Multiple SUSE Kernel RT Security Updates Address Critical Vulnerabilities

Multiple SUSE Kernel RT Security Updates Address Critical Vulnerabilities

First seen 27 Aug 2026, 03:38 UTC Linuxsecurity 67.2

Article Content

Browse articles
ThreatCluster

SUSE has released a series of important security updates for its Linux Enterprise Kernel, addressing multiple vulnerabilities across various versions. Key vulnerabilities include CVE-2026-23449, a double-free issue in net/sched, and CVE-2026-43109, related to x86 shadow stacks. Other notable CVEs include CVE-2026-46037 and CVE-2026-46242, both of which have been confirmed with proof-of-concept code. The updates affect multiple kernel versions, including 6.12.0-160000.26.1 through 6.12.0-160000.35.1. Security professionals are urged to apply the patches immediately to mitigate risks. The vulnerabilities could allow for potential exploitation, including denial of service and unauthorized access. The updates were released on August 24, 2026, and are rated as important by SUSE.

Key Points: • SUSE released critical updates for multiple kernel versions addressing several CVEs. • CVE-2026-23449 and CVE-2026-43109 are among the most severe vulnerabilities fixed. • Immediate patching is recommended to prevent potential exploitation of these vulnerabilities.

Timeline

2026-02-14
CVE-2026-23161 published
A race condition in mm/shmem and swap was disclosed, affecting memory management.
Linuxsecurity
2026-04-03
CVE-2026-23449 published
A double-free vulnerability in net/sched was disclosed, impacting kernel operations.
Linuxsecurity
2026-04-24
CVE-2026-31629 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-01
CVE-2026-31759 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-06
CVE-2026-43109 published
A vulnerability in x86 shadow stacks was disclosed, affecting error handling in mmap locks.
Linuxsecurity
2026-05-06
CVE-2026-43077 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-06
CVE-2026-43110 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-27
CVE-2026-46037 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-30
CVE-2026-46242 published
A vulnerability in eventpoll was disclosed, with a proof-of-concept released on July 5.
Linuxsecurity
2026-06-09
CVE-2026-46319 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE