Back Linuxsecurity SUSE Linux 15 SP7 Kernel Security Advisory 2026-0281
## The SUSE Linux Enterprise 15 SP7 Azure kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-38321: smb: Log an error when close_all_cached_dirs fails (bsc#1246328). * CVE-2025-38728: smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256). * CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046). * CVE-2025-40006: mm/hugetlb: fix folio is still mapped when deleted (bsc#1252342). * CVE-2025-40024: vhost: Take a reference on the task in struct vhost_task (bsc#1252686). * CVE-2025-40033: remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (bsc#1252824). * CVE-2025-40042: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (bsc#1252861). Read the Full Advisory
## The SUSE Linux Enterprise 15 SP7 Azure kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-38321: smb: Log an error when close_all_cached_dirs fails (bsc#1246328). * CVE-2025-38728: smb3: fix for slab out of bounds on mount to ksmbd (bsc#1249256). * CVE-2025-39977: futex: Prevent use-after-free during requeue-PI (bsc#1252046). * CVE-2025-40006: mm/hugetlb: fix folio is still mapped when deleted (bsc#1252342). * CVE-2025-40024: vhost: Take a reference on the task in struct vhost_task (bsc#1252686). * CVE-2025-40033: remoteproc: pru: Fix potential NULL pointer dereference in pru_rproc_set_ctable() (bsc#1252824). * CVE-2025-40042: tracing: Fix race condition in kprobe initialization causing NULL pointer dereference (bsc#1252861). Read the Full Advisory
* bsc#1012628 * bsc#1065729 * bsc#1194869 * bsc#1205462 * bsc#1214285 * bsc#1214635 * bsc#1214847 * bsc#1215146 * bsc#1215211 * bsc#1215344 * bsc#1216062 * bsc#1216436 * bsc#1219165 * bsc#1220419 * bsc#1223731 * bsc#1234163 * bsc#1243112 * bsc#1245193 * bsc#1245449 * bsc#1246328 * bsc#1247500 * bsc#1248886 * bsc#1249256 * bsc#1251752 * bsc#1252046 * bsc#1252342 * bsc#1252686 * bsc#1252776 * bsc#1252808 * bsc#1252824 * bsc#1252861 * bsc#1252919 * bsc#1252973 * bsc#1253155 * bsc#1253262 * bsc#1253342 * bsc#1253365 * bsc#1253386 * bsc#1253400 * bsc#1253402 * bsc#1253408 * bsc#1253413 * bsc#1253442 * bsc#1253458 * bsc#1253463 * bsc#1253623 * bsc#1253647 * bsc#1253674 * bsc#1253739 * bsc#1254119 * bsc#1254126 * bsc#1254235 * bsc#1254244 * bsc#1254363 * bsc#1254373 * bsc#1254378 * bsc#1254477 * bsc#1254518 Read the Full Advisory
Read the Full Advisory
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
