{"affected":[{"ecosystem_specific":{"binaries":[{"kernel-livepatch-6_4_0-150600_10_49-rt":"2-150600.2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP6","name":"kernel-livepatch-SLE15-SP6-RT_Update_14","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP6-RT_Update_14&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP6"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2-150600.2.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"kernel-livepatch-6_4_0-150700_7_13-rt":"2-150700.2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP7","name":"kernel-livepatch-SLE15-SP7-RT_Update_3","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP7-RT_Update_3&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP7"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2-150700.2.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for the Linux Kernel 6.4.0-150700_7_13 fixes several issues.\n\nThe following security issues were fixed:\n\n- CVE-2025-38678: netfilter: nf_tables: reject duplicate device on updates (bsc#1249534).\n- CVE-2025-38499: clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns (bsc#1248673).\n- CVE-2025-38566: sunrpc: fix handling of server side tls alerts (bsc#1248376).\n- kernel-livepatch.spec: Replace kernel-syms with kernel-&lt;flavor&gt;-specific dependencies (bsc#1248108)  The commit ead79afe7cbfae ('kernel-livepatch.spec: Update build  dependencies for non-default flavors') broke build of livepatches  which were built with kernel-syms-rt.  The problem is that livepatch packages for already released kernels  are built in exactly the same build environment as the initial livepatch.  The BS (Build Service) installs the build environment using the given  _buildinfo-*.xml and ignores BuildRequires. But the BuildRequires are  later checked by rpmbuild tool. It would complain when new dependencies  were added.  Unfortunately, kernel-syms-rt does not exist on SLE16. This was the main  motivation for the above mentioned commit.  But the package kernel-syms is empty. Its only purpose is to add other  dependencies. Replace it by opencoding the dependencies.  Note that the kernel devel files are historically split into various  packages, kernel-&lt;flavor&gt;-devel, kernel-devel-&lt;flavor&gt;, and  even kernel-devel. But it is enough to require kernel-&lt;flavor&gt;-devel  because it requires the other devel files on its own. This seems  to be true back to SLE15-SP4 at minimum.\n","id":"SUSE-SU-2025:03643-1","modified":"2025-10-18T10:33:40Z","published":"2025-10-18T10:33:40Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2025/suse-su-202503643-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248108"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248376"},{"type":"REPORT","url":"https://bugzilla.suse.com/1248673"},{"type":"REPORT","url":"https://bugzilla.suse.com/1249534"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-38499"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-38566"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-38678"}],"related":["CVE-2025-38499","CVE-2025-38566","CVE-2025-38678"],"summary":"Security update for the Linux Kernel RT (Live Patch 3 for SLE 15 SP7)","upstream":["CVE-2025-38499","CVE-2025-38566","CVE-2025-38678"]}