# SUSE Patches Dozens of Linux Kernel Flaws

Published: 2026-10-09 · Severity: routine
Canonical: https://vorant.io/reports/22c24f16-eb47-5c11-94a5-e876df92473d/suse-patches-dozens-of-linux-kernel-flaws

> CERT-FR advisory details over 100 Linux kernel vulnerabilities across SUSE products enabling code execution, DoS, and data exposure; patches available.

CERT-FR has issued an advisory consolidating more than 100 vulnerabilities discovered in the Linux kernel as shipped by SUSE, affecting a broad range of SUSE and openSUSE products including SUSE Linux Enterprise Server, SUSE Linux Enterprise Micro, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Real Time, SUSE Linux Enterprise Live Patching, and multiple openSUSE Leap releases across versions 12 through 15 SP7. The flaws collectively allow attackers to achieve arbitrary code execution, trigger remote denial of service, compromise data confidentiality and integrity, and bypass security policies, though the advisory does not specify exploitation requirements or confirm active exploitation for any individual CVE.

SUSE has released a large batch of security updates (dozens of SUSE-SU bulletins dated October 2–8, 2026) addressing these kernel issues. No evidence of in-the-wild exploitation is cited in the advisory; this is a routine, large-scale kernel patch rollup rather than an active-attack notification. Defenders running affected SUSE/openSUSE kernel versions should prioritize patching per the linked SUSE-SU bulletins, particularly for systems exposed to untrusted input or multi-tenant workloads where local privilege escalation or DoS impact is most relevant.

Given the sheer volume of CVEs, organizations should use the official SUSE bulletin references to map specific kernel subsystems/packages in their environment to applicable fixes, and apply kernel live-patching where available (SLE Live Patching) to minimize downtime during remediation.

## Mentioned in this report

- Vulnerabilities: CVE-2024-57841, CVE-2026-23451, CVE-2026-31502, CVE-2026-43456, CVE-2026-45968, CVE-2026-46116, CVE-2026-52910, CVE-2026-52912, CVE-2026-52929, CVE-2026-52977, CVE-2026-53059, CVE-2026-53163, CVE-2026-53260, CVE-2026-53264, CVE-2026-53381, CVE-2026-53388, CVE-2026-63801, CVE-2026-63802, CVE-2026-63823, CVE-2026-63827, CVE-2026-63887, CVE-2026-63888, CVE-2026-63912, CVE-2026-63917, CVE-2026-63920, CVE-2026-63921, CVE-2026-63944, CVE-2026-63971, CVE-2026-63992, CVE-2026-63994, CVE-2026-64000, CVE-2026-64002, CVE-2026-64007, CVE-2026-64010, CVE-2026-64011, CVE-2026-64015, CVE-2026-64047, CVE-2026-64048, CVE-2026-64098, CVE-2026-64109

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1288

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/22c24f16-eb47-5c11-94a5-e876df92473d/suse-patches-dozens-of-linux-kernel-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
