ESSA-2026:0024
Vulnerability from csaf_opensuse - Published: 2026-02-02 10:30 - Updated: 2026-09-17 12:33Summary
kernel security update
Severity
Moderate
Notes
Title of the patch: kernel security update
Description of the patch: [3.10.0-1160.119.1.0.15]- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() {CVE-2022-3640} [Orabug: 38742878]- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put [Orabug: 38742878]- Bluetooth: L2CAP: Fix user-after-free {CVE-2022-50386} [Orabug: 38742878]- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() {CVE-2022-50408} [Orabug: 38742878]- Bluetooth: L2CAP: Fix use-after-free {CVE-2023-53305} [Orabug: 38742878]- ip6mr: Fix skb_under_panic in ip6mr_cache_report() {CVE-2023-53365} [Orabug: 38742878]- sctp: linearize cloned gso packets in sctp_rcv {CVE-2025-38718} [Orabug: 38742878][3.10.0-1160.119.1.0.14]- HID: core: fix shift-out-of-bounds in hid_report_raw_event {CVE-2022-48978} [Orabug: 38644370]- crypto: seqiv - Handle EBUSY correctly {CVE-2023-53373} [Orabug: 38644370]- nfsd: don't ignore the return code of svc_proc_register() {CVE-2025-22026} [Orabug: 38644370]- net_sched: hfsc: Fix a UAF vulnerability in class handling {CVE-2025-37797} [Orabug: 38644370]- HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} [Orabug: 38644370]- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control {CVE-2025-39751} [Orabug: 38644370][3.10.0-1160.119.1.0.13]- ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() {CVE-2022-48701} [Orabug: 38493400]- md-raid10: fix KASAN warning {CVE-2022-50211} [Orabug: 38493400]- ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50229} [Orabug: 38493400]- net: usb: smsc75xx: Limit packet length to skb->len {CVE-2023-53125} [Orabug: 38493400]- i40e: fix MMIO write access to an invalid page in i40e_clear_hw {CVE-2025-38200} [Orabug: 38493400]- net/sched: sch_qfq: Fix race condition on qfq_aggregate {CVE-2025-38477} [Orabug: 38493400][3.10.0-1160.119.1.0.12]- scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) [Orabug: 38414589]- posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CVE-2025-38352) [Orabug: 38414589][3.10.0-1160.119.1.0.11]- kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)- kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CVE-2025-21928)- kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)- kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)- kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000)- kernel: ext4: avoid resizing to a partial cluster size (CVE-2022-50020)- kernel: drivers:md:fix a potential use-after-free bug (CVE-2022-50022)- kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-38177)- kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350)- crypto: algif_hash - fix double free in hash_accept (CVE-2025-38079)[3.10.0-1160.119.1.0.10]- net: atlantic: fix aq_vec index out of range error (Chia-Lin Kao) {CVE-2022-50066} [Orabug: 38201271]- net: atm: fix use after free in lec_send() (Dan Carpenter) {CVE-2025-22004} [Orabug: 38201271][3.10.0-1160.119.1.0.9]- netfilter: ipset: add missing range check in bitmap_ip_uadt (Jeongjun Park) {CVE-2024-53141} [Orabug: 37964173]- Update OL SB certificates- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985797][3.10.0-1160.119.1.0.8]- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (Takashi Iwai) {CVE-2024-53150} [Orabug: 37830084][3.10.0-1160.119.1.0.7]- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Benoit Sevens) {CVE-2024-53197} [Orabug: 37686305]- can: bcm: Fix UAF in bcm_proc_show() (YueHaibing) {CVE-2023-52922} [Orabug: 37686305]- HID: core: zero-initialize the report buffer (Benoit Sevens) {CVE-2024-50302} [Orabug: 37686305][3.10.0-1160.119.1.0.6]- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (Benoit Sevens) {CVE-2024-53104} [Orabug: 37584712]
Patchnames: ESSA-2026:0024
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
7.1 (High)
Affected products
Recommended
13 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64 | — |
Vendor Fix
|
Threats
Impact
important
5.5 (Medium)
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
moderate
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
important
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
important
5.5 (Medium)
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
moderate
5.5 (Medium)
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
moderate
5.5 (Medium)
Affected products
Recommended
13 products, the same list as for
CVE-2022-3640
Threats
Impact
moderate
References
31 references
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "Moderate"
},
"category": "csaf_security_advisory",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "kernel security update",
"title": "Title of the patch"
},
{
"category": "description",
"text": "[3.10.0-1160.119.1.0.15]- Bluetooth: L2CAP: fix use-after-free in l2cap_conn_del() {CVE-2022-3640} [Orabug: 38742878]- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_chan_put [Orabug: 38742878]- Bluetooth: L2CAP: Fix user-after-free {CVE-2022-50386} [Orabug: 38742878]- wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() {CVE-2022-50408} [Orabug: 38742878]- Bluetooth: L2CAP: Fix use-after-free {CVE-2023-53305} [Orabug: 38742878]- ip6mr: Fix skb_under_panic in ip6mr_cache_report() {CVE-2023-53365} [Orabug: 38742878]- sctp: linearize cloned gso packets in sctp_rcv {CVE-2025-38718} [Orabug: 38742878][3.10.0-1160.119.1.0.14]- HID: core: fix shift-out-of-bounds in hid_report_raw_event {CVE-2022-48978} [Orabug: 38644370]- crypto: seqiv - Handle EBUSY correctly {CVE-2023-53373} [Orabug: 38644370]- nfsd: don\u0027t ignore the return code of svc_proc_register() {CVE-2025-22026} [Orabug: 38644370]- net_sched: hfsc: Fix a UAF vulnerability in class handling {CVE-2025-37797} [Orabug: 38644370]- HID: core: Harden s32ton() against conversion to 0 bits {CVE-2025-38556} [Orabug: 38644370]- ALSA: hda/ca0132: Fix buffer overflow in add_tuning_control {CVE-2025-39751} [Orabug: 38644370][3.10.0-1160.119.1.0.13]- ALSA: usb-audio: Fix an out-of-bounds bug in __snd_usb_parse_audio_interface() {CVE-2022-48701} [Orabug: 38493400]- md-raid10: fix KASAN warning {CVE-2022-50211} [Orabug: 38493400]- ALSA: bcd2000: Fix a UAF bug on the error path of probing {CVE-2022-50229} [Orabug: 38493400]- net: usb: smsc75xx: Limit packet length to skb-\u003elen {CVE-2023-53125} [Orabug: 38493400]- i40e: fix MMIO write access to an invalid page in i40e_clear_hw {CVE-2025-38200} [Orabug: 38493400]- net/sched: sch_qfq: Fix race condition on qfq_aggregate {CVE-2025-38477} [Orabug: 38493400][3.10.0-1160.119.1.0.12]- scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) [Orabug: 38414589]- posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() (CVE-2025-38352) [Orabug: 38414589][3.10.0-1160.119.1.0.11]- kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980)- kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() (CVE-2025-21928)- kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150)- kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788)- kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000)- kernel: ext4: avoid resizing to a partial cluster size (CVE-2022-50020)- kernel: drivers:md:fix a potential use-after-free bug (CVE-2022-50022)- kernel: sch_hfsc: make hfsc_qlen_notify() idempotent (CVE-2025-38177)- kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350)- crypto: algif_hash - fix double free in hash_accept (CVE-2025-38079)[3.10.0-1160.119.1.0.10]- net: atlantic: fix aq_vec index out of range error (Chia-Lin Kao) {CVE-2022-50066} [Orabug: 38201271]- net: atm: fix use after free in lec_send() (Dan Carpenter) {CVE-2025-22004} [Orabug: 38201271][3.10.0-1160.119.1.0.9]- netfilter: ipset: add missing range check in bitmap_ip_uadt (Jeongjun Park) {CVE-2024-53141} [Orabug: 37964173]- Update OL SB certificates- Add new Oracle Linux Driver Signing (key 1) certificate [Orabug: 37985797][3.10.0-1160.119.1.0.8]- ALSA: usb-audio: Fix out of bounds reads when finding clock sources (Takashi Iwai) {CVE-2024-53150} [Orabug: 37830084][3.10.0-1160.119.1.0.7]- ALSA: usb-audio: Fix potential out-of-bound accesses for Extigy and Mbox devices (Benoit Sevens) {CVE-2024-53197} [Orabug: 37686305]- can: bcm: Fix UAF in bcm_proc_show() (YueHaibing) {CVE-2023-52922} [Orabug: 37686305]- HID: core: zero-initialize the report buffer (Benoit Sevens) {CVE-2024-50302} [Orabug: 37686305][3.10.0-1160.119.1.0.6]- media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format (Benoit Sevens) {CVE-2024-53104} [Orabug: 37584712]",
"title": "Description of the patch"
},
{
"category": "details",
"text": "ESSA-2026:0024",
"title": "Patchnames"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "SUSE ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "self",
"summary": "URL of this CSAF notice",
"url": "https://ftp.suse.com/pub/projects/security/csaf/essa-2026_0024.json"
},
{
"category": "self",
"summary": "URL for ESSA-2026:0024",
"url": "https://lists.suse.com/pipermail/suse-liberty-linux-updates/2026-February/002461.html"
},
{
"category": "self",
"summary": "E-Mail link for ESSA-2026:0024",
"url": "https://lists.suse.com/pipermail/suse-liberty-linux-updates/2026-February/002461.html"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2022-3640 page",
"url": "https://www.suse.com/security/cve/CVE-2022-3640/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2022-50341 page",
"url": "https://www.suse.com/security/cve/CVE-2022-50341/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2022-50386 page",
"url": "https://www.suse.com/security/cve/CVE-2022-50386/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2022-50408 page",
"url": "https://www.suse.com/security/cve/CVE-2022-50408/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2023-53305 page",
"url": "https://www.suse.com/security/cve/CVE-2023-53305/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2023-53365 page",
"url": "https://www.suse.com/security/cve/CVE-2023-53365/"
},
{
"category": "self",
"summary": "SUSE CVE CVE-2025-38718 page",
"url": "https://www.suse.com/security/cve/CVE-2025-38718/"
}
],
"title": "kernel security update",
"tracking": {
"current_release_date": "2026-09-17T12:33:29Z",
"generator": {
"date": "2026-02-02T10:30:16Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf.pl",
"version": "1"
}
},
"id": "ESSA-2026:0024",
"initial_release_date": "2026-02-02T10:30:16Z",
"revision_history": [
{
"date": "2026-02-02T10:30:16Z",
"number": "1",
"summary": "Current version"
},
{
"date": "2026-09-16T16:05:36Z",
"number": "2",
"summary": "unknown changes"
},
{
"date": "2026-09-16T17:56:44Z",
"number": "3",
"summary": "unknown changes"
},
{
"date": "2026-09-16T18:11:18Z",
"number": "4",
"summary": "unknown changes"
},
{
"date": "2026-09-17T12:33:29Z",
"number": "5",
"summary": "unknown changes"
}
],
"status": "final",
"version": "5"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product": {
"name": "kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product_id": "kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-abi-whitelists@3.10.0-1160.125.1.0.15.el7?arch=noarch"
}
}
},
{
"category": "product_version",
"name": "kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product": {
"name": "kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product_id": "kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-doc@3.10.0-1160.125.1.0.15.el7?arch=noarch"
}
}
}
],
"category": "architecture",
"name": "noarch"
},
{
"branches": [
{
"category": "product_version",
"name": "bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/bpftool@3.10.0-1160.125.1.0.15.el7?arch=x86_64\u0026upstream=bpftool-0:3.10.0-1160.125.1.0.15.el7.src.rpm"
}
}
},
{
"category": "product_version",
"name": "kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
},
{
"category": "product_version",
"name": "kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:linux:linux_kernel:3.10.0:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/kernel-debug@3.10.0-1160.125.1.0.15.el7?arch=x86_64\u0026upstream=kernel-debug-0:3.10.0-1160.125.1.0.15.el7.src.rpm"
}
}
},
{
"category": "product_version",
"name": "kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"cpe": "cpe:2.3:a:linux:linux_kernel:3.10.0:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/kernel-debug-devel@3.10.0-1160.125.1.0.15.el7?arch=x86_64\u0026upstream=kernel-debug-0:3.10.0-1160.125.1.0.15.el7.src.rpm"
}
}
},
{
"category": "product_version",
"name": "kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"cpe": "cpe:2.3:o:linux:linux_kernel:3.10.0:*:*:*:*:*:*:*",
"purl": "pkg:rpm/suse/kernel-devel@3.10.0-1160.125.1.0.15.el7?arch=x86_64\u0026upstream=kernel-source-0:3.10.0-1160.125.1.0.15.el7.src.rpm"
}
}
},
{
"category": "product_version",
"name": "kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-headers@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
},
{
"category": "product_version",
"name": "kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-tools@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
},
{
"category": "product_version",
"name": "kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-tools-libs@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
},
{
"category": "product_version",
"name": "kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/kernel-tools-libs-devel@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
},
{
"category": "product_version",
"name": "perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/perf@3.10.0-1160.125.1.0.15.el7?arch=x86_64\u0026upstream=perf-0:3.10.0-1160.125.1.0.15.el7.src.rpm"
}
}
},
{
"category": "product_version",
"name": "python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product": {
"name": "python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_id": "python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"product_identification_helper": {
"purl": "pkg:rpm/suse/python-perf@3.10.0-1160.125.1.0.15.el7?arch=x86_64"
}
}
}
],
"category": "architecture",
"name": "x86_64"
},
{
"branches": [
{
"category": "product_name",
"name": "SUSE Liberty Linux 7 LTSS",
"product": {
"name": "SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS"
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch"
},
"product_reference": "kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch"
},
"product_reference": "kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "perf-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64 as component of SUSE Liberty Linux 7 LTSS",
"product_id": "SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
},
"product_reference": "python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"relates_to_product_reference": "SUSE Liberty Linux 7 LTSS"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2022-3640",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2022-3640"
}
],
"notes": [
{
"category": "general",
"text": "A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2022-3640",
"url": "https://www.suse.com/security/cve/CVE-2022-3640"
},
{
"category": "external",
"summary": "SUSE Bug 1204619 for CVE-2022-3640",
"url": "https://bugzilla.suse.com/1204619"
},
{
"category": "external",
"summary": "SUSE Bug 1204624 for CVE-2022-3640",
"url": "https://bugzilla.suse.com/1204624"
},
{
"category": "external",
"summary": "SUSE Bug 1209225 for CVE-2022-3640",
"url": "https://bugzilla.suse.com/1209225"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7.1,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "important"
}
],
"title": "CVE-2022-3640"
},
{
"cve": "CVE-2022-50341",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2022-50341"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix oops during encryption\n\nWhen running xfstests against Azure the following oops occurred on an\narm64 system\n\n Unable to handle kernel write to read-only memory at virtual address\n ffff0001221cf000\n Mem abort info:\n ESR = 0x9600004f\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x0f: level 3 permission fault\n Data abort info:\n ISV = 0, ISS = 0x0000004f\n CM = 0, WnR = 1\n swapper pgtable: 4k pages, 48-bit VAs, pgdp=00000000294f3000\n [ffff0001221cf000] pgd=18000001ffff8003, p4d=18000001ffff8003,\n pud=18000001ff82e003, pmd=18000001ff71d003, pte=00600001221cf787\n Internal error: Oops: 9600004f [#1] PREEMPT SMP\n ...\n pstate: 80000005 (Nzcv daif -PAN -UAO -TCO BTYPE=--)\n pc : __memcpy+0x40/0x230\n lr : scatterwalk_copychunks+0xe0/0x200\n sp : ffff800014e92de0\n x29: ffff800014e92de0 x28: ffff000114f9de80 x27: 0000000000000008\n x26: 0000000000000008 x25: ffff800014e92e78 x24: 0000000000000008\n x23: 0000000000000001 x22: 0000040000000000 x21: ffff000000000000\n x20: 0000000000000001 x19: ffff0001037c4488 x18: 0000000000000014\n x17: 235e1c0d6efa9661 x16: a435f9576b6edd6c x15: 0000000000000058\n x14: 0000000000000001 x13: 0000000000000008 x12: ffff000114f2e590\n x11: ffffffffffffffff x10: 0000040000000000 x9 : ffff8000105c3580\n x8 : 2e9413b10000001a x7 : 534b4410fb86b005 x6 : 534b4410fb86b005\n x5 : ffff0001221cf008 x4 : ffff0001037c4490 x3 : 0000000000000001\n x2 : 0000000000000008 x1 : ffff0001037c4488 x0 : ffff0001221cf000\n Call trace:\n __memcpy+0x40/0x230\n scatterwalk_map_and_copy+0x98/0x100\n crypto_ccm_encrypt+0x150/0x180\n crypto_aead_encrypt+0x2c/0x40\n crypt_message+0x750/0x880\n smb3_init_transform_rq+0x298/0x340\n smb_send_rqst.part.11+0xd8/0x180\n smb_send_rqst+0x3c/0x100\n compound_send_recv+0x534/0xbc0\n smb2_query_info_compound+0x32c/0x440\n smb2_set_ea+0x438/0x4c0\n cifs_xattr_set+0x5d4/0x7c0\n\nThis is because in scatterwalk_copychunks(), we attempted to write to\na buffer (@sign) that was allocated in the stack (vmalloc area) by\ncrypt_message() and thus accessing its remaining 8 (x2) bytes ended up\ncrossing a page boundary.\n\nTo simply fix it, we could just pass @sign kmalloc\u0027d from\ncrypt_message() and then we\u0027re done. Luckily, we don\u0027t seem to pass\nany other vmalloc\u0027d buffers in smb_rqst::rq_iov...\n\nInstead, let\u0027s map the correct pages and offsets from vmalloc buffers\nas well in cifs_sg_set_buf() and then avoiding such oopses.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2022-50341",
"url": "https://www.suse.com/security/cve/CVE-2022-50341"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "moderate"
}
],
"title": "CVE-2022-50341"
},
{
"cve": "CVE-2022-50386",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2022-50386"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix user-after-free\n\nThis uses l2cap_chan_hold_unless_zero() after calling\n__l2cap_get_chan_blah() to prevent the following trace:\n\nBluetooth: l2cap_core.c:static void l2cap_chan_destroy(struct kref\n*kref)\nBluetooth: chan 0000000023c4974d\nBluetooth: parent 00000000ae861c08\n==================================================================\nBUG: KASAN: use-after-free in __mutex_waiter_is_first\nkernel/locking/mutex.c:191 [inline]\nBUG: KASAN: use-after-free in __mutex_lock_common\nkernel/locking/mutex.c:671 [inline]\nBUG: KASAN: use-after-free in __mutex_lock+0x278/0x400\nkernel/locking/mutex.c:729\nRead of size 8 at addr ffff888006a49b08 by task kworker/u3:2/389",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2022-50386",
"url": "https://www.suse.com/security/cve/CVE-2022-50386"
},
{
"category": "external",
"summary": "SUSE Bug 1247374 for CVE-2022-50386",
"url": "https://bugzilla.suse.com/1247374"
},
{
"category": "external",
"summary": "SUSE Bug 1250301 for CVE-2022-50386",
"url": "https://bugzilla.suse.com/1250301"
},
{
"category": "external",
"summary": "SUSE Bug 1250302 for CVE-2022-50386",
"url": "https://bugzilla.suse.com/1250302"
},
{
"category": "external",
"summary": "SUSE Bug 1253291 for CVE-2022-50386",
"url": "https://bugzilla.suse.com/1253291"
},
{
"category": "external",
"summary": "SUSE Bug 1253292 for CVE-2022-50386",
"url": "https://bugzilla.suse.com/1253292"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "important"
}
],
"title": "CVE-2022-50386"
},
{
"cve": "CVE-2022-50408",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2022-50408"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()\n\n\u003e ret = brcmf_proto_tx_queue_data(drvr, ifp-\u003eifidx, skb);\n\nmay be schedule, and then complete before the line\n\n\u003e ndev-\u003estats.tx_bytes += skb-\u003elen;\n\n[ 46.912801] ==================================================================\n[ 46.920552] BUG: KASAN: use-after-free in brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac]\n[ 46.928673] Read of size 4 at addr ffffff803f5882e8 by task systemd-resolve/328\n[ 46.935991]\n[ 46.937514] CPU: 1 PID: 328 Comm: systemd-resolve Tainted: G O 5.4.199-[REDACTED] #1\n[ 46.947255] Hardware name: [REDACTED]\n[ 46.954568] Call trace:\n[ 46.957037] dump_backtrace+0x0/0x2b8\n[ 46.960719] show_stack+0x24/0x30\n[ 46.964052] dump_stack+0x128/0x194\n[ 46.967557] print_address_description.isra.0+0x64/0x380\n[ 46.972877] __kasan_report+0x1d4/0x240\n[ 46.976723] kasan_report+0xc/0x18\n[ 46.980138] __asan_report_load4_noabort+0x18/0x20\n[ 46.985027] brcmf_netdev_start_xmit+0x718/0x8c8 [brcmfmac]\n[ 46.990613] dev_hard_start_xmit+0x1bc/0xda0\n[ 46.994894] sch_direct_xmit+0x198/0xd08\n[ 46.998827] __qdisc_run+0x37c/0x1dc0\n[ 47.002500] __dev_queue_xmit+0x1528/0x21f8\n[ 47.006692] dev_queue_xmit+0x24/0x30\n[ 47.010366] neigh_resolve_output+0x37c/0x678\n[ 47.014734] ip_finish_output2+0x598/0x2458\n[ 47.018927] __ip_finish_output+0x300/0x730\n[ 47.023118] ip_output+0x2e0/0x430\n[ 47.026530] ip_local_out+0x90/0x140\n[ 47.030117] igmpv3_sendpack+0x14c/0x228\n[ 47.034049] igmpv3_send_cr+0x384/0x6b8\n[ 47.037895] igmp_ifc_timer_expire+0x4c/0x118\n[ 47.042262] call_timer_fn+0x1cc/0xbe8\n[ 47.046021] __run_timers+0x4d8/0xb28\n[ 47.049693] run_timer_softirq+0x24/0x40\n[ 47.053626] __do_softirq+0x2c0/0x117c\n[ 47.057387] irq_exit+0x2dc/0x388\n[ 47.060715] __handle_domain_irq+0xb4/0x158\n[ 47.064908] gic_handle_irq+0x58/0xb0\n[ 47.068581] el0_irq_naked+0x50/0x5c\n[ 47.072162]\n[ 47.073665] Allocated by task 328:\n[ 47.077083] save_stack+0x24/0xb0\n[ 47.080410] __kasan_kmalloc.isra.0+0xc0/0xe0\n[ 47.084776] kasan_slab_alloc+0x14/0x20\n[ 47.088622] kmem_cache_alloc+0x15c/0x468\n[ 47.092643] __alloc_skb+0xa4/0x498\n[ 47.096142] igmpv3_newpack+0x158/0xd78\n[ 47.099987] add_grhead+0x210/0x288\n[ 47.103485] add_grec+0x6b0/0xb70\n[ 47.106811] igmpv3_send_cr+0x2e0/0x6b8\n[ 47.110657] igmp_ifc_timer_expire+0x4c/0x118\n[ 47.115027] call_timer_fn+0x1cc/0xbe8\n[ 47.118785] __run_timers+0x4d8/0xb28\n[ 47.122457] run_timer_softirq+0x24/0x40\n[ 47.126389] __do_softirq+0x2c0/0x117c\n[ 47.130142]\n[ 47.131643] Freed by task 180:\n[ 47.134712] save_stack+0x24/0xb0\n[ 47.138041] __kasan_slab_free+0x108/0x180\n[ 47.142146] kasan_slab_free+0x10/0x18\n[ 47.145904] slab_free_freelist_hook+0xa4/0x1b0\n[ 47.150444] kmem_cache_free+0x8c/0x528\n[ 47.154292] kfree_skbmem+0x94/0x108\n[ 47.157880] consume_skb+0x10c/0x5a8\n[ 47.161466] __dev_kfree_skb_any+0x88/0xa0\n[ 47.165598] brcmu_pkt_buf_free_skb+0x44/0x68 [brcmutil]\n[ 47.171023] brcmf_txfinalize+0xec/0x190 [brcmfmac]\n[ 47.176016] brcmf_proto_bcdc_txcomplete+0x1c0/0x210 [brcmfmac]\n[ 47.182056] brcmf_sdio_sendfromq+0x8dc/0x1e80 [brcmfmac]\n[ 47.187568] brcmf_sdio_dpc+0xb48/0x2108 [brcmfmac]\n[ 47.192529] brcmf_sdio_dataworker+0xc8/0x238 [brcmfmac]\n[ 47.197859] process_one_work+0x7fc/0x1a80\n[ 47.201965] worker_thread+0x31c/0xc40\n[ 47.205726] kthread+0x2d8/0x370\n[ 47.208967] ret_from_fork+0x10/0x18\n[ 47.212546]\n[ 47.214051] The buggy address belongs to the object at ffffff803f588280\n[ 47.214051] which belongs to the cache skbuff_head_cache of size 208\n[ 47.227086] The buggy address is located 104 bytes inside of\n[ 47.227086] 208-byte region [ffffff803f588280, ffffff803f588350)\n[ 47.238814] The buggy address belongs to the page:\n[ 47.243618] page:ffffffff00dd6200 refcount:1 mapcou\n---truncated---",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2022-50408",
"url": "https://www.suse.com/security/cve/CVE-2022-50408"
},
{
"category": "external",
"summary": "SUSE Bug 1250391 for CVE-2022-50408",
"url": "https://bugzilla.suse.com/1250391"
},
{
"category": "external",
"summary": "SUSE Bug 1250419 for CVE-2022-50408",
"url": "https://bugzilla.suse.com/1250419"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 7,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "important"
}
],
"title": "CVE-2022-50408"
},
{
"cve": "CVE-2023-53305",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2023-53305"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix use-after-free\n\nFix potential use-after-free in l2cap_le_command_rej.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2023-53305",
"url": "https://www.suse.com/security/cve/CVE-2023-53305"
},
{
"category": "external",
"summary": "SUSE Bug 1250049 for CVE-2023-53305",
"url": "https://bugzilla.suse.com/1250049"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "moderate"
}
],
"title": "CVE-2023-53305"
},
{
"cve": "CVE-2023-53365",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2023-53365"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nip6mr: Fix skb_under_panic in ip6mr_cache_report()\n\nskbuff: skb_under_panic: text:ffffffff88771f69 len:56 put:-4\n head:ffff88805f86a800 data:ffff887f5f86a850 tail:0x88 end:0x2c0 dev:pim6reg\n ------------[ cut here ]------------\n kernel BUG at net/core/skbuff.c:192!\n invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n CPU: 2 PID: 22968 Comm: kworker/2:11 Not tainted 6.5.0-rc3-00044-g0a8db05b571a #236\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Workqueue: ipv6_addrconf addrconf_dad_work\n RIP: 0010:skb_panic+0x152/0x1d0\n Call Trace:\n \u003cTASK\u003e\n skb_push+0xc4/0xe0\n ip6mr_cache_report+0xd69/0x19b0\n reg_vif_xmit+0x406/0x690\n dev_hard_start_xmit+0x17e/0x6e0\n __dev_queue_xmit+0x2d6a/0x3d20\n vlan_dev_hard_start_xmit+0x3ab/0x5c0\n dev_hard_start_xmit+0x17e/0x6e0\n __dev_queue_xmit+0x2d6a/0x3d20\n neigh_connected_output+0x3ed/0x570\n ip6_finish_output2+0x5b5/0x1950\n ip6_finish_output+0x693/0x11c0\n ip6_output+0x24b/0x880\n NF_HOOK.constprop.0+0xfd/0x530\n ndisc_send_skb+0x9db/0x1400\n ndisc_send_rs+0x12a/0x6c0\n addrconf_dad_completed+0x3c9/0xea0\n addrconf_dad_work+0x849/0x1420\n process_one_work+0xa22/0x16e0\n worker_thread+0x679/0x10c0\n ret_from_fork+0x28/0x60\n ret_from_fork_asm+0x11/0x20\n\nWhen setup a vlan device on dev pim6reg, DAD ns packet may sent on reg_vif_xmit().\nreg_vif_xmit()\n ip6mr_cache_report()\n skb_push(skb, -skb_network_offset(pkt));//skb_network_offset(pkt) is 4\nAnd skb_push declared as:\n\tvoid *skb_push(struct sk_buff *skb, unsigned int len);\n\t\tskb-\u003edata -= len;\n\t\t//0xffff88805f86a84c - 0xfffffffc = 0xffff887f5f86a850\nskb-\u003edata is set to 0xffff887f5f86a850, which is invalid mem addr, lead to skb_push() fails.",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2023-53365",
"url": "https://www.suse.com/security/cve/CVE-2023-53365"
},
{
"category": "external",
"summary": "SUSE Bug 1249988 for CVE-2023-53365",
"url": "https://bugzilla.suse.com/1249988"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "moderate"
}
],
"title": "CVE-2023-53365"
},
{
"cve": "CVE-2025-38718",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2025-38718"
}
],
"notes": [
{
"category": "general",
"text": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: linearize cloned gso packets in sctp_rcv\n\nA cloned head skb still shares these frag skbs in fraglist with the\noriginal head skb. It\u0027s not safe to access these frag skbs.\n\nsyzbot reported two use-of-uninitialized-memory bugs caused by this:\n\n BUG: KMSAN: uninit-value in sctp_inq_pop+0x15b7/0x1920 net/sctp/inqueue.c:211\n sctp_inq_pop+0x15b7/0x1920 net/sctp/inqueue.c:211\n sctp_assoc_bh_rcv+0x1a7/0xc50 net/sctp/associola.c:998\n sctp_inq_push+0x2ef/0x380 net/sctp/inqueue.c:88\n sctp_backlog_rcv+0x397/0xdb0 net/sctp/input.c:331\n sk_backlog_rcv+0x13b/0x420 include/net/sock.h:1122\n __release_sock+0x1da/0x330 net/core/sock.c:3106\n release_sock+0x6b/0x250 net/core/sock.c:3660\n sctp_wait_for_connect+0x487/0x820 net/sctp/socket.c:9360\n sctp_sendmsg_to_asoc+0x1ec1/0x1f00 net/sctp/socket.c:1885\n sctp_sendmsg+0x32b9/0x4a80 net/sctp/socket.c:2031\n inet_sendmsg+0x25a/0x280 net/ipv4/af_inet.c:851\n sock_sendmsg_nosec net/socket.c:718 [inline]\n\nand\n\n BUG: KMSAN: uninit-value in sctp_assoc_bh_rcv+0x34e/0xbc0 net/sctp/associola.c:987\n sctp_assoc_bh_rcv+0x34e/0xbc0 net/sctp/associola.c:987\n sctp_inq_push+0x2a3/0x350 net/sctp/inqueue.c:88\n sctp_backlog_rcv+0x3c7/0xda0 net/sctp/input.c:331\n sk_backlog_rcv+0x142/0x420 include/net/sock.h:1148\n __release_sock+0x1d3/0x330 net/core/sock.c:3213\n release_sock+0x6b/0x270 net/core/sock.c:3767\n sctp_wait_for_connect+0x458/0x820 net/sctp/socket.c:9367\n sctp_sendmsg_to_asoc+0x223a/0x2260 net/sctp/socket.c:1886\n sctp_sendmsg+0x3910/0x49f0 net/sctp/socket.c:2032\n inet_sendmsg+0x269/0x2a0 net/ipv4/af_inet.c:851\n sock_sendmsg_nosec net/socket.c:712 [inline]\n\nThis patch fixes it by linearizing cloned gso packets in sctp_rcv().",
"title": "CVE description"
}
],
"product_status": {
"recommended": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2025-38718",
"url": "https://www.suse.com/security/cve/CVE-2025-38718"
},
{
"category": "external",
"summary": "SUSE Bug 1249161 for CVE-2025-38718",
"url": "https://bugzilla.suse.com/1249161"
}
],
"remediations": [
{
"category": "vendor_fix",
"details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
"product_ids": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"scores": [
{
"cvss_v3": {
"baseScore": 5.5,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"products": [
"SUSE Liberty Linux 7 LTSS:bpftool-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-abi-whitelists-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-debug-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-debug-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-doc-0:3.10.0-1160.125.1.0.15.el7.noarch",
"SUSE Liberty Linux 7 LTSS:kernel-headers-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:kernel-tools-libs-devel-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:perf-0:3.10.0-1160.125.1.0.15.el7.x86_64",
"SUSE Liberty Linux 7 LTSS:python-perf-0:3.10.0-1160.125.1.0.15.el7.x86_64"
]
}
],
"threats": [
{
"category": "impact",
"date": "2026-02-02T10:30:16Z",
"details": "moderate"
}
],
"title": "CVE-2025-38718"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…