Back Linuxsecurity SUSE: Kernel Important Update Addresses Race Condition CVE-2025
## The SUSE Linux Enterprise 15 SP6 Azure kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-38008: mm/page_alloc: fix race condition in unaccepted memory handling (bsc#1244939). * CVE-2025-38539: trace/fgraph: Fix the warning caused by missing unregister notifier (bsc#1248211). * CVE-2025-38552: mptcp: plug races between subflow fail and subflow creation (bsc#1248230). * CVE-2025-38653: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (bsc#1248630). * CVE-2025-38699: scsi: bfa: Double-free fix (bsc#1249224). * CVE-2025-38700: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated (bsc#1249182). * CVE-2025-38718: sctp: linearize cloned gso packets in sctp_rcv (bsc#1249161). Read the Full Advisory
## The SUSE Linux Enterprise 15 SP6 Azure kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-38008: mm/page_alloc: fix race condition in unaccepted memory handling (bsc#1244939). * CVE-2025-38539: trace/fgraph: Fix the warning caused by missing unregister notifier (bsc#1248211). * CVE-2025-38552: mptcp: plug races between subflow fail and subflow creation (bsc#1248230). * CVE-2025-38653: proc: use the same treatment to check proc_lseek as ones for proc_read_iter et.al (bsc#1248630). * CVE-2025-38699: scsi: bfa: Double-free fix (bsc#1249224). * CVE-2025-38700: scsi: libiscsi: Initialize iscsi_conn->dd_data only if memory is allocated (bsc#1249182). * CVE-2025-38718: sctp: linearize cloned gso packets in sctp_rcv (bsc#1249161). Read the Full Advisory
* bsc#1012628 * bsc#1214954 * bsc#1215143 * bsc#1215199 * bsc#1216396 * bsc#1220419 * bsc#1239206 * bsc#1244939 * bsc#1248211 * bsc#1248230 * bsc#1248517 * bsc#1248630 * bsc#1248754 * bsc#1248886 * bsc#1249161 * bsc#1249182 * bsc#1249224 * bsc#1249286 * bsc#1249302 * bsc#1249317 * bsc#1249319 * bsc#1249320 * bsc#1249512 * bsc#1249595 * bsc#1249608 * bsc#1250032 * bsc#1250119 * bsc#1250202 * bsc#1250237 * bsc#1250274 * bsc#1250296 * bsc#1250379 * bsc#1250400 * bsc#1250455 * bsc#1250491 * bsc#1250519 * bsc#1250650 * bsc#1250702 * bsc#1250704 * bsc#1250721 * bsc#1250742 * bsc#1250946 * bsc#1251024 * bsc#1251027 * bsc#1251028 * bsc#1251031 * bsc#1251035 * bsc#1251038 * bsc#1251043 * bsc#1251045 * bsc#1251052 * bsc#1251053 * bsc#1251054 * bsc#1251056 * bsc#1251057 * bsc#1251059 * bsc#1251060 * bsc#1251065 Read the Full Advisory
Read the Full Advisory
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
