Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityprivilege-escalation-techniqueoperational-disruption

SUSE Ships Broad Linux Kernel BPF Fixes for Local DoS and Privilege Bypass Flaws

Updated 4h agoFirst seen Jun 26, 202619 sources

SUSE has released a broad set of Linux kernel security updates addressing numerous BPF subsystem vulnerabilities that could be exploited locally with low privileges, including a permission-bypass flaw in BPF_PROG_DETACH on tcx and netkit devices tracked as CVE-2026-45932. That issue allowed unauthorized detachment of BPF programs when no program file descriptor was supplied, and was fixed by enforcing CAP_NET_ADMIN or CAP_SYS_ADMIN checks. Other patched flaws include verifier errors such as CVE-2026-43009 and CVE-2026-43030, a use-after-free in bpf_trampoline_link_cgroup_shim (CVE-2026-23319), an out-of-bounds write in devmap upper-device enumeration (CVE-2026-23359), and a nullable pointer dereference bug in map iterator callbacks (CVE-2026-43333).

The updates also cover earlier BPF and tcp_bpf issues that could crash the kernel or degrade availability, including ring buffer and verifier races, stackmap overflow handling, tail-call compatibility checks, invalid prog->stats access in cgroup BPF paths, and JIT constant-blinding gaps such as CVE-2026-23417. SUSE marked many fixes as released across SLES 15 SP7, SLES 16.0, SUSE Linux Micro 6.x, and openSUSE Leap 16.0, with advisories also listing remediated public cloud images for AWS, Azure, Google Cloud, and Alibaba in several cases. Some branches, including parts of SLES 16.1, older LTSS releases, and selected kernel-source variants, remain affected or in progress depending on product lifecycle and package line.

Share:
SUSE Ships Broad Linux Kernel BPF Fixes for Local DoS and Privilege Bypass Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Jun 26, 20262d ago

SUSE updates CVE-2026-43030 page

SUSE last modified its CVE-2026-43030 page, updating tracking details for the Linux kernel BPF regsafe() vulnerability.

CVE-2026-43030 Common Vulnerabilities and Exposures | SUSE

SUSE updates CVE-2026-43009 page

SUSE last modified its CVE-2026-43009 page, updating vendor tracking information for the Linux kernel BPF verifier vulnerability.

CVE-2026-43009 Common Vulnerabilities and Exposures | SUSE
Jun 15, 202613d ago

SUSE publishes advisories and fixes for CVE-2026-43030

SUSE published multiple advisories and released fixes across numerous SUSE Linux Enterprise, SUSE Linux Micro, and openSUSE Leap 16.0 packages for CVE-2026-43030.

CVE-2026-43030 Common Vulnerabilities and Exposures | SUSE

SUSE publishes advisories and fixes for CVE-2026-45932

SUSE published multiple advisories and fixed package versions across numerous SUSE Linux Enterprise, SUSE Linux Micro, and openSUSE products for CVE-2026-45932, a BPF program detachment permission bypass affecting tcx and netkit devices.

CVE-2026-45932 Common Vulnerabilities and Exposures | SUSE
Jun 11, 202617d ago

SUSE updates CVE-2025-68378 page

SUSE last modified its CVE-2025-68378 page, reflecting updated tracking information for the Linux kernel BPF stackmap overflow issue in __bpf_get_stackid().

CVE-2025-68378 Common Vulnerabilities and Exposures | SUSE
Jun 5, 202623d ago

SUSE publishes advisories and fixes for CVE-2026-43333

SUSE published multiple advisories and released fixes across supported products for CVE-2026-43333, which involved nullable PTR_TO_BUF pointers being directly dereferenced in the Linux kernel BPF subsystem.

CVE-2026-43333 Common Vulnerabilities and Exposures | SUSE

SUSE publishes advisories and fixes for CVE-2026-23359

SUSE published multiple advisories and released fixes across numerous SUSE Linux Enterprise, SUSE Linux Micro, and openSUSE products for CVE-2026-23359, a BPF devmap stack out-of-bounds write issue.

CVE-2026-23359 Common Vulnerabilities and Exposures | SUSE
Jun 4, 202624d ago

SUSE publishes bugzilla entry for CVE-2025-68742 fix

SUSE published Bugzilla entry 1255707 documenting CVE-2025-68742, identifying upstream fixing commit 7dc211c1159d and noting backports to SL-16.0 and fixes/linux-6.4.

1255707 - (CVE-2025-68742) VUL-0: CVE-2025-68742: kernel: bpf: Fix invalid prog->stats access when update_effective_progs fails
May 28, 20261mo ago

SUSE publishes fixes for CVE-2026-43009 across supported products

SUSE published multiple advisories and released fixes across supported products including SLES 15 SP7, SLES 16.0, SLE Micro 6.x, and openSUSE Leap 16.0 for CVE-2026-43009.

CVE-2026-43009 Common Vulnerabilities and Exposures | SUSE

SUSE publishes advisories and fixes for CVE-2026-23417

On 2026-05-28, SUSE published multiple advisories and released fixes for CVE-2026-23417 affecting the Linux kernel BPF subsystem's constant blinding for PROBE_MEM32 stores during JIT compilation.

CVE-2026-23417 Common Vulnerabilities and Exposures | SUSE
May 5, 20262mo ago

SUSE creates CVE-2026-43030 tracking page

SUSE's CVE page for CVE-2026-43030 was created to track the Linux kernel BPF regsafe() flaw affecting pointers to packet handling.

CVE-2026-43030 Common Vulnerabilities and Exposures | SUSE

SUSE creates CVE-2026-43009 tracking page

SUSE's CVE page for CVE-2026-43009 was created, beginning vendor tracking for the Linux kernel BPF verifier flaw involving incorrect pruning from atomic fetch precision tracking.

CVE-2026-43009 Common Vulnerabilities and Exposures | SUSE
Apr 23, 20262mo ago

SUSE publishes advisories and fixes for CVE-2026-23319

SUSE published multiple advisories in April 2026 and released fixes across many SLES, SLE Micro, openSUSE Leap 16.0, and related kernel packages for CVE-2026-23319, a BPF use-after-free issue in bpf_trampoline_link_cgroup_shim.

CVE-2026-23319 Common Vulnerabilities and Exposures | SUSE
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

38 LINKEDOpen in app
Affected products
12 linked
Suse Linux Enterprise High Availability ExtensionLinux KernelSuse Linux Enterprise ServerSuse Linux Enterprise DesktopSuse Linux Enterprise Workstation ExtensionSuse Linux Enterprise Live PatchingSuse Linux Enterprise Module For Public CloudSuse Openstack CloudSuse Enterprise StorageOpensuse LeapOpensuse TumbleweedOpensuse Tumbleweed
Organizations
9 linked
SuseAmazon Web ServicesMicrosoft CorporationGoogleSAPAlibaba CloudMariadbApache Software FoundationMITRE
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.