-2026-53059

https://www.suse.com/security/cve/CVE-2026-53110

https://www.suse.com/security/cve/CVE-2026-53163

https://www.suse.com/security/cve/CVE-2026-53260

https://www.suse.com/security/cve/CVE-2026-53264

https://www.suse.com/security/cve/CVE-2026-53365

https://www.suse.com/security/cve/CVE-2026-53366

https://www.suse.com/security/cve/CVE-2026-53381

https://www.suse.com/security/cve/CVE-2026-53388

https://www.suse.com/security/cve/CVE-2026-63801

https://www.suse.com/security/cve/CVE-2026-63823

https://www.suse.com/security/cve/CVE-2026-63827

https://www.suse.com/security/cve/CVE-2026-63879

https://www.suse.com/security/cve/CVE-2026-63881

https://www.suse.com/security/cve/CVE-2026-63886

https://www.suse.com/security/cve/CVE-2026-63887

https://www.suse.com/security/cve/CVE-2026-63888

https://www.suse.com/security/cve/CVE-2026-63920

https://www.suse.com/security/cve/CVE-2026-63944

https://www.suse.com/security/cve/CVE-2026-63970

https://www.suse.com/security/cve/CVE-2026-63972

https://www.suse.com/security/cve/CVE-2026-63973

https://www.suse.com/security/cve/CVE-2026-63992

https://www.suse.com/security/cve/CVE-2026-64000

https://www.suse.com/security/cve/CVE-2026-64002

https://www.suse.com/security/cve/CVE-2026-64007

https://www.suse.com/security/cve/CVE-2026-64010

https://www.suse.com/security/cve/CVE-2026-64011

https://www.suse.com/security/cve/CVE-2026-64015

https://www.suse.com/security/cve/CVE-2026-64018

https://www.suse.com/security/cve/CVE-2026-64029

https://www.suse.com/security/cve/CVE-2026-64034

https://www.suse.com/security/cve/CVE-2026-64048

https://www.suse.com/security/cve/CVE-2026-64098

https://www.suse.com/security/cve/CVE-2026-64109

https://www.suse.com/security/cve/CVE-2026-64114

https://www.suse.com/security/cve/CVE-2026-64115

https://www.suse.com/security/cve/CVE-2026-64121

https://www.suse.com/security/cve/CVE-2026-64217

https://www.suse.com/security/cve/CVE-2026-64247

https://www.suse.com/security/cve/CVE-2026-64266

https://www.suse.com/security/cve/CVE-2026-64268

https://www.suse.com/security/cve/CVE-2026-64304

https://www.suse.com/security/cve/CVE-2026-64312

https://www.suse.com/security/cve/CVE-2026-64355

https://www.suse.com/security/cve/CVE-2026-64383

https://www.suse.com/security/cve/CVE-2026-64384

https://www.suse.com/security/cve/CVE-2026-64385

https://www.suse.com/security/cve/CVE-2026-64386

https://www.suse.com/security/cve/CVE-2026-64387

https://www.suse.com/security/cve/CVE-2026-64423

https://www.suse.com/security/cve/CVE-2026-64450

https://www.suse.com/security/cve/CVE-2026-64481

https://www.suse.com/security/cve/CVE-2026-64524

https://www.suse.com/security/cve/CVE-2026-64527

https://www.suse.com/security/cve/CVE-2026-64541

https://www.suse.com/security/cve/CVE-2026-64543

https://www.suse.com/security/cve/CVE-2026-64562

https://www.suse.com/security/cve/CVE-2026-64563

https://www.suse.com/security/cve/CVE-2026-64572

https://www.suse.com/security/cve/CVE-2026-64577

https://www.suse.com/security/cve/CVE-2026-64581

https://www.suse.com/security/cve/CVE-2026-64593

https://www.suse.com/security/cve/CVE-2026-68121

https://www.suse.com/security/cve/CVE-2026-68133

https://www.suse.com/security/cve/CVE-2026-68136

https://www.suse.com/security/cve/CVE-2026-68138

https://www.suse.com/security/cve/CVE-2026-68155

https://www.suse.com/security/cve/CVE-2026-68158

https://www.suse.com/security/cve/CVE-2026-68159

https://www.suse.com/security/cve/CVE-2026-68160

https://www.suse.com/security/cve/CVE-2026-68202

https://www.suse.com/security/cve/CVE-2026-68397

https://www.suse.com/security/cve/CVE-2026-68398

https://www.suse.com/security/cve/CVE-2026-68417

https://www.suse.com/security/cve/CVE-2026-68426

https://www.suse.com/security/cve/CVE-2026-68428

https://www.suse.com/security/cve/CVE-2026-68480

https://www.suse.com/security/cve/CVE-2026-72020

https://www.suse.com/security/cve/CVE-2026-72069

https://www.suse.com/security/cve/CVE-2026-72072

https://www.suse.com/security/cve/CVE-2026-72083

https://www.suse.com/security/cve/CVE-2026-72084

https://www.suse.com/security/cve/CVE-2026-72123

https://www.suse.com/security/cve/CVE-2026-72135

https://www.suse.com/security/cve/CVE-2026-72221

https://www.suse.com/security/cve/CVE-2026-72222

https://www.suse.com/security/cve/CVE-2026-72251

https://www.suse.com/security/cve/CVE-2026-72262

https://www.suse.com/security/cve/CVE-2026-72288

https://www.suse.com/security/cve/CVE-2026-72289

https://www.suse.com/security/cve/CVE-2026-72317

https://www.suse.com/security/cve/CVE-2026-72339

https://www.suse.com/security/cve/CVE-2026-72389

https://www.suse.com/security/cve/CVE-2026-74345

https://www.suse.com/security/cve/CVE-2026-74377

https://www.suse.com/security/cve/CVE-2026-74378

https://www.suse.com/security/cve/CVE-2026-74390

https://www.suse.com/security/cve/CVE-2026-74394

https://www.suse.com/security/cve/CVE-2026-74454

https://www.suse.com/security/cve/CVE-2026-74488

https://www.suse.com/security/cve/CVE-2026-74496

https://www.suse.com/security/cve/CVE-2026-74516

https://www.suse.com/security/cve/CVE-2026-74518

https://www.suse.com/security/cve/CVE-2026-74537

https://www.suse.com/security/cve/CVE-2026-74556

https://www.suse.com/security/cve/CVE-2026-74581

https://www.suse.com/security/cve/CVE-2026-74582

https://www.suse.com/security/cve/CVE-2026-74612

https://www.suse.com/security/cve/CVE-2026-74669

https://www.suse.com/security/cve/CVE-2026-74695

https://www.suse.com/security/cve/CVE-2026-80722

http://www.nessus.org/u?7b69071d

Plugin Details

Severity: High

ID: 350940

File Name: suse_SU-2026-4369-1.nasl

Version: 1.2

Type: Local

Agent: unix

Published: 9/29/2026

Updated: 9/30/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.35

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-53059

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.2

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:cluster-md-kmp-default, p-cpe:/a:novell:suse_linux:dlm-kmp-default, p-cpe:/a:novell:suse_linux:gfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-64kb, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:kernel-default-livepatch, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-livepatch-6_4_0-150600_23_135-default, p-cpe:/a:novell:suse_linux:kernel-obs-build, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kernel-zfcpdump, p-cpe:/a:novell:suse_linux:ocfs2-kmp-default, p-cpe:/a:novell:suse_linux:reiserfs-kmp-default

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/28/2026

Vulnerability Publication Date: 9/4/2024

CISA Known Exploited Vulnerability Due Dates: 9/21/2026

Exploitable With

Core Impact

Reference Information

CVE: CVE-2024-44981, CVE-2024-57841, CVE-2025-38469, CVE-2025-39964, CVE-2025-40022, CVE-2025-68179, CVE-2025-68214, CVE-2025-71104, CVE-2026-23210, CVE-2026-23230, CVE-2026-23451, CVE-2026-23454, CVE-2026-31502, CVE-2026-43147, CVE-2026-43456, CVE-2026-45968, CVE-2026-52910, CVE-2026-52912, CVE-2026-52929, CVE-2026-52977, CVE-2026-52994, CVE-2026-53059, CVE-2026-53110, CVE-2026-53163, CVE-2026-53260, CVE-2026-53264, CVE-2026-53365, CVE-2026-53366, CVE-2026-53381, CVE-2026-53388, CVE-2026-63801, CVE-2026-63823, CVE-2026-63827, CVE-2026-63879, CVE-2026-63881, CVE-2026-63886, CVE-2026-63887, CVE-2026-63888, CVE-2026-63920, CVE-2026-63944, CVE-2026-63970, CVE-2026-63972, CVE-2026-63973, CVE-2026-63992, CVE-2026-64000, CVE-2026-64002, CVE-2026-64007, CVE-2026-64010, CVE-2026-64011, CVE-2026-64015, CVE-2026-64018, CVE-2026-64029, CVE-2026-64034, CVE-2026-64048, CVE-2026-64098, CVE-2026-64109, CVE-2026-64114, CVE-2026-64115, CVE-2026-64121, CVE-2026-64217, CVE-2026-64247, CVE-2026-64266, CVE-2026-64268, CVE-2026-64304, CVE-2026-64312, CVE-2026-64355, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64423, CVE-2026-64450, CVE-2026-64481, CVE-2026-64524, CVE-2026-64527, CVE-2026-64541, CVE-2026-64543, CVE-2026-64562, CVE-2026-64563, CVE-2026-64572, CVE-2026-64577, CVE-2026-64581, CVE-2026-64593, CVE-2026-68121, CVE-2026-68133, CVE-2026-68136, CVE-2026-68138, CVE-2026-68155, CVE-2026-68158, CVE-2026-68159, CVE-2026-68160, CVE-2026-68202, CVE-2026-68397, CVE-2026-68398, CVE-2026-68417, CVE-2026-68426, CVE-2026-68428, CVE-2026-68480, CVE-2026-72020, CVE-2026-72069, CVE-2026-72072, CVE-2026-72083, CVE-2026-72084, CVE-2026-72123, CVE-2026-72135, CVE-2026-72221, CVE-2026-72222, CVE-2026-72251, CVE-2026-72262, CVE-2026-72288, CVE-2026-72289, CVE-2026-72317, CVE-2026-72339, CVE-2026-72389, CVE-2026-74345, CVE-2026-74377, CVE-2026-74378, CVE-2026-74390, CVE-2026-74394, CVE-2026-74454, CVE-2026-74488, CVE-2026-74496, CVE-2026-74516, CVE-2026-74518, CVE-2026-74537, CVE-2026-74556, CVE-2026-74581, CVE-2026-74582, CVE-2026-74612, CVE-2026-74669, CVE-2026-74695, CVE-2026-80722

SuSE: SUSE-SU-2026:4369-1