Back Linuxsecurity openSUSE Kernel Important Security Update Vulnerability Fix 2026-3156
Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges ×
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security
The following security issues were fixed:
* CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock
* CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed
* CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).
* CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted
* CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in
__xfrm_state_delete (bsc#1267369).
* CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task
* CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data
exposure (bsc#1267567).
* CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc()
* CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old()
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Availability Extension 15 SP6
zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3156=1
* SUSE Linux Enterprise Live Patching 15-SP6
zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3156=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3156=1
zypper in -t patch SUSE-2026-3156=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3156=1
* openSUSE Leap 15.6 (aarch64)
* dtb-apm-6.4.0-150600.23.125.1
* dtb-lg-6.4.0-150600.23.125.1
* kernel-64kb-optional-debuginfo-6.4.0-150600.23.125.1
* kselftests-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dlm-kmp-64kb-6.4.0-150600.23.125.1
* dtb-amazon-6.4.0-150600.23.125.1
* cluster-md-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-amlogic-6.4.0-150600.23.125.1
* dtb-amd-6.4.0-150600.23.125.1
* kernel-64kb-debuginfo-6.4.0-150600.23.125.1
* dtb-sprd-6.4.0-150600.23.125.1
* kernel-64kb-extra-debuginfo-6.4.0-150600.23.125.1
* dtb-nvidia-6.4.0-150600.23.125.1
* dtb-xilinx-6.4.0-150600.23.125.1
* dtb-mediatek-6.4.0-150600.23.125.1
* kernel-64kb-extra-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-6.4.0-150600.23.125.1
* reiserfs-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* ocfs2-kmp-64kb-debuginfo-6.4.0-150600.23.125.1
* kernel-64kb-debugsource-6.4.0-150600.23.125.1
* dtb-renesas-6.4.0-150600.23.125.1
* dtb-arm-6.4.0-150600.23.125.1
* kernel-64kb-devel-debuginfo-6.4.0-150600.23.125.1
* dtb-broadcom-6.4.0-150600.23.125.1
*
*
*
*
*
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
