SUSE-IU-2025:3743-1: Security update of suse/sl-micro/6.2/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Nov 27 08:05:41 UTC 2025


SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2025:3743-1
Image Tags        : suse/sl-micro/6.2/baremetal-os-container:2.3.0 , suse/sl-micro/6.2/baremetal-os-container:2.3.0-6.4 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release     : 6.4
Severity          : critical
Type              : security
References        : 1205770 1229587 1232226 1235731 1238137 1238848 1240883 1242998
                        1243503 1244573 1245470 1247106 1247108 1247581 1247582 1247875
                        1248117 1248330 1249052 1249370 1249435 1249584 1250413 1250553
                        1250661 1250696 1250974 1251227 1251793 1251862 1251923 1251952
                        1251979 1252110 1252232 1253260 CVE-2024-13978 CVE-2025-10911
                        CVE-2025-11731 CVE-2025-31133 CVE-2025-52565 CVE-2025-52881 CVE-2025-59375
                        CVE-2025-8176 CVE-2025-8177 CVE-2025-8534 CVE-2025-8961 CVE-2025-9165
                        CVE-2025-9900 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 20
Released:    Mon Nov 17 16:06:01 2025
Summary:     Recommended update for selinux-policy
Type:        recommended
Severity:    critical
References:  1205770,1229587,1232226,1235731,1238137,1240883,1242998,1244573,1245470,1247875,1249052,1249370,1249435,1250661,1250696,1250974,1251227,1251793,1251862,1251923,1251952
This update for selinux-policy fixes the following issues:

Changes in selinux-policy:

Update to version 20250627+git239.fcbf2d509:

  * fail2ban: bump module version
  * fail2ban: allow fail2ban to watch all log files and dirs (bsc#1251952)
  * fail2ban: fix typos in interface descriptions
  * fail2ban: tweak file context regex for /run/fail2ban
  * fail2ban: drop file context for old rc.d file
  * Allow wicket to manage its proc directories (bsc#1235731)
  * Allow NM to manage wicked pid files (bsc#1235731)
  * Allow NM to reach systemd unit files (bsc#1235731)
  * Make wicked script backwards compatible (bsc#1251923)
  * Allow snapper grub plugin to domtrans to bootloader_t (bsc#1251862)
  * Allow salt_t transition to rpm_script_t (bsc#1250696)
  * grub snapper plugin is now named 00-grub (bsc#1251793)
  * Assign alts_exec_t exec_file attribute (bsc#1250974)
  * Add equivalency between /srv/tomcat and /var/lib/tomcat (bsc#1251227)
  * Allow sshd_session_t write to wtmpdb
  * Support /usr/libexec/ssh as well as openssh folder
  * Set xenstored_use_store_type_domain boolean true(bsc#1247875)
  * Adjust guest and xguest users policy for sshd-session
  * Allow valkey-server create and use netlink_rdma_socket
  * Allow blueman get attributes of filesystems with extended attributes
  * Update files_search_base_file_types()
  * Introduce unconfined wicked_script_t (bsc#1205770, bsc#1250661)
  * Allow geoclue get attributes of the /dev/shm filesystem
  * Allow apcupsd get attributes of the /dev/shm filesystem
  * Allow sshd-session read cockpit pid files
  * Add /opt/.snapshots to the snapper file context (bsc#1232226)
  * Allow nfs generator create and use netlink sockets
  * Conditionally allow virt guests to read certificates in user home directories
  * xenstored_t needs CAP_SYS_ADMIN for XENSTORETYPE=domain (bsc#1247875)
  * Allow nfs-generator create and use udp sockets
  * Allow kdump search kdumpctl_tmp_t directories
  * Allow init open and read user tmp files
  * Fix the systemd_logind_stream_connect() interface
  * Allow staff and sysadm execute iotop using sudo
  * Allow sudodomains connect to systemd-logind over a unix socket
  * /boot/efi is dosfs_t and kdump needs to access it (bsc#1249370)
  * Add default contexts for sshd-seesion
  * Define types for new openssh executables
  * Fix systemd_manage_unit_symlinks() interface definition
  * Support coreos installation methods
  * Add a new type for systemd-ssh-issue PID files
  * Allow gnome-remote-desktop connect to unreserved ports
  * Zypper moves files in /var/tmp to /var/cache (bsc#1249052, bsc#1249435)
  * Allow mdadm the CAP_SYS_PTRACE capability
  * Allow iptables manage its private fifo_files in /tmp
  * Allow auditd manage its private run dirs
  * Revert 'Allow virt_domain write to virt_image_t files'
  * Allow gdm create /etc/.pwd.lock with a file transition
  * Allow gdm bind a socket in the /run/systemd/userdbd directory
  * Allow nsswitch_domain connect to xdm over a unix domain socket
  * Allow systemd homed getattr all tmpfs files (bsc#1240883)
  * Allow systemd (PID 1) create lastlog entries
  * Allow systemd_homework_t transition pid files to lvm_var_run_t (bsc#1240883)
  * Allow gnome-remote-desktop speak with tabrmd over dbus (bsc#1244573)
  * Allow nm-dispatcher iscsi and sendmail plugins get pidfs attributes
  * Allow systemd-oomd watch tmpfs dirs
  * Allow chronyc the setgid and setuid capabilities
  * Label /usr/lib/systemd/systemd-ssh-issue with systemd_ssh_issue_exec_t
  * Allow stalld map sysfs files
  * Allow NetworkManager-dispatcher-winbind get pidfs attributes
  * Allow openvpn create and use generic netlink socket
  * policy_capabilities: remove estimated from released versions
  * policy_capabilities: add stub for userspace_initial_context
  * add netlink_xperm policy capability and nlmsg permission definitions
  * policy_capabilities: add ioctl_skip_cloexec
  * selinux-policy: add allow rule for tuned_ppd_t
  * selinux-policy: add allow rule for switcheroo_control_t
  * Label /run/audit with auditd_var_run_t
  * Allow virtqemud start a vm which uses nbdkit
  * Add nbdkit_signal() and nbdkit_signull() interfaces
  * Fix insights_client interfaces names
  * Add insights_core and insights_client interfaces
  * Fix selinux-autorelabel-generator label after upstream changes
  * Revert 'Remove the mysql module sources'
  * Revert 'Allow rasdaemon write access to sysfs (bsc#1229587)'
  * Reset postfix.fc to upstream, add alias instead
  * dist/targeted/modules.conf: enable slrnpull module
  * Allow bootupd delete symlinks in the /boot directory
  * Allow systemd-coredumpd capabilities in the user namespace
  * Allow openvswitch read virtqemud process state
  * Allow systemd-networkd to create leases directory
  * Apply generator template to selinux-autorelabel generator
  * Support virtqemud handle hotplug hostdev devices
  * Allow virtstoraged create qemu /var/run files
  * Allow unconfined_domain_type cap2_userns capabilities
  * Label /usr/libexec/postfix/tlsproxy with postfix_smtp_exec_t
  * Remove the mysql module sources
  * dist/targeted/modules.conf: Enable kmscon module (bsc#1238137)
  * Update kmscon policy module to kmscon version 9 (bsc#1238137)
  * Allow login to getattr pidfs
  * Allow systemd to map files under /sys
  * systemd: drop duplicate init_nnp_daemon_domain lines
  * Fix typo
  * Allow logwatch stream connect to opensmtpd
  * Allow geoclue read NetworkManager pid files
  * Allow unconfined user a file transition for creating sudo log directory
  * Allow virtqemud read/write inherited dri devices
  * Allow xdm_t create user namespaces
  * Update policy for login_userdomain
  * Add ppd_base_profile to file transition to get tuned_rw_etc_t type
  * Update policy for bootupd
  * Allow logwatch work with opensmtpd
  * Update dovecot policy for dovecot 2.4.1
  * Allow ras-mc-ctl write to sysfs files
  * Allow anaconda-generator get attributes of all filesystems
  * Add the rhcd_rw_fifo_files() interface
  * Allow systemd-coredump the sys_chroot capability
  * Allow hostapd write to socket files in /tmp
  * Recognize /var/home as an alternate path for /home
  * Label /var/lib/lastlog with lastlog_t
  * Allow virtqemud write to sysfs files
  * Allow irqbalance search sssd lib directories
  * Allow samba-dcerpcd send sigkills to passwd
  * Allow systemd-oomd watch dbus pid sock files
  * Allow some confined users read and map generic log files
  * Allow login_userdomain watch the /run/log/journal directory
  * Allow login_userdomain dbus chat with tuned-ppd
  * Allow login_userdomain dbus chat with switcheroo-control
  * Allow userdomain to connect to systemd-oomd over a unix socket
  * Add insights_client_delete_lib_dirs() interface
  * Allow virtqemud_t use its private tmpfs files (bsc#1242998)
  * Allow virtqemud_t setattr to /dev/userfaultfd (bsc#1242998)
  * Allow virtqemud_t read and write /dev/ptmx (bsc#1242998)
  * Extend virtqemud_t tcp_socket permissions (bsc#1242998)
  * Allow virtqemud_t to read and write generic pty (bsc#1242998)
  * Allow systemd-importd create and unlink init pid socket
  * Allow virtqemud handle virt_content_t chr files
  * Allow svirt read virtqemud fifo files
  * All sblim-sfcbd the dac_read_search capability
  * Allow sblim domain read systemd session files
  * Allow sblim-sfcbd execute dnsdomainname
  * Confine nfs-server generator
  * Allow systemd-timedated start/stop timemaster services
  * Allow 'hostapd_cli ping' run as a systemd service
  * Allow power-profiles-daemon get attributes of filesystems with extended attributes
  * Allow 'oomctl dump' to interact with systemd-oomd
  * Basic functionality for systemd-oomd
  * Basic enablement for systemd-oomd
  * Allow samba-bgqd send to smbd over a unix datagram socket
  * Update kernel_secretmem_use()
  * Add the file/watch_mountns permission
  * Update systemd-generators policy
  * Allow plymouthd_t read proc files of systemd_passwd_agent (bsc#1245470)
  * Allow insights-client file transition for files in /var/tmp
  * Allow tuned-ppd manage tuned log files
  * Allow systemd-coredump mount on tmpfs filesystems
  * Update sssd_dontaudit_read_public_files()
  * Allow zram-generator raw read fixed disk device
  * Add fs_write_cgroup_dirs() and fs_setattr_cgroup_dirs() interfaces

-----------------------------------------------------------------
Advisory ID: 29
Released:    Wed Nov 19 10:37:50 2025
Summary:     Security update for expat
Type:        security
Severity:    important
References:  1249584,CVE-2025-59375
This update for expat fixes the following issues:

- CVE-2025-59375: Fixed large dynamic memory allocations via a small document submitted for parsing (bsc#1249584)

-----------------------------------------------------------------
Advisory ID: 24
Released:    Wed Nov 19 10:40:24 2025
Summary:     Security update for libxslt
Type:        security
Severity:    important
References:  1250553,1251979,CVE-2025-10911,CVE-2025-11731
This update for libxslt fixes the following issues:

Changes in libxslt:

- CVE-2025-11731: Fixed type confusion in exsltFuncResultCompfunction leading to denial of service (bsc#1251979)
- CVE-2025-10911: Fixed use-after-free with key data stored cross-RVT (bsc#1250553)

-----------------------------------------------------------------
Advisory ID: 23
Released:    Wed Nov 19 10:40:24 2025
Summary:     Security update for tiff
Type:        security
Severity:    important
References:  1243503,1247106,1247108,1247581,1247582,1248117,1248330,1250413,CVE-2024-13978,CVE-2025-8176,CVE-2025-8177,CVE-2025-8534,CVE-2025-8961,CVE-2025-9165,CVE-2025-9900
This update for tiff fixes the following issues:

tiff was updated to 4.7.1:

* Software configuration changes:

  * Define HAVE_JPEGTURBO_DUAL_MODE_8_12 and LERC_STATIC in tif_config.h.
  * CMake: define WORDS_BIGENDIAN via tif_config.h
  * doc/CMakeLists.txt: remove useless cmake_minimum_required()
  * CMake: fix build with LLVM/Clang 17 (fixes issue #651)
  * CMake: set CMP0074 new policy
  * Set LINKER_LANGUAGE for C targets with C deps
  * Export tiffxx cmake target (fixes issue #674)
  * autogen.sh: Enable verbose wget.
  * configure.ac: Syntax updates for Autoconf 2.71
  * autogen.sh: Re-implement based on autoreconf. Failure to update
    config.guess/config.sub does not return error (fixes issue #672)
  * CMake: fix CMake 4.0 warning when minimum required version is < 3.10.
  * CMake: Add build option tiff-static (fixes issue #709)
  Library changes:
  * Add TIFFOpenOptionsSetWarnAboutUnknownTags() for explicit control
    about emitting warnings for unknown tags. No longer emit warnings
    about unknown tags by default
  * tif_predict.c: speed-up decompression in some cases.

* Bug fixes:

  * tif_fax3: For fax group 3 data if no EOL is detected, reading is
    retried without synchronisation for EOLs. (fixes issue #54)
  * Updating TIFFMergeFieldInfo() with read_count=write_count=0 for
    FIELD_IGNORE. Updating TIFFMergeFieldInfo() with read_count=write_count=0 for
    FIELD_IGNORE. Improving handling when field_name = NULL. (fixes issue #532)
  * tiff.h: add COMPRESSION_JXL_DNG_1_7=52546 as used for JPEGXL compression in
    the DNG 1.7 specification
  * TIFFWriteDirectorySec: Increment string length for ASCII tags for codec tags
    defined with FIELD_xxx bits, as it is done for FIELD_CUSTOM tags. (fixes issue #648)
  * Do not error out on a tag whose tag count value is zero, just issue a warning.
    Fix parsing a private tag 0x80a6 (fixes issue #647)
  * TIFFDefaultTransferFunction(): give up beyond td_bitspersample = 24
    Fixes https://github.com/OSGeo/gdal/issues/10875)
  * tif_getimage.c: Remove unnecessary calls to TIFFRGBAImageOK() (fixes issue #175)
  * Fix writing a Predictor=3 file with non-native endianness
  * _TIFFVSetField(): fix potential use of unallocated memory (out-of-bounds
  * read / nullptr dereference) in case of out-of-memory situation when dealing with
    custom tags (fixes issue #663)
  * tif_fax3.c: Error out for CCITT fax encoding if SamplesPerPixel is not equal 1 and
    PlanarConfiguration = Contiguous (fixes issue #26)
  * tif_fax3.c: error out after a number of times end-of-line or unexpected bad code
    words have been reached. (fixes issue #670)
  * Fix memory leak in TIFFSetupStrips() (fixes issue #665)
  * tif_zip.c: Provide zlib allocation functions. Otherwise for zlib built with
    -DZ_SOLO inflating will fail.
  * Fix memory leak in _TIFFSetDefaultCompressionState. (fixes issue #676)
  * tif_predict.c: Don’t overwrite input buffer of TIFFWriteScanline() if 'prediction'
    is enabled. Use extra working buffer in PredictorEncodeRow(). (fixes issue #5)
  * tif_getimage.c: update some integer overflow checks (fixes issue #79)
  * tif_getimage.c: Fix buffer underflow crash for less raster rows at
    TIFFReadRGBAImageOriented() (fixes issue #704, bsc#1250413, CVE-2025-9900)
  * TIFFReadRGBAImage(): several fixes to avoid buffer overflows.
  * Correct passing arguments to TIFFCvtIEEEFloatToNative() and TIFFCvtIEEEDoubleToNative()
    if HAVE_IEEEFP is not defined. (fixes issue #699)
  * LZWDecode(): avoid nullptr dereference when trying to read again after EOI marker
    has been found with remaining output bytes (fixes issue #698)
  * TIFFSetSubDirectory(): check _TIFFCheckDirNumberAndOffset() return.
  * TIFFUnlinkDirectory() and TIFFWriteDirectorySec(): clear tif_rawcp when clearing
    tif_rawdata (fixes issue #711)
  * JPEGEncodeRaw(): error out if a previous scanline failed to be written, to avoid
    out-of-bounds access (fixes issue #714)
  * tif_jpeg: Fix bug in JPEGDecodeRaw() if JPEG_LIB_MK1_OR_12BIT is defined for 8/12bit
    dual mode, introduced in libjpeg-turbo 2.2, which was actually released as 3.0.
    Fixes issue #717
  * add assert for TIFFReadCustomDirectory infoarray check.
  * ppm2tiff: Fix bug in pack_words trailing bytes, where last two bytes of each line
    were written wrongly. (fixes issue #467)
  * fax2ps: fix regression of commit 28c38d648b64a66c3218778c4745225fe3e3a06d where
    TIFFTAG_FAXFILLFUNC is being used rather than an output buffer (fixes issue #649)
  * tiff2pdf: Check TIFFTAG_TILELENGTH and TIFFTAGTILEWIDTH (fixes issue #650)
  * tiff2pdf: check h_samp and v_samp for range 1 to 4 to avoid division by zero.
    Fixes issue #654
  * tiff2pdf: avoid null pointer dereference. (fixes issue #741)
  * Improve non-secure integer overflow check (comparison of division result with
    multiplicant) at compiler optimisation in tiffcp, rgb2ycbcr and tiff2rgba.
    Fixes issue #546
  * tiff2rgba: fix some 'a partial expression can generate an overflow before it is
    assigned to a broader type' warnings. (fixes issue #682)
  * tiffdither/tiffmedian: Don't skip the first line of the input image. (fixes issue #703)
  * tiffdither: avoid out-of-bounds read identified in issue #733
  * tiffmedian: error out if TIFFReadScanline() fails (fixes issue #707)
  * tiffmedian: close input file. (fixes issue #735)
  * thumbail: avoid potential out of bounds access (fixes issue #715)
  * tiffcrop: close open TIFF files and release allocated buffers before exiting in case
    of error to avoid memory leaks. (fixes issue #716)
  * tiffcrop: fix double-free and memory leak exposed by issue #721
  * tiffcrop: avoid buffer overflow. (fixes issue #740)
  * tiffcrop: avoid nullptr dereference. (fixes issue #734)
  * tiffdump: Fix coverity scan issue CID 1373365: Passing tainted expression *datamem
    to PrintData, which uses it as a divisor or modulus.
  * tiff2ps: check return of TIFFGetFiled() for TIFFTAG_STRIPBYTECOUNTS and
    TIFFTAG_TILEBYTECOUNTS to avoid NULL pointer dereference. (fixes issue #718)
  * tiffcmp: fix memory leak when second file cannot be opened. (fixes issue #718 and issue #729)
  * tiffcp: fix setting compression level for lossless codecs. (fixes issue #730)
  * raw2tiff: close input file before exit (fixes issue #742)
  Tools changes:
  * tiffinfo: add a -W switch to warn about unknown tags.
  * tiffdither: process all pages in input TIFF file.

* Documentation:

  * TIFFRGBAImage.rst note added for incorrect saving of images with TIFF orientation
    from 5 (LeftTop) to 8 (LeftBottom) in the raster.
  * TIFFRGBAImage.rst note added about un-associated alpha handling (fixes issue #67)
  * Update 'Defining New TIFF Tags' description. (fixes issue #642)
  * Fix return type of TIFFReadEncodedTile()
  * Update the documentation to reflect deprecated typedefs.
  * TIFFWriteDirectory.rst: Clarify TIFFSetWriteOffset() only sets offset for image
    data and not for IFD data.
  * Update documentation on re-entrancy and thread safety.
  * Remove dead links to no more existing Awaresystems web-site.
  * Updating BigTIFF specification and some miscelaneous editions.
  * Replace some last links and remove last todos.
  * Added hints for correct allocation of TIFFYCbCrtoRGB structure and its
    associated buffers. (fixes issue #681)
  * Added chapter to 'Using the TIFF Library' with links to handling multi-page TIFF
    and custom directories. (fixes issue #43)
  * update TIFFOpen.rst with the return values of mapproc and unmapproc. (fixes issue #12)

Security issues fixed:

  * CVE-2025-8961: Fix segmentation fault via main function of tiffcrop utility [bsc#1248117]
  * CVE-2025-8534: Fix null pointer dereference in function PS_Lvl2page [bsc#1247582]
  * CVE-2025-9165: Fix local execution manipulation can lead to memory leak [bsc#1248330]
  * CVE-2024-13978: Fix null pointer dereference in tiff2pdf [bsc#1247581]
  * CVE-2025-8176: Fix heap use-after-free in tools/tiffmedian.c [bsc#1247108]
  * CVE-2025-8177: Fix possible buffer overflow in tools/thumbnail.c:setrow()  [bsc#1247106]

- Fix TIFFMergeFieldInfo() read_count=write_count=0 (bsc#1243503)


-----------------------------------------------------------------
Advisory ID: 27
Released:    Wed Nov 19 10:41:40 2025
Summary:     Recommended update for wpa_supplicant
Type:        recommended
Severity:    moderate
References:  
This update for wpa_supplicant fixes the following issues:

- Build wpa_gui with qt6 instead of obsolete qt5
- Update build config:
  * Enable 802.11ax support

-----------------------------------------------------------------
Advisory ID: 26
Released:    Wed Nov 19 10:43:19 2025
Summary:     Recommended update for dracut
Type:        recommended
Severity:    important
References:  1238848
This update for dracut fixes the following issues:

- Additional fixes for PXE boot with filled-in NBFT (bsc#1238848):
    * fix (74nvmf): make sure autoconnect script is run at least once
    * fix (74nvmf): only set netroot if it's yet empty

-----------------------------------------------------------------
Advisory ID: 46
Released:    Thu Nov 20 17:44:20 2025
Summary:     Security update for runc
Type:        security
Severity:    important
References:  1252110,1252232,CVE-2025-31133,CVE-2025-52565,CVE-2025-52881
This update for runc fixes the following issues:

- Update to runc v1.3.3:
  * CVE-2025-31133, CVE-2025-52565, CVE-2025-52881: Fixed container breakouts by bypassing
    runc's restrictions for writing to arbitrary /proc files (bsc#1252232)

-----------------------------------------------------------------
Advisory ID: 49
Released:    Mon Nov 24 18:01:34 2025
Summary:     Recommended update for colord
Type:        recommended
Severity:    moderate
References:  
This update for colord fixes the following issues:

- Update to version 1.4.8:
  + New Features:
    - Add AppStream metainfo XML with hardware provide info.
    - Add support for -Dsystemd_root_prefix to make local building
      easier.
    - Install sysusers.d config file if configured user is not
      root.
  + Bugfixes:
    - Add the source attribute for each man page.
    - Drop component type from AppStream metadata XML to avoid
      parsing error.
    - Fix a critical warning when running the self tests.
    - Fix USB scanners not working with RestrictAddressFamilies.
    - Fix writing to the database with ProtectSystem=strict.
    - Properly set the status to CD_SESSION_STATUS_RUNNING.
    - Use g_ascii_strtod instead of atof().
    - Use sqlite3_errmsg() to avoid getting a mutable error
      message.

- Changes from version 1.4.7:
  + Bugfixes:
    - Add various hardenings to the systemd service.
    - Always close the ICC profile when loading fails.
    - Avoid destructing LCMS plugin twice with lcms 2.14.
    - Do not make state files executable in tmpfiles.d/colord.conf.
    - Fix a double free spotted by Coverity.
    - Fix an error check when parsing the DTP94 data.
    - Fix a -Wincompatible-pointer-types warning.
    - Fix potential crash when reading from broken Huey hardware.
    - Set FILE_OFFSET_BITS explicitly.
    - Use a 64-bit time_t.
    - Use thread context for Gamut Alarm codes.

-----------------------------------------------------------------
Advisory ID: 54
Released:    Tue Nov 25 17:12:46 2025
Summary:     Recommended update for multipath-tools
Type:        recommended
Severity:    moderate
References:  1253260
This update for multipath-tools fixes the following issues:

- Fixes from upstream 0.11.3 (bsc#1253260)
    * Improved the communication with **udev** and **systemd** by triggering
      uevents when path devices are added to or removed from multipath maps,
      or when `multipathd reconfigure` is executed after changing blacklist
      directives in `multipath.conf`.
    * Failed paths should be checked every `polling_interval`. In certain cases,
      this wouldn't happen, because the check interval wasn't reset by multipathd.
    * It could happen that multipathd would accidentally release a SCSI persistent
      reservation held by another node.
    * After manually failing some paths and then reinstating them, sometimes
      the reinstated paths were immediately failed again by multipathd.
    * Various minor fixes reported by coverity.


The following package changes have been done:

- libexpat1-2.7.1-160000.3.1 updated
- dracut-059+suse.700.g40f7c5c4-160000.1.1 updated
- wpa_supplicant-2.11-160000.3.1 updated
- kpartx-0.11.3+184+suse.e1501732-160000.1.1 updated
- libxslt1-1.1.43-160000.3.1 updated
- runc-1.3.3-160000.1.1 updated
- libtiff6-4.7.1-160000.1.1 updated
- libcolord2-1.4.8-160000.1.1 updated
- libmpath0-0.11.3+184+suse.e1501732-160000.1.1 updated
- multipath-tools-0.11.3+184+suse.e1501732-160000.1.1 updated
- selinux-policy-20250627+git239.fcbf2d509-160000.1.1 updated
- selinux-policy-targeted-20250627+git239.fcbf2d509-160000.1.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-eed3216f44346e966f8ec1aa82ecac4b17c6b24f06daeaccd98bfcfc2da3cd21-0 added
- container:SL-Micro-base-container-2.3.0-6.1 removed


More information about the sle-container-updates mailing list