CODERED VTA

SUSE Ships Live Patch 43 Closing Four Kernel Flaws Including Zapscape and SCTPhantom

High
Code on a computer screen
Photo by Shahadat Rahman on Unsplash

On 28 September 2026 SUSE released Live Patch 43 for SUSE Linux Enterprise 15 SP5 (announcement SUSE-SU-2026:4381-1, rated important), which fixes four kernel CVEs in kernel 5.14.21-150500.55.177. The four issues are CVE-2026-64561 in the KVM x86 MMU, nicknamed Zapscape; CVE-2026-64564 in the SCTP stack, nicknamed SCTPhantom; CVE-2026-68138 in the network scheduler; and CVE-2026-64423 in the IPv4 IGMP code. Affected products are openSUSE Leap 15.5, SUSE Linux Enterprise Server 15 SP5, Server for SAP Applications 15 SP5, High Performance Computing 15 SP5, Real Time 15 SP5, Live Patching 15-SP5 and SUSE Linux Enterprise Micro 5.5, on ppc64le, s390x and x86_64. Sites running any of those products on the 5.14.21-150500.55 kernel line are in scope.

SUSE has not published exploitation write-ups, so what is known comes from the fix descriptions themselves. CVE-2026-64423 stems from a multicast group not being removed from the IGMP hash table when a network device is destroyed, leaving a stale entry behind. Zapscape (CVE-2026-64561) arises because KVM checked for an invalid or obsolete shadow paging root before, rather than after, making MMU pages available — a sequencing error reachable from a guest context, reflected in its scope-changing CVSS 3.1 vector of 8.8 and SUSE's CVSS 4.0 score of 9.3. SCTPhantom (CVE-2026-64564) involves the SCTP ASCONF handler freeing its own transport during DEL-IP processing, the classic shape of a use-after-free; SUSE rates it 7.8 locally while NVD scores it 9.8 as network-reachable. CVE-2026-68138 is a missing serialisation of qdisc_rtab_list against concurrent get and put operations, a race condition SUSE scores 7.0 with high attack complexity.

Three of the four issues sit in networking code paths that are routinely reachable by low-privileged local users, and the SUSE vectors consistently describe high confidentiality, integrity and availability loss — in practice, kernel memory corruption leading to root. Zapscape is the one that changes the security boundary rather than just the privilege level: a scope-changing flaw in KVM shadow paging matters most on shared virtualisation and SAP hosts where untrusted guests share a hypervisor with sensitive workloads. The disagreement between SUSE and NVD on SCTPhantom is worth noting for exposure modelling, since an NVD network vector implies far broader reach than a local one on systems where SCTP is in use. On current exploitation status, FIRST EPSS puts the 30-day probability at 0.1 percent for CVE-2026-64423, 0.3 percent for CVE-2026-64561, 1.4 percent for CVE-2026-64564 and 0.3 percent for CVE-2026-68138, and there is no report of exploitation in the wild in the vendor advisory. The live patch route means the fixes land without a reboot, which removes the usual reason these kernel updates sit in a queue for weeks.

Attack Surface

Server OS, Endpoint OS, Infrastructure

Tactics

Privilege Escalation, Impact

Techniques

  • T1068 – Exploitation for Privilege Escalation
  • T1611 – Escape to Host
  • T1499 – Endpoint Denial of Service

SuperPRO's Threat Countermeasures Procedures

  1. On SUSE Linux Enterprise Live Patching 15-SP5, apply the new patches with: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4381 SUSE-SLE-Module-Live-Patching-15-SP5-2026-4382 — this installs kernel-livepatch-5_14_21-150500_55_177-default-3-150500.2.1 with no reboot required.
  2. On openSUSE Leap 15.5 hosts, run: zypper in -t patch SUSE-2026-4381 SUSE-2026-4382, covering ppc64le, s390x and x86_64 builds of the 55.177 and 55.172 live patch packages.
  3. Confirm the running kernel is 5.14.21-150500.55.177 with uname -r and verify live patch state with klp -v patches (or zypper se -s kernel-livepatch) on SLE Server, Server for SAP Applications, High Performance Computing and Real Time 15 SP5 nodes before closing the change ticket.
  4. Prioritise KVM hypervisors and SAP hosts for the Zapscape fix (CVE-2026-64561, bsc#1273232), since the scope-changing CVSS vector means a guest-side trigger can affect the host MMU, and confirm kernel-livepatch-5_14_21-150500_55_177-default is present on those nodes.
  5. On nodes still running kernel 5.14.21-150500.55.172 rather than 55.177, install the companion live patch from the same SUSE release with: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4382, which delivers kernel-livepatch-5_14_21-150500_55_172-default covering the same four CVEs on that kernel line.
  6. Verify the SUSE-SU-2026:4381-1 patch and its bug references, including bsc#1273232 for Zapscape (CVE-2026-64561), are recorded as installed on every ppc64le, s390x and x86_64 host in scope using zypper patches | grep 4381 and zypper patch-info SUSE-SLE-Module-Live-Patching-15-SP5-2026-4381.
  7. For SUSE Linux Enterprise Micro 5.5 systems, update to the fixed kernel 5.14.21-150500.55.177 published under SUSE-SU-2026:4381-1 and confirm with uname -r on each affected host after redeployment.

Source

Code Red Cyber / VTA – coderedcyber.ai