rpm package
suse/kernel-source-rt&distro=SUSE Real Time Module 15 SP6
pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP6
Vulnerabilities (3,740)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-39759 | Hig | 7.0 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free of qgroup records fro | |
| CVE-2025-39758 | Cri | 9.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_tcp_sendpages(struct socket *s, struct page | |
| CVE-2025-39757 | Hig | 7.1 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer s | |
| CVE-2025-39756 | Med | 5.5 | < 6.4.0-150600.10.58.1 | 6.4.0-150600.10.58.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very high value (for example, 1073741816 as set by systemd), processes attempting to use file descriptors near the | |
| CVE-2025-39754 | Med | 4.7 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm/smaps: fix race between smaps_hugetlb_range and migration smaps_hugetlb_range() handles the pte without holdling ptl, and may be concurrenct with migration, leaing to BUG_ON in pfn_swap_entry_to_page(). The | |
| CVE-2025-39750 | Hig | 8.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Correct tid cleanup when tid setup fails Currently, if any error occurs during ath12k_dp_rx_peer_tid_setup(), the tid value is already incremented, even though the corresponding TID is not actuall | |
| CVE-2025-39749 | Hig | 7.0 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked within an interrupts-disabled region of code [1], it will invoke rcu_read_unlock_spec | |
| CVE-2025-39746 | Med | 5.5 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when hardware is unreliable In rare cases, ath10k may lose connection with the PCIe bus due to some unknown reasons, which could further lead to system crashes during resuming due | |
| CVE-2025-39744 | Hig | 7.1 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work During rcu_read_unlock_special(), if this happens during irq_exit(), we can lockup if an IPI is issued. This is because the IPI itself triggers the irq_exit() | |
| CVE-2025-39743 | Hig | 7.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are | |
| CVE-2025-39742 | Med | 5.5 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by num_core_siblings, and later checks the divider by zero. This implies a possibility to get and divi | |
| CVE-2025-39739 | Med | 5.5 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Add the SM6115 MDSS compatible to clients compatible list, as it also needs that workaround. Without this workaround, for example, QRB4210 RB2 which is based on S | |
| CVE-2025-39738 | Hig | 7.3 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 11, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: item 85 key (594509824 169 0) itemoff | |
| CVE-2025-39732 | Hig | 7.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is | |
| CVE-2025-39730 | Hig | 7.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 7, 2025 | In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() The function needs to check the minimal filehandle length before it can access the embedded filehandle. | |
| CVE-2025-39726 | Cri | 9.8 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time. Unfortunately as of | |
| CVE-2025-39724 | Med | 5.5 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, the device generates an error response if an attempt is made to read an empty RBR (Receive Buffer Register) while the FIFO | |
| CVE-2025-39721 | Med | 5.5 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - flush misc workqueue during device shutdown Repeated loading and unloading of a device specific QAT driver, for example qat_4xxx, in a tight loop can lead to a crash due to a use-after-free scenar | |
| CVE-2025-39719 | Hig | 7.1 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access of the hw_xlate array in bno055.c. In bno055_get_regmask(), hw_xlate was iterated over the length of the vals array | |
| CVE-2025-39718 | Hig | 8.4 | < 6.4.0-150600.10.55.1 | 6.4.0-150600.10.55.1 | Sep 5, 2025 | In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue buffer size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately, virtio_ |
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: btrfs: qgroup: fix race between quota disable and quota rescan ioctl There's a race between a task disabling quotas and another running the rescan ioctl that can result in a use-after-free of qgroup records fro
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_tcp_sendpages(struct socket *s, struct page
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Validate UAC3 cluster segment descriptors UAC3 class segment descriptors need to be verified whether their sizes match with the declared lengths and whether they fit with the allocated buffer s
- affected < 6.4.0-150600.10.58.1fixed 6.4.0-150600.10.58.1
In the Linux kernel, the following vulnerability has been resolved: fs: Prevent file descriptor table allocations exceeding INT_MAX When sysctl_nr_open is set to a very high value (for example, 1073741816 as set by systemd), processes attempting to use file descriptors near the
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: mm/smaps: fix race between smaps_hugetlb_range and migration smaps_hugetlb_range() handles the pte without holdling ptl, and may be concurrenct with migration, leaing to BUG_ON in pfn_swap_entry_to_page(). The
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Correct tid cleanup when tid setup fails Currently, if any error occurs during ath12k_dp_rx_peer_tid_setup(), the tid value is already incremented, even though the corresponding TID is not actuall
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: rcu: Protect ->defer_qs_iw_pending from data race On kernels built with CONFIG_IRQ_WORK=y, when rcu_read_unlock() is invoked within an interrupts-disabled region of code [1], it will invoke rcu_read_unlock_spec
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: wifi: ath10k: shutdown driver when hardware is unreliable In rare cases, ath10k may lose connection with the PCIe bus due to some unknown reasons, which could further lead to system crashes during resuming due
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: rcu: Fix rcu_read_unlock() deadloop due to IRQ work During rcu_read_unlock_special(), if this happens during irq_exit(), we can lockup if an IPI is issued. This is because the IPI itself triggers the irq_exit()
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: jfs: truncate good inode pages when hard link is 0 The fileset value of the inode copy from the disk by the reproducer is AGGR_RESERVED_I. When executing evict, its hard link number is 0, so its inode pages are
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: RDMA: hfi1: fix possible divide-by-zero in find_hw_thread_mask() The function divides number of online CPUs by num_core_siblings, and later checks the divider by zero. This implies a possibility to get and divi
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-qcom: Add SM6115 MDSS compatible Add the SM6115 MDSS compatible to clients compatible list, as it also needs that workaround. Without this workaround, for example, QRB4210 RB2 which is based on S
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: btrfs: do not allow relocation of partially dropped subvolumes [BUG] There is an internal report that balance triggered transaction abort, with the following call trace: item 85 key (594509824 169 0) itemoff
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask() ath11k_mac_disable_peer_fixed_rate() is passed as the iterator to ieee80211_iterate_stations_atomic(). Note in this case the iterator is
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() The function needs to check the minimal filehandle length before it can access the embedded filehandle.
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: s390/ism: fix concurrency management in ism_cmd() The s390x ISM device data sheet clearly states that only one request-response sequence is allowable per ISM function at any point in time. Unfortunately as of
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: serial: 8250: fix panic due to PSLVERR When the PSLVERR_RESP_EN parameter is set to 1, the device generates an error response if an attempt is made to read an empty RBR (Receive Buffer Register) while the FIFO
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - flush misc workqueue during device shutdown Repeated loading and unloading of a device specific QAT driver, for example qat_4xxx, in a tight loop can lead to a crash due to a use-after-free scenar
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: iio: imu: bno055: fix OOB access of hw_xlate array Fix a potential out-of-bounds array access of the hw_xlate array in bno055.c. In bno055_get_regmask(), hw_xlate was iterated over the length of the vals array
- affected < 6.4.0-150600.10.55.1fixed 6.4.0-150600.10.55.1
In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: Validate length in packet header before skb_put() When receiving a vsock packet in the guest, only the virtqueue buffer size is validated prior to virtio_vsock_skb_rx_put(). Unfortunately, virtio_
Page 24 of 187