SUSE-SU-2026%3A21075-1
This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: - CVE-2025-39973: i40e: add validation for ring_len param (bsc#1252036). - CVE-2025-40018: ipvs: Defer ip_vs_ftp unregister during netns cleanup (bsc#1252689). - CVE-2025-40159: xsk: Harden userspace-supplied xdp_desc validation (bsc#1253404). - CVE-2025-71120: SUNRPC: svcauth_gss: avoid NULL deref on zero length gss_token in gss_read_proxy_verf (bsc#1256780). - CVE-2026-22999: net/sched: sch_qfq: do not free existing class in qfq_change_class() (bsc#1257238). - CVE-2026-23074: net/sched: Enforce that teql can only be used as root qdisc (bsc#1258051). - CVE-2026-23111: netfilter: nf_tables: fix inverted genmask check in nft_map_catchall_activate() (bsc#1258183). - CVE-2026-23209: macvlan: fix error recovery in macvlan_common_newlink() (bsc#1258784).
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE:Linux Micro 6.0 | kernel-livepatch-MICRO-6-0_Update_10 | 0, 0 |
Timeline
- Apr 9, 2026 CVE Published
- Apr 14, 2026 CVE Updated
References
- https://bugzilla.suse.com/1253404 report
- https://bugzilla.suse.com/1256780 report
- https://bugzilla.suse.com/1258051 report
- https://bugzilla.suse.com/1258784 report
- https://www.suse.com/security/cve/CVE-2025-39973 url
- https://www.suse.com/security/cve/CVE-2025-40018 url
- https://www.suse.com/security/cve/CVE-2026-22999 url
- https://www.suse.com/security/cve/CVE-2026-23111 url
- https://www.suse.com/support/update/announcement/2026/suse-su-202621075-1/ advisory
- https://bugzilla.suse.com/1252036 report
- https://bugzilla.suse.com/1252689 report
- https://bugzilla.suse.com/1257238 report
- https://bugzilla.suse.com/1258183 report
- https://www.suse.com/security/cve/CVE-2025-40159 url
- https://www.suse.com/security/cve/CVE-2025-71120 url
- https://www.suse.com/security/cve/CVE-2026-23074 url
- https://www.suse.com/security/cve/CVE-2026-23209 url