Skip to content
Critical Kernel Update for CVE-2025-4269

Critical Kernel Update for CVE-2025-4269

Linuxsecurity •LinuxSecurity Advisories • November 27, 2025

This update for the SUSE Linux Enterprise kernel 6.4.0-150600.23.65 fixes various security issues The following security issues were fixed: * CVE-2025-38500: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (bsc#1248672). * CVE-2025-38616: tls: handle data disappearing from under the TLS ULP (bsc#1249537).

## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-4269=1 SUSE-2025-4270=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-4269=1 SUSE-SLE- Module-Live-Patching-15-SP6-2025-4270=1

## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-4269=1 SUSE-2025-4270=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2025-4269=1 SUSE-SLE- Module-Live-Patching-15-SP6-2025-4270=1

* openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-4-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-4-150600.2.1

* openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-4-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_12-debugsource-9-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-4-150600.2.1 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-4-150600.2.1

* bsc#1248672 * bsc#1249537 ## References: * * * *

* bsc#1248672 * bsc#1249537 ## References: * * * *