VORANT. Threat Intelligence Research Sign in Create a free account

SUSE Patches Dozens of Linux Kernel Flaws

routine vulnerability

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory details over 100 Linux kernel vulnerabilities across SUSE products enabling code execution, DoS, and data exposure; patches available.

CERT-FR has issued an advisory consolidating more than 100 vulnerabilities discovered in the Linux kernel as shipped by SUSE, affecting a broad range of SUSE and openSUSE products including SUSE Linux Enterprise Server, SUSE Linux Enterprise Micro, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Live Patching, and multiple openSUSE Leap releases across versions 12 through 15 SP7. The flaws collectively allow attackers to achieve arbitrary code execution, trigger remote denial of service, compromise data confidentiality and integrity, and bypass security policies, though the advisory does not specify exploitation requirements or confirm active exploitation for any individual CVE.

SUSE has released a large batch of security updates (dozens of SUSE-SU bulletins dated October 2–8, 2026) addressing these kernel issues. No evidence of in-the-wild exploitation is cited in the advisory; this is a routine, large-scale kernel patch rollup rather than an active-attack notification. Defenders running affected SUSE/openSUSE kernel versions should prioritize patching per the linked SUSE-SU bulletins, particularly for systems exposed to untrusted input or multi-tenant workloads where local privilege escalation or DoS impact is most relevant.

Given the sheer volume of CVEs, organizations should use the official SUSE bulletin references to map specific kernel subsystems/packages in their environment to applicable fixes, and apply kernel live-patching where available (SLE Live Patching) to minimize downtime during remediation.

Mentioned in this report

Vulnerabilities CVE-2024-57841CVE-2026-23451CVE-2026-31502CVE-2026-43456CVE-2026-45968CVE-2026-46116CVE-2026-52910CVE-2026-52912CVE-2026-52929CVE-2026-52977CVE-2026-53059CVE-2026-53163CVE-2026-53260CVE-2026-53264CVE-2026-53381CVE-2026-53388CVE-2026-63801CVE-2026-63802CVE-2026-63823CVE-2026-63827CVE-2026-63887CVE-2026-63888CVE-2026-63912CVE-2026-63917CVE-2026-63920CVE-2026-63921CVE-2026-63944CVE-2026-63971CVE-2026-63992CVE-2026-63994CVE-2026-64000CVE-2026-64002CVE-2026-64007CVE-2026-64010CVE-2026-64011CVE-2026-64015CVE-2026-64047CVE-2026-64048CVE-2026-64098CVE-2026-64109

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1288

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,164 reports from 148 sources, 494 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs