{"id":"SUSE-SU-2026:23792-1","summary":"Security update for kronosnet","details":"This update for kronosnet fixes the following issues:\n\n- CVE-2026-15811: improper sanitization of sensitive memory locations following cryptographic configuration adjustments\n  can lead to potential exposure of encryption keys (bsc#1271923).\n- CVE-2026-15812: improper verification of packet origins allows for access control list (ACL) bypass via ID spoofing\n  (bsc#1271924).\n- CVE-2026-15813: improper validation during fragment reassembly can trigger memory corruption or out-of-bounds memory\n  access (bsc#1271925).\n","modified":"2026-09-27T18:23:12.574694860Z","published":"2026-09-15T06:42:14Z","related":["CVE-2026-15811","CVE-2026-15812","CVE-2026-15813"],"upstream":["CVE-2026-15811","CVE-2026-15812","CVE-2026-15813"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623792-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271925"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15811"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15812"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15813"}],"affected":[{"package":{"name":"kernel-livepatch-SLE16-RT_Update_15","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/kernel-livepatch-SLE16-RT_Update_15&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-livepatch-6_12_0-160000_36-rt":"3-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23792-1.json"}},{"package":{"name":"kronosnet","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/kronosnet&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.30-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"libknet1-compress-lzo2-plugin":"1.30-160000.4.1","libknet-devel":"1.30-160000.4.1","libknet1-compress-lz4-plugin":"1.30-160000.4.1","libknet1-compress-lzma-plugin":"1.30-160000.4.1","libknet1-crypto-openssl-plugin":"1.30-160000.4.1","libknet1":"1.30-160000.4.1","libknet1-compress-bzip2-plugin":"1.30-160000.4.1","libnozzle1":"1.30-160000.4.1","libnozzle-devel":"1.30-160000.4.1","libknet1-plugins-all":"1.30-160000.4.1","libknet1-compress-zlib-plugin":"1.30-160000.4.1","libknet1-compress-zstd-plugin":"1.30-160000.4.1","libknet1-crypto-plugins-all":"1.30-160000.4.1","libknet1-compress-plugins-all":"1.30-160000.4.1","libknet1-crypto-nss-plugin":"1.30-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23792-1.json"}}],"schema_version":"1.9.0"}