Skip to content
openSUSE Kernel Important Security Update Vulnerability Fix 2026-3156

openSUSE Kernel Important Security Update Vulnerability Fix 2026-3156

Linuxsecurity LinuxSecurity Advisories July 22, 2026

Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges ×

The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security

The following security issues were fixed:

* CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock

* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed

* CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).

* CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted

* CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in

__xfrm_state_delete (bsc#1267369).

* CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task

* CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data

exposure (bsc#1267567).

* CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc()

* CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old()

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise High Availability Extension 15 SP6

zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1

* SUSE Linux Enterprise Live Patching 15-SP6

zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1

zypper in -t patch SUSE-2026-3156=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1

* openSUSE Leap 15.6 (aarch64)

* dtb-apm-6.4.0-150600.23.125.1

* dtb-lg-6.4.0-150600.23.125.1

* kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1

* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* dlm-kmp-64kb-6.4.0-150600.23.125.1

* dtb-amazon-6.4.0-150600.23.125.1

* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* dtb-amlogic-6.4.0-150600.23.125.1

* dtb-amd-6.4.0-150600.23.125.1

* kernel-64kb-debuginfo-6.4.0-150600.23.125.1

* dtb-sprd-6.4.0-150600.23.125.1

* kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1

* dtb-nvidia-6.4.0-150600.23.125.1

* dtb-xilinx-6.4.0-150600.23.125.1

* dtb-mediatek-6.4.0-150600.23.125.1

* kernel-64kb-extra-6.4.0-150600.23.125.1

* ocfs2-kmp-64kb-6.4.0-150600.23.125.1

* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1

* kernel-64kb-debugsource-6.4.0-150600.23.125.1

* dtb-renesas-6.4.0-150600.23.125.1

* dtb-arm-6.4.0-150600.23.125.1

* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1

* dtb-broadcom-6.4.0-150600.23.125.1

*

*

*

*

*

Get the latest Linux and open source security news straight to your inbox.