CODERED VTA

SUSE Live Patch Closes Thirteen Kernel Flaws Across Enterprise Linux 15 Fleets

High
Engineer in a server room aisle
Photo by USDAgov on Flickr

SUSE has released announcement SUSE-SU-2026:4507-1, dated 5 October 2026 and rated important, which resolves thirteen kernel vulnerabilities. The set comprises CVE-2026-46116, CVE-2026-63888, CVE-2026-63917, CVE-2026-63920, CVE-2026-63921, CVE-2026-63971, CVE-2026-63994, CVE-2026-64011, CVE-2026-64114, CVE-2026-64189, CVE-2026-68121, CVE-2026-68202 and CVE-2026-74394. The fix lands as Live Patch 41 for SUSE Linux Enterprise 15 SP5, built against kernel 5.14.21-150500.55.169, and the affected product list is broad: SUSE Linux Enterprise Server 15 SP4 and SP5, Server for SAP Applications 15 SP4 and SP5, High Performance Computing 15 SP4 and SP5, Real Time 15 SP4 and SP5, Micro 5.3 through 5.5, Live Patching 15-SP4 and 15-SP5, and openSUSE Leap 15.4 and 15.5. SUSE scores the most serious issue, CVE-2026-63921, at 9.3 under CVSS v4.0, with several others in the 7.0 to 8.5 range.

SUSE has not published exploitation details or proof-of-concept code for any of these issues, so what follows is limited to the defect classes the advisory itself names. The majority sit in the networking stack. CVE-2026-63917 and CVE-2026-63921 both involve incorrect network namespace handling in the IPv6 VTI tunnel driver, in vti6_changelink() and vti6_siocdevprivate() respectively; the latter is the only flaw in the set that SUSE marks as crossing a privilege scope boundary. CVE-2026-63920 is a missing length validation on IPv6 extension headers before they are copied into a control message, while CVE-2026-64114 concerns raw IPv4 sockets accepting IP_HDRINCL packets with an internet header length below five. CVE-2026-64011 is a use-after-free in llcp_sock_release() in the NFC stack, CVE-2026-63888 is a CRC overread combined with a double free in the iSCSI target function iscsit_handle_text_cmd(), and CVE-2026-63971 is a race between sctp_wait_for_connect and socket peeloff. The remainder cover a race between dump and list resize in netfilter ipset (CVE-2026-64189), a stale header pointer in PPPoE after dev_hard_header() (CVE-2026-68121), a re-opened sequencer queue timer in ALSA (CVE-2026-68202), an skb_cow() ordering bug in ICMPv6 tunnel path MTU handling (CVE-2026-63994), an xfrm state unhashing defect (CVE-2026-46116), and an integer overflow in the RDMA/srpt immediate data length check (CVE-2026-74394).

Most of these vectors assume a local account with low privileges, which in practice points at shared servers, multi-tenant hosts, container nodes and SAP estates where unprivileged workloads already run alongside sensitive data. A smaller group is reachable over the network or adjacent network where the relevant subsystem is actually enabled, notably the iSCSI target code, the RDMA SRP target and the tunnel and IPv6 paths. Present exploitation pressure is low across the set. FIRST EPSS places CVE-2026-63888 at a 0.8 percent probability of exploitation in the next 30 days, CVE-2026-63994 at 0.5 percent, CVE-2026-68121 at 0.3 percent, CVE-2026-46116, CVE-2026-63917, CVE-2026-63920, CVE-2026-63921 and CVE-2026-68202 at 0.2 percent each, and CVE-2026-63971, CVE-2026-64011, CVE-2026-64114 and CVE-2026-64189 at 0.1 percent each. None of the thirteen is listed in the CISA Known Exploited Vulnerabilities catalogue and no in-the-wild activity has been reported. The practical significance is scope rather than urgency: the same kernel base sits under production SAP, HPC and real-time workloads where unplanned reboots are expensive, which is exactly why these fixes were shipped as live patches in the first place.

Attack Surface

Server OS, Endpoint OS, Infrastructure

Tactics

Privilege Escalation, Impact, Lateral Movement

Techniques

  • T1068 – Exploitation for Privilege Escalation
  • T1210 – Exploitation of Remote Services
  • T1499 – Endpoint Denial of Service
  • T1499.004 – Application or System Exploitation

SuperPRO's Threat Countermeasures Procedures

  1. On SUSE Linux Enterprise Live Patching 15-SP5 and openSUSE Leap 15.5, apply the live patches with 'zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4486 SUSE-SLE-Module-Live-Patching-15-SP5-2026-4490 SUSE-SLE-Module-Live-Patching-15-SP5-2026-4488' (Leap 15.5 uses SUSE-2026-4486, SUSE-2026-4488 and SUSE-2026-4490).
  2. On SUSE Linux Enterprise Live Patching 15-SP4, run 'zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4507'; on openSUSE Leap 15.4 run 'zypper in -t patch SUSE-2026-4507'. These deliver kernel-livepatch-5_14_21-150400_24_214-default-7-150400.2.1.
  3. Confirm the live patch is active rather than merely installed: check 'uname -r' against kernel 5.14.21-150500.55.169, 55.166 or 55.127 on SP5 and 5.14.21-150400.24.214 on SP4, then verify with 'cat /sys/kernel/livepatch/*/enabled' returning 1.
  4. Inventory estate-wide for the affected products named in SUSE-SU-2026:4507-1 – SLES 15 SP4/SP5, SLES for SAP Applications 15 SP4/SP5, HPC 15 SP4/SP5, Real Time 15 SP4/SP5, SUSE Linux Enterprise Micro 5.3/5.4/5.5 and openSUSE Leap 15.4/15.5 – and schedule a full kernel update for Micro and any host without a Live Patching subscription, since live patches do not cover those channels.
  5. Track completion across the estate by listing outstanding patches with 'zypper lp' on SLES 15 SP4/SP5 and openSUSE Leap 15.4/15.5 hosts, treating any host that still offers SUSE-SLE-Module-Live-Patching-15-SP4-2026-4507 or SUSE-2026-4507 as not yet covered by SUSE-SU-2026:4507-1.
  6. Confirm the vendor packages named in SUSE-SU-2026:4507-1 are actually installed after patching, querying 'rpm -q kernel-livepatch-5_14_21-150400_24_214-default' on 15 SP4 hosts and the matching kernel-livepatch package for the Live Patch 41 kernel 5.14.21-150500.55.169 on 15 SP5, and re-run the 'zypper in -t patch' command for any host where the query returns no package.
  7. Sequence the rollout of SUSE-SU-2026:4507-1 so that SUSE Linux Enterprise Server for SAP Applications 15 SP4/SP5 and Real Time 15 SP4/SP5 hosts are covered first, as SUSE scores CVE-2026-63921 in the IPv6 VTI tunnel driver at 9.3 under CVSS v4.0 and marks it as the only flaw in the set crossing a privilege scope boundary; the live patch route avoids the reboot those workloads cannot easily absorb.

Source

Code Red Cyber / VTA – coderedcyber.ai