SUSE Kernel RT Security Updates Address Multiple Vulnerabilities

SUSE Kernel RT Security Updates Address Multiple Vulnerabilities

First seen 25 Aug 2026, 10:17 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

On August 24, 2026, SUSE released two important security updates for the SUSE Linux Enterprise Kernel, addressing several vulnerabilities. The updates, identified as SUSE-SU-2026:3746-1 and SUSE-SU-2026:3748-1, fix issues including CVE-2025-40204, CVE-2026-53224, and CVE-2026-53246, which involve vulnerabilities in the SCTP protocol and other components. The updates also amend previous fixes related to TLS race conditions and address double-free vulnerabilities in network scheduling and USB interfaces. Affected systems include SUSE Linux Enterprise Kernel versions 6.4.0-150700.7.40 and 6.4.0-150700.7.28. Administrators are urged to apply these updates to mitigate potential security risks. The vulnerabilities have varying CVSS scores, indicating a mix of severity levels. The updates were released shortly after the vulnerabilities were identified, highlighting SUSE's proactive approach to security.

Key Points: • SUSE released two important kernel updates on August 24, 2026, addressing multiple vulnerabilities. • Key vulnerabilities include CVE-2025-40204 and CVE-2026-53224, affecting SCTP and TLS components. • Administrators are advised to apply the updates to SUSE Linux Enterprise Kernel versions 6.4.0-150700.7.40 and 6.4.0-150700.7.28.

Timeline

2025-11-12
CVE-2025-40204 published
A vulnerability in the SCTP protocol was disclosed, allowing potential exploitation.
Linuxsecurity
2026-03-10
CVE-2026-23240 published
A race condition in TLS handling was identified, requiring an amendment to previous fixes.
Linuxsecurity
2026-04-03
CVE-2026-23449 published
A double-free vulnerability in network scheduling was disclosed, affecting kernel operations.
Linuxsecurity
2026-04-24
CVE-2026-31629 published
A missing return check in NFC LLCP processing was identified, necessitating a fix.
Linuxsecurity
2026-05-01
CVE-2026-31759 published
A double-free vulnerability in USB interface registration was disclosed, impacting kernel stability.
Linuxsecurity
2026-05-06
CVE-2026-43077 and CVE-2026-43109 published
Vulnerabilities in crypto algorithms and shadow stacks were disclosed, requiring immediate attention.
Linuxsecurity
2026-06-25
CVE-2026-53224 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-25
CVE-2026-53246 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-24
SUSE Kernel updates released
Two important updates were released to address multiple vulnerabilities in the SUSE Linux Enterprise Kernel.
Linuxsecurity