From sle-container-updates at lists.suse.com Sat Aug 1 07:14:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:14:53 +0200 (CEST) Subject: SUSE-CU-2026:7745-1: Security update of private-registry/1.2/harbor-core Message-ID: <20260801071453.B4B8BFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7745-1 Container Tags : private-registry/1.2/harbor-core:1.2.0 , private-registry/1.2/harbor-core:1.2.0-1.64 , private-registry/1.2/harbor-core:latest Container Release : 1.64 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - harbor-core-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:15:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:15:08 +0200 (CEST) Subject: SUSE-CU-2026:7746-1: Security update of private-registry/1.2/harbor-exporter Message-ID: <20260801071508.E88DDFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7746-1 Container Tags : private-registry/1.2/harbor-exporter:1.2.0 , private-registry/1.2/harbor-exporter:1.2.0-1.64 , private-registry/1.2/harbor-exporter:latest Container Release : 1.64 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - harbor-exporter-2.15.1-150700.1.23 updated - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:15:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:15:24 +0200 (CEST) Subject: SUSE-CU-2026:7747-1: Security update of private-registry/1.2/harbor-jobservice Message-ID: <20260801071524.DC823FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7747-1 Container Tags : private-registry/1.2/harbor-jobservice:1.2.0 , private-registry/1.2/harbor-jobservice:1.2.0-1.62 , private-registry/1.2/harbor-jobservice:latest Container Release : 1.62 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - harbor-jobservice-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:15:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:15:44 +0200 (CEST) Subject: SUSE-CU-2026:7748-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260801071544.6FA76FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7748-1 Container Tags : private-registry/1.2/harbor-portal:1.2.0 , private-registry/1.2/harbor-portal:1.2.0-1.71 , private-registry/1.2/harbor-portal:latest Container Release : 1.71 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - harbor-portal-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:16:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:16:01 +0200 (CEST) Subject: SUSE-CU-2026:7749-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260801071601.113A6FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7749-1 Container Tags : private-registry/1.2/harbor-registry:1.2.0 , private-registry/1.2/harbor-registry:1.2.0-1.63 , private-registry/1.2/harbor-registry:latest Container Release : 1.63 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:16:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:16:17 +0200 (CEST) Subject: SUSE-CU-2026:7750-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260801071617.CC6E9FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7750-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.0 , private-registry/1.2/harbor-registryctl:1.2.0-1.63 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.63 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - harbor-registryctl-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:16:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:16:39 +0200 (CEST) Subject: SUSE-CU-2026:7751-1: Security update of private-registry/1.2/harbor-trivy-adapter Message-ID: <20260801071639.1264AFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7751-1 Container Tags : private-registry/1.2/harbor-trivy-adapter:1.2.0 , private-registry/1.2/harbor-trivy-adapter:1.2.0-1.70 , private-registry/1.2/harbor-trivy-adapter:latest Container Release : 1.70 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/1.2/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.15.1-150700.1.23 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:18:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:18:15 +0200 (CEST) Subject: SUSE-CU-2026:7752-1: Security update of private-registry/harbor-core Message-ID: <20260801071815.A680EFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7752-1 Container Tags : private-registry/harbor-core:1.1.3 , private-registry/harbor-core:1.1.3-2.79 , private-registry/harbor-core:latest Container Release : 2.79 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated - harbor-core-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:19:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:19:38 +0200 (CEST) Subject: SUSE-CU-2026:7753-1: Security update of private-registry/harbor-exporter Message-ID: <20260801071938.6DD44FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7753-1 Container Tags : private-registry/harbor-exporter:1.1.3 , private-registry/harbor-exporter:1.1.3-2.80 , private-registry/harbor-exporter:latest Container Release : 2.80 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - harbor-exporter-2.14.4-150700.1.25 updated - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:20:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:20:56 +0200 (CEST) Subject: SUSE-CU-2026:7754-1: Security update of private-registry/harbor-jobservice Message-ID: <20260801072056.5E972FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7754-1 Container Tags : private-registry/harbor-jobservice:1.1.3 , private-registry/harbor-jobservice:1.1.3-2.79 , private-registry/harbor-jobservice:latest Container Release : 2.79 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated - harbor-jobservice-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:22:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:22:18 +0200 (CEST) Subject: SUSE-CU-2026:7755-1: Security update of private-registry/harbor-portal Message-ID: <20260801072218.3E849FDA4@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7755-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.88 , private-registry/harbor-portal:latest Container Release : 2.88 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated - harbor-portal-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:22:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:22:57 +0200 (CEST) Subject: SUSE-CU-2026:7756-1: Security update of private-registry/harbor-registry Message-ID: <20260801072257.62085FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7756-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.79 , private-registry/harbor-registry:latest Container Release : 2.79 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:24:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:24:17 +0200 (CEST) Subject: SUSE-CU-2026:7757-1: Security update of private-registry/harbor-registryctl Message-ID: <20260801072417.67B14FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7757-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.80 , private-registry/harbor-registryctl:latest Container Release : 2.80 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated - harbor-registryctl-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:25:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:25:37 +0200 (CEST) Subject: SUSE-CU-2026:7758-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260801072537.6A800FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7758-1 Container Tags : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.89 , private-registry/harbor-trivy-adapter:latest Container Release : 2.89 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.14.4-150700.1.25 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:25:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:25:47 +0200 (CEST) Subject: SUSE-CU-2026:7759-1: Security update of private-registry/harbor-core Message-ID: <20260801072547.7B8E5FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-core ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7759-1 Container Tags : private-registry/harbor-core:2.13 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5 , private-registry/harbor-core:2.13.5-1.31 , private-registry/harbor-core:2.13.5-1.31 , private-registry/harbor-core:latest Container Release : 1.31 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-core was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - harbor213-core-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:25:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:25:55 +0200 (CEST) Subject: SUSE-CU-2026:7760-1: Security update of private-registry/harbor-exporter Message-ID: <20260801072555.BAEE3FDC8@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-exporter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7760-1 Container Tags : private-registry/harbor-exporter:2.13 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5 , private-registry/harbor-exporter:2.13.5-1.31 , private-registry/harbor-exporter:2.13.5-1.31 , private-registry/harbor-exporter:latest Container Release : 1.31 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-exporter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - harbor213-exporter-2.13.5-150700.1.15 updated - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:26:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:26:05 +0200 (CEST) Subject: SUSE-CU-2026:7761-1: Security update of private-registry/harbor-jobservice Message-ID: <20260801072605.271BCFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-jobservice ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7761-1 Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.31 , private-registry/harbor-jobservice:2.13.5-1.31 , private-registry/harbor-jobservice:latest Container Release : 1.31 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-jobservice was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - harbor213-jobservice-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:26:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:26:15 +0200 (CEST) Subject: SUSE-CU-2026:7762-1: Security update of private-registry/harbor-portal Message-ID: <20260801072615.75C66FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7762-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.34 , private-registry/harbor-portal:2.13.5-1.34 , private-registry/harbor-portal:latest Container Release : 1.34 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - harbor213-portal-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:26:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:26:24 +0200 (CEST) Subject: SUSE-CU-2026:7763-1: Security update of private-registry/harbor-registry Message-ID: <20260801072624.BECB4FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7763-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.31 , private-registry/harbor-registry:latest Container Release : 1.31 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:26:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:26:34 +0200 (CEST) Subject: SUSE-CU-2026:7764-1: Security update of private-registry/harbor-registryctl Message-ID: <20260801072634.0737EFD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7764-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.30 , private-registry/harbor-registryctl:2.13.5-1.30 , private-registry/harbor-registryctl:latest Container Release : 1.30 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - harbor213-registryctl-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sat Aug 1 07:26:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 1 Aug 2026 09:26:43 +0200 (CEST) Subject: SUSE-CU-2026:7765-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260801072643.A4592FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7765-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.33 , private-registry/harbor-trivy-adapter:latest Container Release : 1.33 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:05:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:05:49 +0200 (CEST) Subject: SUSE-CU-2026:7765-1: Security update of private-registry/harbor-trivy-adapter Message-ID: <20260802070549.8DFD1FDA4@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-trivy-adapter ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7765-1 Container Tags : private-registry/harbor-trivy-adapter:0.35.1 , private-registry/harbor-trivy-adapter:0.35.1-1.33 , private-registry/harbor-trivy-adapter:latest Container Release : 1.33 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - system-user-harbor-2.13.5-150700.1.15 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:29:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:29:01 +0200 (CEST) Subject: SUSE-CU-2026:7766-1: Security update of bci/golang Message-ID: <20260802072901.3A8E0FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7766-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.12-openssl , bci/golang:1.25.12-openssl-89.24 , bci/golang:oldstable-openssl Container Release : 89.24 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl-3-devel-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:29:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:29:55 +0200 (CEST) Subject: SUSE-CU-2026:7767-1: Security update of suse/kea Message-ID: <20260802072955.9C1F5FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7767-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.4 Container Release : 79.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:31:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:31:24 +0200 (CEST) Subject: SUSE-CU-2026:7768-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260802073124.9F8D3FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7768-1 Container Tags : suse/kiosk/firefox-esr:140.13 , suse/kiosk/firefox-esr:140.13-75.4 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:39 +0200 (CEST) Subject: SUSE-CU-2026:7580-1: Security update of suse/postgres Message-ID: <20260802073239.AF009FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7580-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-92.16 Container Release : 92.16 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:41 +0200 (CEST) Subject: SUSE-CU-2026:7769-1: Security update of suse/postgres Message-ID: <20260802073241.C547AFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7769-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-92.18 Container Release : 92.18 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:44 +0200 (CEST) Subject: SUSE-CU-2026:7771-1: Security update of suse/postgres Message-ID: <20260802073244.7D188FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7771-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-92.21 Container Release : 92.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:42 +0200 (CEST) Subject: SUSE-CU-2026:7770-1: Security update of suse/postgres Message-ID: <20260802073242.E38FDFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7770-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-92.20 Container Release : 92.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:47 +0200 (CEST) Subject: SUSE-CU-2026:7773-1: Security update of suse/postgres Message-ID: <20260802073247.DBE3CFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7773-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-93.2 Container Release : 93.2 Severity : moderate Type : security References : 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:32:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:32:49 +0200 (CEST) Subject: SUSE-CU-2026:7774-1: Security update of suse/postgres Message-ID: <20260802073249.06B81FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7774-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-93.4 Container Release : 93.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:43 +0200 (CEST) Subject: SUSE-CU-2026:7775-1: Security update of suse/postgres Message-ID: <20260802073343.3C121FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7775-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-82.14 Container Release : 82.14 Severity : important Type : security References : 1252306 1253043 1257463 1269790 1270393 CVE-2026-11979 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:46 +0200 (CEST) Subject: SUSE-CU-2026:7777-1: Security update of suse/postgres Message-ID: <20260802073346.34DA3FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7777-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-82.18 Container Release : 82.18 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:44 +0200 (CEST) Subject: SUSE-CU-2026:7776-1: Security update of suse/postgres Message-ID: <20260802073344.CD19BFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7776-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-82.17 Container Release : 82.17 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:47 +0200 (CEST) Subject: SUSE-CU-2026:7778-1: Security update of suse/postgres Message-ID: <20260802073347.8286AFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7778-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-82.20 Container Release : 82.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:49 +0200 (CEST) Subject: SUSE-CU-2026:7779-1: Security update of suse/postgres Message-ID: <20260802073349.418B6FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7779-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-82.21 Container Release : 82.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:50 +0200 (CEST) Subject: SUSE-CU-2026:7780-1: Security update of suse/postgres Message-ID: <20260802073350.B1E86FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7780-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.2 Container Release : 83.2 Severity : moderate Type : security References : 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:33:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:33:51 +0200 (CEST) Subject: SUSE-CU-2026:7781-1: Security update of suse/postgres Message-ID: <20260802073351.D32C6FDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7781-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.4 Container Release : 83.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:34:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:34:11 +0200 (CEST) Subject: SUSE-CU-2026:7782-1: Security update of suse/postgres Message-ID: <20260802073411.C91AEFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7782-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.14 Container Release : 82.14 Severity : important Type : security References : 1252306 1253043 1257463 1269790 1270393 CVE-2026-11979 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:34:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:34:13 +0200 (CEST) Subject: SUSE-CU-2026:7783-1: Security update of suse/postgres Message-ID: <20260802073413.6655AFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7783-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.16 Container Release : 82.16 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:34:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:34:14 +0200 (CEST) Subject: SUSE-CU-2026:7784-1: Security update of suse/postgres Message-ID: <20260802073415.00293FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7784-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.18 Container Release : 82.18 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Sun Aug 2 07:34:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 2 Aug 2026 09:34:16 +0200 (CEST) Subject: SUSE-CU-2026:7785-1: Security update of suse/postgres Message-ID: <20260802073416.8C9DBFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7785-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.20 Container Release : 82.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:21:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:21:21 +0200 (CEST) Subject: SUSE-CU-2026:7786-1: Security update of bci/golang Message-ID: <20260803072121.EFC6FFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7786-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.5-openssl , bci/golang:1.26.5-openssl-89.24 , bci/golang:latest , bci/golang:stable-openssl Container Release : 89.24 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl-3-devel-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:21:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:21:53 +0200 (CEST) Subject: SUSE-CU-2026:7787-1: Security update of bci/bci-micro-fips Message-ID: <20260803072153.6207EFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7787-1 Container Tags : bci/bci-micro-fips:15.7 , bci/bci-micro-fips:15.7-25.11 , bci/bci-micro-fips:latest Container Release : 25.11 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/bci-micro-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:23:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:23:31 +0200 (CEST) Subject: SUSE-CU-2026:7785-1: Security update of suse/postgres Message-ID: <20260803072331.04FDAFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7785-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.20 Container Release : 82.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:23:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:23:32 +0200 (CEST) Subject: SUSE-CU-2026:7788-1: Security update of suse/postgres Message-ID: <20260803072332.6BE2BFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7788-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-82.21 Container Release : 82.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:23:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:23:33 +0200 (CEST) Subject: SUSE-CU-2026:7789-1: Security update of suse/postgres Message-ID: <20260803072333.B8722FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7789-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-83.2 Container Release : 83.2 Severity : moderate Type : security References : 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:23:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:23:35 +0200 (CEST) Subject: SUSE-CU-2026:7790-1: Security update of suse/postgres Message-ID: <20260803072335.9A63AFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7790-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-83.4 Container Release : 83.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:05 +0200 (CEST) Subject: SUSE-CU-2026:7791-1: Security update of suse/postgres Message-ID: <20260803072405.5328BFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7791-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-72.17 , suse/postgres:latest Container Release : 72.17 Severity : important Type : security References : 1252306 1253043 1257463 1268290 1269790 1270393 CVE-2026-11979 CVE-2026-54411 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:06 +0200 (CEST) Subject: SUSE-CU-2026:7792-1: Security update of suse/postgres Message-ID: <20260803072406.B5516FDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7792-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-72.18 , suse/postgres:latest Container Release : 72.18 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:08 +0200 (CEST) Subject: SUSE-CU-2026:7793-1: Security update of suse/postgres Message-ID: <20260803072408.1B782FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7793-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-72.20 , suse/postgres:latest Container Release : 72.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:10 +0200 (CEST) Subject: SUSE-CU-2026:7795-1: Security update of suse/postgres Message-ID: <20260803072410.D5A3FFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7795-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-73.2 , suse/postgres:latest Container Release : 73.2 Severity : moderate Type : security References : 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:09 +0200 (CEST) Subject: SUSE-CU-2026:7794-1: Security update of suse/postgres Message-ID: <20260803072409.7A04DFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7794-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-72.21 , suse/postgres:latest Container Release : 72.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:12 +0200 (CEST) Subject: SUSE-CU-2026:7796-1: Security update of suse/postgres Message-ID: <20260803072412.3FD49FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7796-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-73.4 , suse/postgres:latest Container Release : 73.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:25 +0200 (CEST) Subject: SUSE-CU-2026:7226-1: Security update of suse/postgres Message-ID: <20260803072425.07115FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7226-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.4 , suse/postgres:latest Container Release : 72.4 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:26 +0200 (CEST) Subject: SUSE-CU-2026:7797-1: Recommended update of suse/postgres Message-ID: <20260803072426.63C8AFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7797-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.5 , suse/postgres:latest Container Release : 72.5 Severity : moderate Type : recommended References : 1245862 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2893-1 Released: Mon Jul 13 13:40:09 2026 Summary: Recommended update for postgresql Type: recommended Severity: moderate References: 1245862 This update for postgresql fixes the following issues: Changes in postgresql: - Get rid of update-alternatives and support immutable mode. See README.SUSE for details. (bsc#1245862, jsc#PED-14820) - Bump default to 17 for SLE-15-SP7. The following package changes have been done: - postgresql-18-150700.23.6.1 updated - postgresql-server-18-150700.23.6.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:28 +0200 (CEST) Subject: SUSE-CU-2026:7799-1: Security update of suse/postgres Message-ID: <20260803072428.B5A7DFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7799-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.8 , suse/postgres:latest Container Release : 72.8 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-locale-base-2.38-150600.14.52.1 updated - glibc-locale-2.38-150600.14.52.1 updated - container:suse-sle15-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:27 +0200 (CEST) Subject: SUSE-CU-2026:7798-1: Security update of suse/postgres Message-ID: <20260803072427.C350BFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7798-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.6 , suse/postgres:latest Container Release : 72.6 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:30 +0200 (CEST) Subject: SUSE-CU-2026:7800-1: Security update of suse/postgres Message-ID: <20260803072430.20FBEFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7800-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.14 , suse/postgres:latest Container Release : 72.14 Severity : important Type : security References : 1252306 1253043 1257463 1269790 1270393 CVE-2026-11979 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:31 +0200 (CEST) Subject: SUSE-CU-2026:7801-1: Security update of suse/postgres Message-ID: <20260803072431.1540BFE13@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7801-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.17 , suse/postgres:latest Container Release : 72.17 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:32 +0200 (CEST) Subject: SUSE-CU-2026:7802-1: Security update of suse/postgres Message-ID: <20260803072432.7B776FEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7802-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.18 , suse/postgres:latest Container Release : 72.18 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:33 +0200 (CEST) Subject: SUSE-CU-2026:7803-1: Security update of suse/postgres Message-ID: <20260803072433.D7A83FDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7803-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.20 , suse/postgres:latest Container Release : 72.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Mon Aug 3 07:24:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Mon, 3 Aug 2026 09:24:35 +0200 (CEST) Subject: SUSE-CU-2026:7804-1: Security update of suse/postgres Message-ID: <20260803072435.44B00FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7804-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.21 , suse/postgres:latest Container Release : 72.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:07:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:07:13 +0200 (CEST) Subject: SUSE-IU-2026:6042-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260804070713.C1414FDA4@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6042-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.302 , suse/sle-micro/base-5.5:latest Image Release : 5.8.302 Severity : moderate Type : security References : 1271351 1271352 1271354 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:09:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:09:33 +0200 (CEST) Subject: SUSE-IU-2026:6043-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260804070933.2196EFDA4@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6043-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.582 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.582 Severity : moderate Type : security References : 1271351 1271352 1271354 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.302 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:13:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:13:15 +0200 (CEST) Subject: SUSE-IU-2026:6044-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260804071315.04734FDC8@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6044-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.675 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.675 Severity : moderate Type : security References : 1271351 1271352 1271354 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.76 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:16:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:16:14 +0200 (CEST) Subject: SUSE-IU-2026:6045-1: Security update of suse/sle-micro/5.5 Message-ID: <20260804071614.6C0A4FD9F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6045-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.76 , suse/sle-micro/5.5:latest Image Release : 5.8.76 Severity : important Type : security References : 1268162 1271193 1271194 1271195 1271351 1271352 1271354 1271684 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857 CVE-2026-59858 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3458-1 Released: Mon Aug 3 14:00:20 2026 Summary: Security update for vim Type: security Severity: important References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for vim fixes the following issues: This update for vim fixes the following issues: Security issues fixed: - CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). - CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). - CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). Non security issue fixed: - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: - Updated to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). - Updated to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ':wqall' and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the '%' command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the '%' command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update '# and clobbers '0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support 'noclose' (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - vim-data-common-9.2.0780-150500.20.61.2 updated - vim-small-9.2.0780-150500.20.61.2 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.302 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:22:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:22:10 +0200 (CEST) Subject: SUSE-CU-2026:7811-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260804072210.31799FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7811-1 Container Tags : private-registry/1.2/harbor-portal:1.2.0 , private-registry/1.2/harbor-portal:1.2.0-1.74 , private-registry/1.2/harbor-portal:latest Container Release : 1.74 Severity : important Type : security References : 1271514 CVE-2026-42533 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3469-1 Released: Mon Aug 3 18:40:29 2026 Summary: Security update for nginx Type: security Severity: important References: 1271514,CVE-2026-42533 This update for nginx fixes the following issue: - CVE-2026-42533: referencing regex capture variables before map output variables can trigger a heap buffer overflow (bsc#1271514). The following package changes have been done: - nginx-1.21.5-150600.10.27.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:27:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:27:45 +0200 (CEST) Subject: SUSE-CU-2026:7819-1: Security update of private-registry/harbor-portal Message-ID: <20260804072745.09A74FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7819-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.91 , private-registry/harbor-portal:latest Container Release : 2.91 Severity : important Type : security References : 1271514 CVE-2026-42533 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3469-1 Released: Mon Aug 3 18:40:29 2026 Summary: Security update for nginx Type: security Severity: important References: 1271514,CVE-2026-42533 This update for nginx fixes the following issue: - CVE-2026-42533: referencing regex capture variables before map output variables can trigger a heap buffer overflow (bsc#1271514). The following package changes have been done: - nginx-1.21.5-150600.10.27.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:31:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:31:40 +0200 (CEST) Subject: SUSE-CU-2026:7827-1: Security update of private-registry/harbor-portal Message-ID: <20260804073140.0A287FD9F@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7827-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.37 , private-registry/harbor-portal:2.13.5-1.37 , private-registry/harbor-portal:latest Container Release : 1.37 Severity : important Type : security References : 1271514 CVE-2026-42533 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3469-1 Released: Mon Aug 3 18:40:29 2026 Summary: Security update for nginx Type: security Severity: important References: 1271514,CVE-2026-42533 This update for nginx fixes the following issue: - CVE-2026-42533: referencing regex capture variables before map output variables can trigger a heap buffer overflow (bsc#1271514). The following package changes have been done: - nginx-1.21.5-150600.10.27.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:40:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:40:40 +0200 (CEST) Subject: SUSE-CU-2026:7832-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260804074040.2C7B9FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7832-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.260 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.260 Severity : important Type : security References : 1271351 1271352 1271354 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:45:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:45:15 +0200 (CEST) Subject: SUSE-CU-2026:7833-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260804074515.72A10FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7833-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.161 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.161 Severity : important Type : security References : 1271351 1271352 1271354 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:47:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:47:57 +0200 (CEST) Subject: SUSE-CU-2026:7834-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260804074757.64F1BFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7834-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.261 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.261 Severity : important Type : security References : 1271351 1271352 1271354 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:50:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:50:20 +0200 (CEST) Subject: SUSE-CU-2026:7835-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260804075020.89C0FFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7835-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.170 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.170 Severity : important Type : security References : 1268162 1271193 1271194 1271195 1271351 1271352 1271354 1271684 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857 CVE-2026-59858 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3458-1 Released: Mon Aug 3 14:00:20 2026 Summary: Security update for vim Type: security Severity: important References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for vim fixes the following issues: This update for vim fixes the following issues: Security issues fixed: - CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194). - CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195). - CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193). Non security issue fixed: - Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). - allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: - Updated to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). - Updated to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ':wqall' and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the '%' command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the '%' command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update '# and clobbers '0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support 'noclose' (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - vim-data-common-9.2.0780-150500.20.61.2 updated - vim-9.2.0780-150500.20.61.2 updated From sle-container-updates at lists.suse.com Tue Aug 4 07:52:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 09:52:45 +0200 (CEST) Subject: SUSE-IU-2026:6046-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260804075245.07891FD9F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6046-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.156 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.156 Severity : important Type : security References : 1230797 1239461 1269892 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2025-24912 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58374 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 642 Released: Fri Jul 31 11:07:43 2026 Summary: Security update for wpa_supplicant Type: security Severity: moderate References: 1230797,1239461,1269892,CVE-2025-24912,CVE-2026-58374 This update for wpa_supplicant fixes the following issues: Security issues fixed: - CVE-2025-24912: RADIUS pending request dropping (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/. Other updates and bugfixes: - Revert 'Mark authorization completed on driver indication during 4-way HS offload' because of WPA2-PSK/WPA-SAE connection problems with brcmfmac wifi hardware (bsc#1230797). ----------------------------------------------------------------- Advisory ID: 647 Released: Mon Aug 3 09:43:21 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.59 updated - libglib-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_7.1 updated - glib2-tools-2.78.6-slfo.1.1_7.1 updated - wpa_supplicant-2.11-slfo.1.1_2.1 updated - container:SL-Micro-container-2.2.1-7.142 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:15:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:15:18 +0200 (CEST) Subject: SUSE-CU-2026:7841-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260804081518.AA999FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7841-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.39 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.39 , suse/ltss/sle15.4/sle15:latest Container Release : 6.39 Severity : important Type : security References : 1246974 1249375 1258045 1258049 1258054 1258080 1258081 1259377 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2025-8114 CVE-2025-8277 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3788-1 Released: Fri Oct 24 15:28:50 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1565-1 Released: Thu Apr 23 09:08:29 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,1259377,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). - CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:19:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:19:34 +0200 (CEST) Subject: SUSE-CU-2026:7842-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260804081934.C6249FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7842-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.58 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.58 , suse/ltss/sle15.5/sle15:latest Container Release : 8.58 Severity : moderate Type : security References : 1246974 1249375 1258045 1258049 1258054 1258080 1258081 1259377 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2025-8114 CVE-2025-8277 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3788-1 Released: Fri Oct 24 15:28:50 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1565-1 Released: Thu Apr 23 09:08:29 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,1259377,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). - CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150400.3.20.1 updated - libssh4-0.9.8-150400.3.20.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:22:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:22:05 +0200 (CEST) Subject: SUSE-CU-2026:7843-1: Security update of bci/dotnet-aspnet Message-ID: <20260804082205.E5E9BFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7843-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.10 , bci/dotnet-aspnet:10.0.10-27.4 , bci/dotnet-aspnet:latest Container Release : 27.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:23:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:23:06 +0200 (CEST) Subject: SUSE-CU-2026:7844-1: Security update of bci/dotnet-aspnet Message-ID: <20260804082306.B37B5FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7844-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.29 , bci/dotnet-aspnet:8.0.29-97.4 Container Release : 97.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:24:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:24:01 +0200 (CEST) Subject: SUSE-CU-2026:7845-1: Security update of bci/dotnet-aspnet Message-ID: <20260804082401.9E112FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7845-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.18 , bci/dotnet-aspnet:9.0.18-56.4 Container Release : 56.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:25:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:25:07 +0200 (CEST) Subject: SUSE-CU-2026:7846-1: Security update of bci/bci-base-fips Message-ID: <20260804082507.51E0FFDA4@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7846-1 Container Tags : bci/bci-base-fips:15.7 , bci/bci-base-fips:15.7-22.12 , bci/bci-base-fips:latest Container Release : 22.12 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:25:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:25:52 +0200 (CEST) Subject: SUSE-CU-2026:7847-1: Security update of bci/dotnet-sdk Message-ID: <20260804082552.8C0E9FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7847-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.10 , bci/dotnet-sdk:10.0.10-27.4 , bci/dotnet-sdk:latest Container Release : 27.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:27:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:27:13 +0200 (CEST) Subject: SUSE-CU-2026:7848-1: Security update of bci/dotnet-sdk Message-ID: <20260804082713.4BEA9FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7848-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.29 , bci/dotnet-sdk:8.0.29-97.4 Container Release : 97.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 08:28:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 10:28:16 +0200 (CEST) Subject: SUSE-CU-2026:7849-1: Security update of bci/dotnet-sdk Message-ID: <20260804082816.E35F9FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7849-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.18 , bci/dotnet-sdk:9.0.18-57.4 Container Release : 57.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:45:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:45:49 +0200 (CEST) Subject: SUSE-CU-2026:7849-1: Security update of bci/dotnet-sdk Message-ID: <20260804114549.8D05EFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7849-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.18 , bci/dotnet-sdk:9.0.18-57.4 Container Release : 57.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:46:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:46:43 +0200 (CEST) Subject: SUSE-CU-2026:7850-1: Security update of bci/dotnet-runtime Message-ID: <20260804114643.5B555FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7850-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.10 , bci/dotnet-runtime:10.0.10-27.4 , bci/dotnet-runtime:latest Container Release : 27.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:48:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:48:02 +0200 (CEST) Subject: SUSE-CU-2026:7851-1: Security update of bci/dotnet-runtime Message-ID: <20260804114802.A1F20FD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7851-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.29 , bci/dotnet-runtime:8.0.29-97.4 Container Release : 97.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:49:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:49:22 +0200 (CEST) Subject: SUSE-CU-2026:7852-1: Security update of bci/dotnet-runtime Message-ID: <20260804114922.77F3DFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7852-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.18 , bci/dotnet-runtime:9.0.18-56.4 Container Release : 56.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:50:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:50:52 +0200 (CEST) Subject: SUSE-CU-2026:7853-1: Security update of bci/golang Message-ID: <20260804115052.BA07CFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7853-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.5-openssl , bci/golang:1.26.5-openssl-89.26 , bci/golang:latest , bci/golang:stable-openssl Container Release : 89.26 Severity : moderate Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:51:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:51:56 +0200 (CEST) Subject: SUSE-CU-2026:7854-1: Security update of bci/bci-init Message-ID: <20260804115156.C6C4AFD9F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7854-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.27 , bci/bci-init:latest Container Release : 53.27 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:52:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:52:54 +0200 (CEST) Subject: SUSE-CU-2026:7855-1: Security update of suse/postgres Message-ID: <20260804115254.9976DFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7855-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.5 Container Release : 93.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:54:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:54:50 +0200 (CEST) Subject: SUSE-CU-2026:7804-1: Security update of suse/postgres Message-ID: <20260804115450.C6534FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7804-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-72.21 , suse/postgres:latest Container Release : 72.21 Severity : important Type : security References : 1269622 CVE-2026-41991 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:54:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:54:52 +0200 (CEST) Subject: SUSE-CU-2026:7856-1: Security update of suse/postgres Message-ID: <20260804115452.C3594FDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7856-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-73.2 , suse/postgres:latest Container Release : 73.2 Severity : moderate Type : security References : 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:54:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:54:54 +0200 (CEST) Subject: SUSE-CU-2026:7857-1: Security update of suse/postgres Message-ID: <20260804115454.7177EFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7857-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-73.4 , suse/postgres:latest Container Release : 73.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:55:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:55:58 +0200 (CEST) Subject: SUSE-CU-2026:7858-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115558.2D0DBFD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7858-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.11 , suse/kiosk/pulseaudio:latest Container Release : 72.11 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-0180bc786e784f4f99302a008c5991e2d05f7fac404ce0fa2a07aaef564e6ef8-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:55:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:55:59 +0200 (CEST) Subject: SUSE-CU-2026:7859-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115559.9BCA8FDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7859-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.16 , suse/kiosk/pulseaudio:latest Container Release : 72.16 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:suse-sle15-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated - container:registry.suse.com-bci-bci-micro-15.7-cbe2687a5ef4608cef82a7e320e3b24974f14b1fd2e641e107ef12eb62001a09-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:00 +0200 (CEST) Subject: SUSE-CU-2026:7860-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115600.ED0FDFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7860-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.17 , suse/kiosk/pulseaudio:latest Container Release : 72.17 Severity : important Type : security References : 1269790 CVE-2026-11979 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - libxml2-2-2.12.10-150700.4.14.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:02 +0200 (CEST) Subject: SUSE-CU-2026:7861-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260804115602.3B12FFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7861-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.18 , suse/kiosk/pulseaudio:latest Container Release : 72.18 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3106-1 Released: Fri Jul 17 16:02:05 2026 Summary: Recommended update for kmod Type: recommended Severity: moderate References: This update for kmod fixes the following issues: - Use in-kernel decompression if available (jsc#PED-16303): * libkmod: + Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. + Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. + Don't only set the type as direct, but also keep track of the compression being used. + When creating the context, read /sys/kernel/compression to check. what's the compression type supported by the kernel. + Use kernel decompression when available + add fallback MODULE_INIT_COMPRESSED_FILE define The following package changes have been done: - libkmod2-29-150600.13.6.1 updated - kmod-29-150600.13.6.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:03 +0200 (CEST) Subject: SUSE-CU-2026:7862-1: Recommended update of suse/kiosk/pulseaudio Message-ID: <20260804115603.7E0A8FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7862-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.19 , suse/kiosk/pulseaudio:latest Container Release : 72.19 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgomp1-15.3.0+git11272-150000.1.12.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:04 +0200 (CEST) Subject: SUSE-CU-2026:7863-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115604.B7740FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7863-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.23 , suse/kiosk/pulseaudio:latest Container Release : 72.23 Severity : important Type : security References : 1268290 1270393 CVE-2026-54411 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:07 +0200 (CEST) Subject: SUSE-CU-2026:7865-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115607.244B1FD9F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7865-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.27 , suse/kiosk/pulseaudio:latest Container Release : 72.27 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libudev1-254.27-150600.4.71.2 updated - libsystemd0-254.27-150600.4.71.2 updated - systemd-254.27-150600.4.71.2 updated - udev-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:05 +0200 (CEST) Subject: SUSE-CU-2026:7864-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115605.EFA97FEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7864-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.25 , suse/kiosk/pulseaudio:latest Container Release : 72.25 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:08 +0200 (CEST) Subject: SUSE-CU-2026:7866-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115608.55B2EFDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7866-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-72.28 , suse/kiosk/pulseaudio:latest Container Release : 72.28 Severity : important Type : security References : 1268853 1269622 CVE-2026-41991 CVE-2026-56109 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3270-1 Released: Mon Jul 27 13:01:22 2026 Summary: Security update for alsa Type: security Severity: moderate References: 1268853,CVE-2026-56109 This update for alsa fixes the following issue - CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). The following package changes have been done: - libasound2-1.2.10-150600.4.3.1 updated - gzip-1.10-150200.13.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:10 +0200 (CEST) Subject: SUSE-CU-2026:7868-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115610.5A5D2FDC9@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7868-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.2 , suse/kiosk/pulseaudio:latest Container Release : 73.2 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 11:56:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 13:56:11 +0200 (CEST) Subject: SUSE-CU-2026:7869-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804115611.86CBFFF02@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7869-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.4 , suse/kiosk/pulseaudio:latest Container Release : 73.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:41:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:41:51 +0200 (CEST) Subject: SUSE-CU-2026:7870-1: Security update of bci/openjdk-devel Message-ID: <20260804134151.1EA8BFD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7870-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.0 , bci/openjdk-devel:17.0.20.0-21.33 Container Release : 21.33 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - container:bci-openjdk-17-15.7.17-20.29 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:43:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:43:08 +0200 (CEST) Subject: SUSE-CU-2026:7871-1: Security update of bci/openjdk Message-ID: <20260804134308.9B83FFD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7871-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.0 , bci/openjdk:17.0.20.0-20.29 Container Release : 20.29 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:44:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:44:20 +0200 (CEST) Subject: SUSE-CU-2026:7872-1: Security update of bci/openjdk-devel Message-ID: <20260804134420.71E97FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7872-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.0 , bci/openjdk-devel:21.0.12.0-25.33 Container Release : 25.33 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - container:bci-openjdk-21-15.7.21-24.28 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:45:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:45:26 +0200 (CEST) Subject: SUSE-CU-2026:7873-1: Security update of bci/openjdk Message-ID: <20260804134526.49368FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7873-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.0 , bci/openjdk:21.0.12.0-24.28 Container Release : 24.28 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:46:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:46:42 +0200 (CEST) Subject: SUSE-CU-2026:7874-1: Security update of bci/php-apache Message-ID: <20260804134642.0C941FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7874-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.32 , bci/php-apache:8.3.32-25.5 , bci/php-apache:latest Container Release : 25.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:47:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:47:37 +0200 (CEST) Subject: SUSE-CU-2026:7875-1: Security update of bci/php-fpm Message-ID: <20260804134737.8FAE1FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7875-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.32 , bci/php-fpm:8.3.32-25.5 , bci/php-fpm:latest Container Release : 25.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:48:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:48:36 +0200 (CEST) Subject: SUSE-CU-2026:7876-1: Security update of bci/php Message-ID: <20260804134836.4546BFD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7876-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.32 , bci/php:8.3.32-25.5 , bci/php:latest Container Release : 25.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:51:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:51:56 +0200 (CEST) Subject: SUSE-CU-2026:7869-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260804135156.B0A3CFD9B@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7869-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.4 , suse/kiosk/pulseaudio:latest Container Release : 73.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:52:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:52:57 +0200 (CEST) Subject: SUSE-CU-2026:7878-1: Security update of bci/python Message-ID: <20260804135257.1E896FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7878-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.11 Container Release : 85.11 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:52:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:52:58 +0200 (CEST) Subject: SUSE-CU-2026:7879-1: Security update of bci/python Message-ID: <20260804135258.17DE5FDA4@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7879-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.12 Container Release : 85.12 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:52:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:52:59 +0200 (CEST) Subject: SUSE-CU-2026:7880-1: Recommended update of bci/python Message-ID: <20260804135259.1B252FDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7880-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.15 Container Release : 85.15 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2972-1 Released: Tue Jul 14 13:33:14 2026 Summary: Recommended update for lifecycle-data-sle-module-development-tools Type: recommended Severity: moderate References: This update for lifecycle-data-sle-module-development-tools fixes the following issues: - lifecycle of gcc14 got extended until end of july. The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:53:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:53:00 +0200 (CEST) Subject: SUSE-CU-2026:7881-1: Security update of bci/python Message-ID: <20260804135300.1B22AFDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7881-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.18 Container Release : 85.18 Severity : important Type : security References : 1261969 1262098 1262319 1262654 1263656 1263658 CVE-2026-1502 CVE-2026-4786 CVE-2026-5435 CVE-2026-6019 CVE-2026-6100 CVE-2026-6238 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3104-1 Released: Fri Jul 17 15:31:14 2026 Summary: Security update for python311 Type: security Severity: important References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100 This update for python311 fixes the following issues - CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). - CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). - CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). - CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re-used (bsc#1262098). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libpython3_11-1_0-3.11.15-150600.3.59.3 updated - python311-base-3.11.15-150600.3.59.3 updated - python311-3.11.15-150600.3.59.3 updated - python311-devel-3.11.15-150600.3.59.3 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:53:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:53:02 +0200 (CEST) Subject: SUSE-CU-2026:7883-1: Security update of bci/python Message-ID: <20260804135302.1C370FE10@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7883-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.23 Container Release : 85.23 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:53:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:53:01 +0200 (CEST) Subject: SUSE-CU-2026:7882-1: Security update of bci/python Message-ID: <20260804135301.1EFE6FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7882-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.22 Container Release : 85.22 Severity : moderate Type : security References : 1252306 1253043 1257463 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:53:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:53:03 +0200 (CEST) Subject: SUSE-CU-2026:7885-1: Security update of bci/python Message-ID: <20260804135303.C644FFEBF@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7885-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.26 Container Release : 85.26 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:07 +0200 (CEST) Subject: SUSE-CU-2026:7887-1: Security update of bci/python Message-ID: <20260804135407.20495FD9B@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7887-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.10 , bci/python:latest Container Release : 88.10 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:08 +0200 (CEST) Subject: SUSE-CU-2026:7888-1: Security update of bci/python Message-ID: <20260804135408.25332FDA4@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7888-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.11 , bci/python:latest Container Release : 88.11 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:09 +0200 (CEST) Subject: SUSE-CU-2026:7889-1: Recommended update of bci/python Message-ID: <20260804135409.2F555FDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7889-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.14 , bci/python:latest Container Release : 88.14 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2972-1 Released: Tue Jul 14 13:33:14 2026 Summary: Recommended update for lifecycle-data-sle-module-development-tools Type: recommended Severity: moderate References: This update for lifecycle-data-sle-module-development-tools fixes the following issues: - lifecycle of gcc14 got extended until end of july. The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:11 +0200 (CEST) Subject: SUSE-CU-2026:7891-1: Security update of bci/python Message-ID: <20260804135411.36275FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7891-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.20 , bci/python:latest Container Release : 88.20 Severity : moderate Type : security References : 1252306 1253043 1257463 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:12 +0200 (CEST) Subject: SUSE-CU-2026:7892-1: Security update of bci/python Message-ID: <20260804135412.3D9FAFE10@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7892-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.21 , bci/python:latest Container Release : 88.21 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Tue Aug 4 13:54:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 15:54:10 +0200 (CEST) Subject: SUSE-CU-2026:7890-1: Security update of bci/python Message-ID: <20260804135410.34B38FDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7890-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.16 , bci/python:latest Container Release : 88.16 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 15:35:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 17:35:42 +0200 (CEST) Subject: SUSE-IU-2026:6047-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260804153542.9ADADFDA4@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6047-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.161 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.161 Severity : important Type : security References : 1230797 1239461 1266304 1266361 1268349 1269892 1270008 1270009 1270010 1270016 1270018 1270021 1271045 1271372 1271386 CVE-2025-15649 CVE-2025-24912 CVE-2026-12087 CVE-2026-13221 CVE-2026-50811 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58374 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 642 Released: Fri Jul 31 11:07:43 2026 Summary: Security update for wpa_supplicant Type: security Severity: moderate References: 1230797,1239461,1269892,CVE-2025-24912,CVE-2026-58374 This update for wpa_supplicant fixes the following issues: Security issues fixed: - CVE-2025-24912: RADIUS pending request dropping (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/. Other updates and bugfixes: - Revert 'Mark authorization completed on driver indication during 4-way HS offload' because of WPA2-PSK/WPA-SAE connection problems with brcmfmac wifi hardware (bsc#1230797). ----------------------------------------------------------------- Advisory ID: 643 Released: Fri Jul 31 11:35:01 2026 Summary: Security update for freetype2 Type: security Severity: moderate References: 1271045,CVE-2026-50811 This update for freetype2 fixes the following issue Update freetype2 and ft2demos to version 2.14.3. - CVE-2026-50811: out-of-bounds read in `src/truetype/ttgxvar.c` in the `TT_Get_Var_Design` implementation used by `FT_Get_Var_Design_Coordinates` (bsc#1271045). ----------------------------------------------------------------- Advisory ID: 644 Released: Fri Jul 31 11:51:56 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1266361,1268349,1271372,1271386,CVE-2025-15649,CVE-2026-12087,CVE-2026-13221,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues - CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). - CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching (bsc#1271386). ----------------------------------------------------------------- Advisory ID: 647 Released: Mon Aug 3 09:43:21 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - perl-base-5.38.2-slfo.1.1_3.1 updated - libfreetype6-2.14.3-slfo.1.1_1.1 updated - SL-Micro-release-6.1-slfo.1.12.60 updated - libglib-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_7.1 updated - glib2-tools-2.78.6-slfo.1.1_7.1 updated - wpa_supplicant-2.11-slfo.1.1_2.1 updated - container:suse-toolbox-image-1.0.0-5.82 updated From sle-container-updates at lists.suse.com Tue Aug 4 15:38:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 17:38:02 +0200 (CEST) Subject: SUSE-IU-2026:6048-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260804153802.A1D68FD9F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6048-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.163 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.163 Severity : important Type : security References : 1230797 1239461 1269892 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2025-24912 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58374 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 642 Released: Fri Jul 31 11:07:43 2026 Summary: Security update for wpa_supplicant Type: security Severity: moderate References: 1230797,1239461,1269892,CVE-2025-24912,CVE-2026-58374 This update for wpa_supplicant fixes the following issues: Security issues fixed: - CVE-2025-24912: RADIUS pending request dropping (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/. Other updates and bugfixes: - Revert 'Mark authorization completed on driver indication during 4-way HS offload' because of WPA2-PSK/WPA-SAE connection problems with brcmfmac wifi hardware (bsc#1230797). ----------------------------------------------------------------- Advisory ID: 647 Released: Mon Aug 3 09:43:21 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.60 updated - libglib-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_7.1 updated - glib2-tools-2.78.6-slfo.1.1_7.1 updated - wpa_supplicant-2.11-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.161 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:08:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:08:12 +0200 (CEST) Subject: SUSE-CU-2026:7899-1: Security update of bci/nodejs Message-ID: <20260804160812.A474CFDA4@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7899-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.1 , bci/node:22.23.1-24.27 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.1 , bci/nodejs:22.23.1-24.27 Container Release : 24.27 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:11:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:11:59 +0200 (CEST) Subject: SUSE-CU-2026:7900-1: Security update of bci/python Message-ID: <20260804161159.175F0FDA4@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7900-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.29 Container Release : 85.29 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:13:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:13:14 +0200 (CEST) Subject: SUSE-CU-2026:7892-1: Security update of bci/python Message-ID: <20260804161314.8F88CFDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7892-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.21 , bci/python:latest Container Release : 88.21 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:13:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:13:16 +0200 (CEST) Subject: SUSE-CU-2026:7902-1: Security update of bci/python Message-ID: <20260804161316.776C5FDD1@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7902-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.24 , bci/python:latest Container Release : 88.24 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:13:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:13:17 +0200 (CEST) Subject: SUSE-CU-2026:7903-1: Security update of bci/python Message-ID: <20260804161317.7F892FDEC@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7903-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.13 , bci/python:3.13.13-88.27 , bci/python:latest Container Release : 88.27 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:29 +0200 (CEST) Subject: SUSE-CU-2026:7904-1: Security update of bci/python Message-ID: <20260804161429.40209FDC8@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7904-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.8 Container Release : 84.8 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:30 +0200 (CEST) Subject: SUSE-CU-2026:7905-1: Security update of bci/python Message-ID: <20260804161430.65959FDD1@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7905-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.9 Container Release : 84.9 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:31 +0200 (CEST) Subject: SUSE-CU-2026:7906-1: Recommended update of bci/python Message-ID: <20260804161431.75D9CFDEC@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7906-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.12 Container Release : 84.12 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2972-1 Released: Tue Jul 14 13:33:14 2026 Summary: Recommended update for lifecycle-data-sle-module-development-tools Type: recommended Severity: moderate References: This update for lifecycle-data-sle-module-development-tools fixes the following issues: - lifecycle of gcc14 got extended until end of july. The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:32 +0200 (CEST) Subject: SUSE-CU-2026:7907-1: Security update of bci/python Message-ID: <20260804161432.7797EFE0D@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7907-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.14 Container Release : 84.14 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:35 +0200 (CEST) Subject: SUSE-CU-2026:7910-1: Security update of bci/python Message-ID: <20260804161435.D0C15FEE1@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7910-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.22 Container Release : 84.22 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:33 +0200 (CEST) Subject: SUSE-CU-2026:7908-1: Security update of bci/python Message-ID: <20260804161433.96D20FE13@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7908-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.18 Container Release : 84.18 Severity : moderate Type : security References : 1252306 1253043 1257463 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:34 +0200 (CEST) Subject: SUSE-CU-2026:7909-1: Security update of bci/python Message-ID: <20260804161434.B82F2FEC4@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7909-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.20 Container Release : 84.20 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:14:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:14:37 +0200 (CEST) Subject: SUSE-CU-2026:7911-1: Security update of bci/python Message-ID: <20260804161437.080CAFF12@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7911-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.25 Container Release : 84.25 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:15:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:15:06 +0200 (CEST) Subject: SUSE-CU-2026:7912-1: Security update of suse/mariadb-client Message-ID: <20260804161506.38A2FFDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7912-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-71.9 , suse/mariadb-client:latest Container Release : 71.9 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:15:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:15:07 +0200 (CEST) Subject: SUSE-CU-2026:7913-1: Security update of suse/mariadb-client Message-ID: <20260804161507.5A159FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7913-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-71.20 , suse/mariadb-client:latest Container Release : 71.20 Severity : important Type : security References : 1252306 1253043 1257463 1263656 1263658 1266438 1268290 1270393 CVE-2026-44172 CVE-2026-5435 CVE-2026-54411 CVE-2026-6238 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3110-1 Released: Fri Jul 17 16:15:25 2026 Summary: Security update for mariadb-connector-c Type: security Severity: important References: 1266438,CVE-2026-44172 This update for mariadb-connector-c fixes the following issue: - CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: - Update to 3.1.28. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libmariadb3-3.1.28-150600.18.3.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:15:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:15:09 +0200 (CEST) Subject: SUSE-CU-2026:7915-1: Security update of suse/mariadb-client Message-ID: <20260804161509.3365EFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7915-1 Container Tags : suse/mariadb-client:11.8 , suse/mariadb-client:11.8.8 , suse/mariadb-client:11.8.8-72.3 , suse/mariadb-client:latest Container Release : 72.3 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/mariadb-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:15:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:15:57 +0200 (CEST) Subject: SUSE-CU-2026:7916-1: Security update of suse/mariadb Message-ID: <20260804161557.4AF46FDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7916-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-78.11 , suse/mariadb:latest Container Release : 78.11 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:15:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:15:58 +0200 (CEST) Subject: SUSE-CU-2026:7917-1: Security update of suse/mariadb Message-ID: <20260804161558.A6C70FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7917-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-78.23 , suse/mariadb:latest Container Release : 78.23 Severity : important Type : security References : 1252306 1253043 1257463 1263656 1263658 1266438 1268290 1269790 1270393 CVE-2026-11979 CVE-2026-44172 CVE-2026-5435 CVE-2026-54411 CVE-2026-6238 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3110-1 Released: Fri Jul 17 16:15:25 2026 Summary: Security update for mariadb-connector-c Type: security Severity: important References: 1266438,CVE-2026-44172 This update for mariadb-connector-c fixes the following issue: - CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: - Update to 3.1.28. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libmariadb3-3.1.28-150600.18.3.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 16:16:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 18:16:00 +0200 (CEST) Subject: SUSE-CU-2026:7918-1: Security update of suse/mariadb Message-ID: <20260804161600.0CE30FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7918-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-78.24 , suse/mariadb:latest Container Release : 78.24 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:18:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:18:06 +0200 (CEST) Subject: SUSE-IU-2026:6050-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260804171806.2090AFDC8@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6050-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.303 , suse/sle-micro/base-5.5:latest Image Release : 5.8.303 Severity : important Type : security References : 1239461 1262684 1271712 CVE-2025-24912 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3490-1 Released: Tue Aug 4 13:58:35 2026 Summary: Security update for wpa_supplicant Type: security Severity: low References: 1239461,CVE-2025-24912 This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3491-1 Released: Tue Aug 4 13:58:43 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.60.1 updated - libgcrypt20-1.9.4-150500.12.6.1 updated - openssl-1_1-1.1.1l-150500.17.60.1 updated - wpa_supplicant-2.10-150500.3.6.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:20:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:20:45 +0200 (CEST) Subject: SUSE-IU-2026:6051-1: Security update of suse/sle-micro/5.5 Message-ID: <20260804172045.2A707FDC8@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6051-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.78 , suse/sle-micro/5.5:latest Image Release : 5.8.78 Severity : important Type : security References : 1239461 1262684 1268144 1268145 1271712 CVE-2025-24912 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3489-1 Released: Tue Aug 4 13:57:05 2026 Summary: Security update for multipath-tools Type: security Severity: moderate References: 1268144,1268145 This update for multipath-tools fixes the following issues: Update to version 0.9.4+134+suse.c82f347. - kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image (bsc#1268145). - kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3490-1 Released: Tue Aug 4 13:58:35 2026 Summary: Security update for wpa_supplicant Type: security Severity: low References: 1239461,CVE-2025-24912 This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3491-1 Released: Tue Aug 4 13:58:43 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.60.1 updated - libgcrypt20-1.9.4-150500.12.6.1 updated - openssl-1_1-1.1.1l-150500.17.60.1 updated - wpa_supplicant-2.10-150500.3.6.1 updated - kpartx-0.9.4+134+suse.c82f347-150500.3.12.1 updated - libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1 updated - multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.303 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:22:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:22:37 +0200 (CEST) Subject: SUSE-CU-2026:7922-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260804172237.67F0CFDC8@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7922-1 Container Tags : private-registry/1.2/harbor-portal:1.2.0 , private-registry/1.2/harbor-portal:1.2.0-1.75 , private-registry/1.2/harbor-portal:latest Container Release : 1.75 Severity : important Type : security References : ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - system-user-harbor-2.15.1-150700.1.25 updated - harbor-portal-2.15.1-150700.1.25 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:27:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:27:19 +0200 (CEST) Subject: SUSE-CU-2026:7929-1: Security update of private-registry/harbor-portal Message-ID: <20260804172719.A2984FDC8@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7929-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.93 , private-registry/harbor-portal:latest Container Release : 2.93 Severity : important Type : security References : ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - system-user-harbor-2.14.4-150700.1.27 updated - harbor-portal-2.14.4-150700.1.27 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:30:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:30:24 +0200 (CEST) Subject: SUSE-CU-2026:7934-1: Security update of private-registry/harbor-portal Message-ID: <20260804173024.A46FFFDC8@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7934-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.38 , private-registry/harbor-portal:2.13.5-1.38 , private-registry/harbor-portal:latest Container Release : 1.38 Severity : important Type : security References : ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - system-user-harbor-2.13.5-150700.1.17 updated - harbor213-portal-2.13.5-150700.1.17 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:33:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:33:05 +0200 (CEST) Subject: SUSE-CU-2026:7938-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260804173305.93C69FDC8@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7938-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.171 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.171 Severity : important Type : security References : 1262684 1271712 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3491-1 Released: Tue Aug 4 13:58:43 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-hmac-1.9.4-150500.12.6.1 updated - libgcrypt20-1.9.4-150500.12.6.1 updated - libopenssl1_1-hmac-1.1.1l-150500.17.60.1 updated - libopenssl1_1-1.1.1l-150500.17.60.1 updated - openssl-1_1-1.1.1l-150500.17.60.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:46:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:46:36 +0200 (CEST) Subject: SUSE-CU-2026:7939-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260804174636.5753FFDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7939-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.59 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.59 , suse/ltss/sle15.5/sle15:latest Container Release : 8.59 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-hmac-1.1.1l-150500.17.60.1 updated - libopenssl1_1-1.1.1l-150500.17.60.1 updated - openssl-1_1-1.1.1l-150500.17.60.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:50:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:50:31 +0200 (CEST) Subject: SUSE-CU-2026:7918-1: Security update of suse/mariadb Message-ID: <20260804175031.ADD57FDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7918-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-78.24 , suse/mariadb:latest Container Release : 78.24 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:50:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:50:32 +0200 (CEST) Subject: SUSE-CU-2026:7940-1: Security update of suse/mariadb Message-ID: <20260804175032.8B49FFDC9@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7940-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-78.26 , suse/mariadb:latest Container Release : 78.26 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:50:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:50:33 +0200 (CEST) Subject: SUSE-CU-2026:7941-1: Security update of suse/mariadb Message-ID: <20260804175033.67F86FDE2@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7941-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.4 , suse/mariadb:latest Container Release : 79.4 Severity : important Type : security References : 1271017 1271018 1271399 1271458 1271459 1271629 CVE-2026-14380 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3415-1 Released: Thu Jul 30 08:54:36 2026 Summary: Security update for perl-DBI Type: security Severity: important References: 1271017,1271018,1271399,1271458,1271459,1271629,CVE-2026-14380,CVE-2026-14740,CVE-2026-15043,CVE-2026-15392,CVE-2026-60081,CVE-2026-60082 This update for perl-DBI fixes the following issues - CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). - CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). - CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). - CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). - CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). - CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). The following package changes have been done: - perl-DBI-1.647.0-150600.12.18.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:50:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:50:34 +0200 (CEST) Subject: SUSE-CU-2026:7942-1: Security update of suse/mariadb Message-ID: <20260804175034.3BC22FDFA@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7942-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.5 , suse/mariadb:latest Container Release : 79.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:50:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:50:35 +0200 (CEST) Subject: SUSE-CU-2026:7943-1: Security update of suse/mariadb Message-ID: <20260804175035.119E8FE10@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7943-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.7 , suse/mariadb:latest Container Release : 79.7 Severity : moderate Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:22 +0200 (CEST) Subject: SUSE-CU-2026:7945-1: Security update of suse/rmt-server Message-ID: <20260804175122.052FFFDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7945-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-82.10 , suse/rmt-server:latest Container Release : 82.10 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:23 +0200 (CEST) Subject: SUSE-CU-2026:7947-1: Security update of suse/rmt-server Message-ID: <20260804175123.5AEA6FDC9@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7947-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-82.13 , suse/rmt-server:latest Container Release : 82.13 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:24 +0200 (CEST) Subject: SUSE-CU-2026:7948-1: Security update of suse/rmt-server Message-ID: <20260804175124.2D6EEFDE2@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7948-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-82.15 , suse/rmt-server:latest Container Release : 82.15 Severity : important Type : security References : 1266438 CVE-2026-44172 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3110-1 Released: Fri Jul 17 16:15:25 2026 Summary: Security update for mariadb-connector-c Type: security Severity: important References: 1266438,CVE-2026-44172 This update for mariadb-connector-c fixes the following issue: - CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: - Update to 3.1.28. The following package changes have been done: - libmariadb3-3.1.28-150600.18.3.1 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:25 +0200 (CEST) Subject: SUSE-CU-2026:7950-1: Security update of suse/rmt-server Message-ID: <20260804175125.92CF6FDFA@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7950-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-84.3 , suse/rmt-server:latest Container Release : 84.3 Severity : important Type : security References : 1252306 1253043 1257463 1269790 1270393 CVE-2026-11979 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:registry.suse.com-bci-bci-base-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:26 +0200 (CEST) Subject: SUSE-CU-2026:7951-1: Security update of suse/rmt-server Message-ID: <20260804175126.67E37FE10@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7951-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-84.4 , suse/rmt-server:latest Container Release : 84.4 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:registry.suse.com-bci-bci-base-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:27 +0200 (CEST) Subject: SUSE-CU-2026:7952-1: Security update of suse/rmt-server Message-ID: <20260804175127.3F8DEFEBF@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7952-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-84.6 , suse/rmt-server:latest Container Release : 84.6 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:29 +0200 (CEST) Subject: SUSE-CU-2026:7954-1: Security update of suse/rmt-server Message-ID: <20260804175129.535BAFF02@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7954-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.1 , suse/rmt-server:latest Container Release : 88.1 Severity : important Type : security References : 1175825 1197771 1229655 1230111 1233529 1245309 1245310 1245311 1245314 1246197 1246974 1247498 1249191 1249348 1249367 1249375 1251264 1253757 1255731 1255732 1255733 1255734 1256105 1258045 1258049 1258054 1258080 1258081 1259362 1259363 1259364 1259365 1259377 1259845 1262144 1262631 1264971 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2020-8927 CVE-2025-10148 CVE-2025-11563 CVE-2025-14017 CVE-2025-14524 CVE-2025-14819 CVE-2025-15079 CVE-2025-15224 CVE-2025-4877 CVE-2025-4878 CVE-2025-5318 CVE-2025-5372 CVE-2025-8114 CVE-2025-8277 CVE-2025-9086 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-10536 CVE-2026-12064 CVE-2026-1965 CVE-2026-27135 CVE-2026-3731 CVE-2026-3783 CVE-2026-3784 CVE-2026-3805 CVE-2026-4873 CVE-2026-5958 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:3942-1 Released: Mon Dec 6 14:46:05 2021 Summary: Security update for brotli Type: security Severity: moderate References: 1175825,CVE-2020-8927 This update for brotli fixes the following issues: - CVE-2020-8927: Fixed integer overflow when input chunk is larger than 2GiB (bsc#1175825). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:1658-1 Released: Fri May 13 15:40:20 2022 Summary: Recommended update for libpsl Type: recommended Severity: important References: 1197771 This update for libpsl fixes the following issues: - Fix libpsl compilation issues (bsc#1197771) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2024:3589-1 Released: Thu Oct 10 16:39:07 2024 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1230111 This update for cyrus-sasl fixes the following issues: - Make DIGEST-MD5 work with openssl3 ( bsc#1230111 ) RC4 is legacy provided since openSSL3 and requires explicit loading, disable openssl3 depricated API warnings. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:2229-1 Released: Fri Jul 4 18:02:30 2025 Summary: Security update for libssh Type: security Severity: important References: 1245309,1245310,1245311,1245314,CVE-2025-4877,CVE-2025-4878,CVE-2025-5318,CVE-2025-5372 This update for libssh fixes the following issues: - CVE-2025-5318: Fixed likely read beyond bounds in sftp server handle management (bsc#1245311). - CVE-2025-4877: Fixed write beyond bounds in binary to base64 conversion functions (bsc#1245309). - CVE-2025-4878: Fixed use of uninitialized variable in privatekey_from_file() (bsc#1245310). - CVE-2025-5372: Fixed cases where ssh_kdf() returns a success code on certain failures (bsc#1245314). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:2301-1 Released: Mon Jul 14 11:48:57 2025 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1229655 This update for cyrus-sasl fixes the following issues: - Add Channel Binding support for GSSAPI/GSS-SPNEGO (bsc#1229655, jsc#PED-12097) - Add support for setting max ssf 0 to GSS-SPNEGO (bsc#1229655, jsc#PED-12097). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3268-1 Released: Thu Sep 18 13:08:10 2025 Summary: Security update for curl Type: security Severity: important References: 1246197,1249191,1249348,1249367,CVE-2025-10148,CVE-2025-9086 This update for curl fixes the following issues: Security issues fixed: - CVE-2025-9086: bug in patch comparison logic when processing cookies can lead to out-of-bounds read in heap buffer (bsc#1249191). - CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348). Other issues fixed: - Fix the --ftp-pasv option in curl v8.14.1 (bsc#1246197). * tool_getparam: fix --ftp-pasv [5f805ee] - Update to version 8.14.1 (jsc#PED-13055, jsc#PED-13056). * TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs. * websocket: add option to disable auto-pong reply. * huge number of bugfixes. Please see https://curl.se/ch/ for full changelogs. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3369-1 Released: Fri Sep 26 12:54:43 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3596-1 Released: Wed Oct 15 09:51:21 2025 Summary: Recommended update for curl Type: recommended Severity: moderate References: 1251264 This update for curl fixes the following issue: - rebuilds it against a newer nghttp2 to fix handling 2 or more whitespaces in headers. (bsc#1251264) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:3934-1 Released: Tue Nov 4 12:23:11 2025 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1247498 This update for cyrus-sasl fixes the following issue: - Replace insecure MD5 with ephemeral HMAC-SHA256 (bsc#1247498). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2025:4155-1 Released: Fri Nov 21 15:09:44 2025 Summary: Recommended update for cyrus-sasl Type: recommended Severity: moderate References: 1233529 This update for cyrus-sasl fixes the following issues: - Python3 error log upon importing pycurl (bsc#1233529) * Remove senceless log message. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4300-1 Released: Fri Nov 28 13:57:41 2025 Summary: Security update for curl Type: security Severity: moderate References: 1253757,CVE-2025-11563 This update for curl fixes the following issues: - CVE-2025-11563: Fixed wcurl path traversal with percent-encoded slashes (bsc#1253757) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:52-1 Released: Wed Jan 7 10:28:34 2026 Summary: Security update for curl Type: security Severity: moderate References: 1255731,1255732,1255733,1255734,CVE-2025-14524,CVE-2025-14819,CVE-2025-15079,CVE-2025-15224 This update for curl fixes the following issues: - CVE-2025-14524: bearer token leak on cross-protocol redirect (bsc#1255731). - CVE-2025-14819: libssh global knownhost override (bsc#1255732). - CVE-2025-15079: libssh key passphrase bypass without agent set (bsc#1255733). - CVE-2025-15224: OpenSSL partial chain store policy bypass (bsc#1255734). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:221-1 Released: Thu Jan 22 13:15:35 2026 Summary: Security update for curl Type: security Severity: moderate References: 1256105,CVE-2025-14017 This update for curl fixes the following issues: - CVE-2025-14017: Fixed broken TLS options for threaded LDAPS (bsc#1256105). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:779-1 Released: Tue Mar 3 14:25:07 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:863-1 Released: Wed Mar 11 13:41:48 2026 Summary: Recommended update for openldap2 Type: recommended Severity: moderate References: This update for openldap2 fixes the following issues: - expose ldap_log.h in -devel (jsc#PED-15735) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:903-1 Released: Tue Mar 17 11:04:44 2026 Summary: Security update for curl Type: security Severity: important References: 1259362,1259363,1259364,1259365,CVE-2026-1965,CVE-2026-3783,CVE-2026-3784,CVE-2026-3805 This update for curl fixes the following issues: - CVE-2026-1965: bad reuse of HTTP Negotiate connection (bsc#1259362). - CVE-2026-3783: token leak with redirect and netrc (bsc#1259363). - CVE-2026-3784: wrong proxy connection reuse with credentials (bsc#1259364). - CVE-2026-3805: use after free in SMB connection reuse (bsc#1259365). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1074-1 Released: Thu Mar 26 13:39:49 2026 Summary: Security update for nghttp2 Type: security Severity: important References: 1259845,CVE-2026-27135 This update for nghttp2 fixes the following issues: - CVE-2026-27135: Assertion failure due to missing state validation can lead to DoS (bsc#1259845). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1310-1 Released: Tue Apr 14 12:42:12 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1259377,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-3731: Denial of Service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1941-1 Released: Mon May 18 09:44:34 2026 Summary: Security update for sed Type: security Severity: moderate References: 1262144,CVE-2026-5958 This update for sed fixes the following issue: - CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2661-1 Released: Fri Jun 26 15:15:48 2026 Summary: Recommended update for curl Type: recommended Severity: important References: 1264971 This update for curl fixes the following issues: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libbrotlicommon1-1.0.7-150200.3.5.1 added - libldap-data-2.4.46-150600.25.3.1 added - libnghttp2-14-1.64.0-150700.3.3.1 added - libsasl2-3-2.1.28-150600.7.14.1 added - libssh-config-0.9.8-150600.11.15.1 added - libunistring2-0.9.10-1.1 added - libzstd1-1.5.7-150700.1.2 added - sed-4.9-150600.3.3.1 added - libbrotlidec1-1.0.7-150200.3.5.1 added - libidn2-0-2.2.0-3.6.1 added - libpsl5-0.20.1-150000.3.3.1 added - libldap-2_4-2-2.4.46-150600.25.3.1 added - libssh4-0.9.8-150600.11.15.1 added - libcurl4-8.14.1-150700.7.20.1 added - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 added - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 added - bash-sh-4.4-150400.27.6.1 removed - container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 removed - coreutils-8.32-150400.9.12.1 removed - filesystem-15.0-11.8.1 removed - glibc-2.38-150600.14.52.1 removed - libacl1-2.2.52-4.3.1 removed - libattr1-2.4.47-2.19 removed - libcap2-2.63-150400.3.6.1 removed - libgcc_s1-15.3.0+git11272-150000.1.12.1 removed - libgmp10-6.1.2-4.9.1 removed - libncurses6-6.1-150000.5.33.1 removed - libopenssl-3-fips-provider-3.2.3-150700.5.36.1 removed - libpcre2-8-0-10.42-150600.1.26 removed - libreadline7-7.0-150400.27.6.1 removed - libselinux1-3.5-150600.3.3.1 removed - libstdc++6-15.3.0+git11272-150000.1.12.1 removed - patterns-base-fips-20200124-150700.36.1 removed - system-user-root-20190513-3.3.1 removed - terminfo-base-6.1-150000.5.33.1 removed From sle-container-updates at lists.suse.com Tue Aug 4 17:51:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:28 +0200 (CEST) Subject: SUSE-CU-2026:7953-1: Security update of suse/rmt-server Message-ID: <20260804175128.303BDFED5@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7953-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-84.8 , suse/rmt-server:latest Container Release : 84.8 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 1269279 CVE-2026-40226 CVE-2026-57062 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libudev1-254.27-150600.4.71.2 updated - gpg2-2.4.4-150600.3.18.1 updated - container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Tue Aug 4 17:51:30 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 4 Aug 2026 19:51:30 +0200 (CEST) Subject: SUSE-CU-2026:7955-1: Security update of suse/rmt-server Message-ID: <20260804175130.6398AFDA4@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7955-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.2 , suse/rmt-server:latest Container Release : 88.2 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:07:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:07:26 +0200 (CEST) Subject: SUSE-IU-2026:6052-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260805070726.99D69FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6052-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.584 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.584 Severity : important Type : security References : 1239461 1262684 1271712 CVE-2025-24912 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3490-1 Released: Tue Aug 4 13:58:35 2026 Summary: Security update for wpa_supplicant Type: security Severity: low References: 1239461,CVE-2025-24912 This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3491-1 Released: Tue Aug 4 13:58:43 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.60.1 updated - libgcrypt20-1.9.4-150500.12.6.1 updated - wpa_supplicant-2.10-150500.3.6.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.303 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:11:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:11:39 +0200 (CEST) Subject: SUSE-IU-2026:6053-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260805071139.49BB4FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6053-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.678 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.678 Severity : important Type : security References : 1239461 1262684 1271712 CVE-2025-24912 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3488-1 Released: Tue Aug 4 13:55:33 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3490-1 Released: Tue Aug 4 13:58:35 2026 Summary: Security update for wpa_supplicant Type: security Severity: low References: 1239461,CVE-2025-24912 This update for wpa_supplicant fixes the following issues: - CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3491-1 Released: Tue Aug 4 13:58:43 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libopenssl1_1-1.1.1l-150500.17.60.1 updated - libgcrypt20-1.9.4-150500.12.6.1 updated - wpa_supplicant-2.10-150500.3.6.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.78 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:19:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:19:37 +0200 (CEST) Subject: SUSE-IU-2026:6054-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260805071937.98673FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6054-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.144 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.144 Severity : critical Type : security References : 1230797 1232063 1232227 1233588 1236321 1236390 1236392 1238484 1239461 1244917 1246501 1253260 1254094 1254323 1255285 1255451 1257007 1257153 1257244 1257476 1266304 1266361 1268144 1268145 1268275 1268349 1269892 1270008 1270009 1270010 1270016 1270018 1270021 1271372 1271386 CVE-2024-58251 CVE-2025-15649 CVE-2025-24912 CVE-2025-59529 CVE-2026-12087 CVE-2026-13221 CVE-2026-41579 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58374 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 642 Released: Fri Jul 31 11:07:43 2026 Summary: Security update for wpa_supplicant Type: security Severity: moderate References: 1230797,1239461,1269892,CVE-2025-24912,CVE-2026-58374 This update for wpa_supplicant fixes the following issues: Security issues fixed: - CVE-2025-24912: RADIUS pending request dropping (bsc#1239461). - CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). - Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/. - Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/. Other updates and bugfixes: - Revert 'Mark authorization completed on driver indication during 4-way HS offload' because of WPA2-PSK/WPA-SAE connection problems with brcmfmac wifi hardware (bsc#1230797). ----------------------------------------------------------------- Advisory ID: 644 Released: Fri Jul 31 11:51:56 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1266361,1268349,1271372,1271386,CVE-2025-15649,CVE-2026-12087,CVE-2026-13221,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues - CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). - CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching (bsc#1271386). ----------------------------------------------------------------- Advisory ID: 648 Released: Mon Aug 3 09:33:31 2026 Summary: Security update for net-tools Type: security Severity: moderate References: 1254323,CVE-2024-58251 This update for net-tools fixes the following issues: - CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323). ----------------------------------------------------------------- Advisory ID: 647 Released: Mon Aug 3 09:43:21 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ----------------------------------------------------------------- Advisory ID: 652 Released: Tue Aug 4 13:04:57 2026 Summary: Security update for multipath-tools Type: security Severity: critical References: 1232063,1232227,1233588,1236321,1236390,1236392,1238484,1244917,1246501,1253260,1254094,1255285,1257007,1257153,1257244,1257476,1268144,1268145 This update for multipath-tools fixes the following issues: Update to version 0.10.7~1+211+suse.18f1559. Security issues fixed: - kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145). - kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). Other updates and bugfixes: - Fix system with multipath failing to boot during first boot during the installation (bsc#1232063). - Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 >= 0` message showing up in syslog (bsc#1255285). - Version 0.10.7~1+211+suse.18f1559: * Fix ALUA asymmetric access state descriptions in multipathd logs, so that the same terms are used as by the kernel ('lba-dependent', 'transitioning'). * Don't set a hardware handler for bio-based multipath devices. The kernel rejects this anyway. * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page 0x83 format for their device identifier. * Fix duplicate 'checker timed out' log messages when `log_checker_err` is set to `once`. (bsc#1254094) * Avoid potential buffer overflows in the iet and datacore prioritizers. * iet prioritizer: avoid misleading error message with systemd 256 and newer, and properly use udev to derive path parameters. (gh#opensvc/multipath-tools#145) - Version 0.10.6+201+suse.9f189e79: * libmultipath: reduce log level of 'map X has no targets' (bsc#1257476) - Version 0.10.6+200+suse.547788f4 (bsc#1257007): * kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153) * multipathd: print path offline message even without a checker (bsc#1254094) * Fix command descriptions in the multipathd man page. * Fix ISO C23 compatibility issue causing errors with new compilers. * Fix memory leak caused by not joining the 'init unwinder' thread. * Fix memory leaks in kpartx. * Print the warning 'setting scsi timeouts is unsupported for protocol' only once per protocol. * Make sure multipath-tools is compiled with the compiler flag `-fno-strict-aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285) - Version 0.10.5+213+suse.04c3a0ac: * Log offline path state if 'log_checker_err always' is set * mpathpersist: Fix REPORT CAPABILITIES output - Version 0.10.5+190+suse.a9f87040: * CI: GitHub workflow updates. No code changes. - _service: switched to tar_scm for git LFS. - Version 0.10.5+125+suse.1ed79487: - Fixes from upstream 0.10.5 (see also NEWS.md) (bsc#1253260) * Improved the communication with **udev** and **systemd** by triggering uevents when path devices are added to or removed from multipath maps, or when `multipathd reconfigure` is executed after changing blacklist directives in `multipath.conf`. * Failed paths should be checked every `polling_interval`. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd. * It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. Fix it. * After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. Fix it. * Various minor fixes reported by coverity. - Version 0.10.3+124+suse.ed5b4b11: * multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable (bsc#1246501) - Version 0.10.2+123+suse.48d66ee8: * multipathd: cli_reinstate(): avoid reinstated paths being failed again (bsc#1244917) - Version 0.10.2+122+suse.51e02cc: * multipathd: fix hang during shutdown with queuing maps (bsc#1238484). * This adds multipathd-queueing.service. - Version 0.10.2+117+suse.33411aa: * multipathd: trigger uevents for blacklisted paths in reconfigure (bsc#1236321) * Make sure maps are reloaded in the path checker loop after detecting an inconsistent or wrong kernel state (bsc#1236392) * Make sure udev and systemd notice changes in multipath path state when devices are added to or removed from multipath maps (bsc#1236321) * Fix the problem that `group_by_tpg` might be disabled if one or more paths were offline during initial configuration (bsc#1236392) * Fix multipathd crash because of invalid path group index value, for example if an invalid path device was removed from a map. (gh#opensvc/multipath-tools#105, bsc#1236392) * Fixed a memory leak in the nvme foreign library. * Fixed a problem in the marginal path detection algorithm that could cause the io error check for a recently failed path to be delayed. (bsc#1236390) * Reduce log level of harmless 'map ... doesn't exist' message - Version 0.10.1~2+112+suse.b66763a: * libmultipath: reduce log level of 'map X has multiple targets' (bsc#1233588) - Version 0.10.1~1+113+suse.d6eca5e: * This is a pre-release of the upstream stable release 0.10.1. * libmultipath: dm_get_maps(): don't bail out for single-map failures (bsc#1233588, gh#opensvc/multipath-tools#102) * libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227) * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL * multipathd: fix deferred_failback_tick for reload removes - Version 0.10.0+108+suse.2c2e597: * Update fix for bsc#1232063 to upstream-accepted solution - Version 0.10.0+106+suse.ffbdb7a: * Fix reboot hang if uevent is processed for suspended device (bsc#1232063) ----------------------------------------------------------------- Advisory ID: 650 Released: Tue Aug 4 13:08:52 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). ----------------------------------------------------------------- Advisory ID: 654 Released: Tue Aug 4 17:21:01 2026 Summary: Security update for runc Type: security Severity: low References: 1268275,CVE-2026-41579 This update for runc fixes the following issues: - CVE-2026-41579: runc allows a malicious image with a /dev symlink to trigger limited host filesystem integrity violations (bsc#1268275). Changes for runc: - update to 1.3.6: * Various integration test improvements. (#5222, #5237, #5226, #5229, #5239, #5249, #5269, #5287, #5295, #5304) * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). - update to 1.3.5 * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. (#5115, #5098) * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. (#5158, #5153, #5151, #4645, #4757) * Updated builds to Go 1.25, libseccomp v2.6.0. (#5111, #5053) * Minor signing keyring updates. (#5146, #5139, #5144, #5148) The following package changes have been done: - perl-base-5.38.2-slfo.1.1_3.1 updated - SL-Micro-release-6.1-slfo.1.12.60 updated - libglib-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgobject-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgmodule-2_0-0-2.78.6-slfo.1.1_7.1 updated - libgio-2_0-0-2.78.6-slfo.1.1_7.1 updated - glib2-tools-2.78.6-slfo.1.1_7.1 updated - wpa_supplicant-2.11-slfo.1.1_2.1 updated - kpartx-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated - libavahi-common3-0.8-slfo.1.1_8.1 updated - runc-1.3.6-slfo.1.1_1.1 updated - libavahi-core7-0.8-slfo.1.1_8.1 updated - libavahi-client3-0.8-slfo.1.1_8.1 updated - net-tools-2.10-slfo.1.1_3.1 updated - avahi-0.8-slfo.1.1_8.1 updated - perl-5.38.2-slfo.1.1_3.1 updated - libmpath0-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated - multipath-tools-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.161 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:45:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:45:33 +0200 (CEST) Subject: SUSE-CU-2026:7962-1: Security update of bci/golang Message-ID: <20260805074533.945E9FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7962-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.12 , bci/golang:1.25.12-2.76.27 , bci/golang:oldstable Container Release : 76.27 Severity : moderate Type : security References : 1245878 1247816 1248082 1264390 1264391 1264392 1264393 1264394 1264395 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3481-1 Released: Tue Aug 4 13:44:40 2026 Summary: Recommended update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl Type: recommended Severity: moderate References: 1245878,1247816,1248082,1264390,1264391,1264392,1264393,1264394,1264395 This update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl fixes the following issues: - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs bsc#1245878 bsc#1264390 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs bsc#1245878 bsc#1264390 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs bsc#1245878 bsc#1264390 * Drop unused conditional %define with_shared refs jsc#PED-1962 * Uniqify %define go_libalternatives 1219 to accommodate parallel installed toolchain variants per go1.x major version. go1.x has highest alternatives priority and uses suffix 9. refs bsc#1245878 bsc#1264390 * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs bsc#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 - Prepare for removing old go versions from Factory: * Switch default for go1.21 to bootstrap with gcc-go using %bcond_without gccgo_go121 * Building go1.21 with gcc-go by default removes need for prjconf * Refs bsc#1247816 bootstrap go1.21 with gccgo The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - go1.25-doc-1.25.12-150000.1.47.1 updated - gawk-4.2.1-150000.3.6.1 updated - go1.25-1.25.12-150000.1.47.1 updated - go1.25-race-1.25.12-150000.1.47.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:46:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:46:38 +0200 (CEST) Subject: SUSE-CU-2026:7963-1: Security update of bci/golang Message-ID: <20260805074638.C0E99FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7963-1 Container Tags : bci/golang:1.25-openssl , bci/golang:1.25-sles15-openssl , bci/golang:1.25.12-openssl , bci/golang:1.25.12-openssl-89.27 , bci/golang:oldstable-openssl Container Release : 89.27 Severity : moderate Type : security References : 1245878 1247816 1248082 1264390 1264391 1264392 1264393 1264394 1264395 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3481-1 Released: Tue Aug 4 13:44:40 2026 Summary: Recommended update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl Type: recommended Severity: moderate References: 1245878,1247816,1248082,1264390,1264391,1264392,1264393,1264394,1264395 This update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl fixes the following issues: - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs bsc#1245878 bsc#1264390 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs bsc#1245878 bsc#1264390 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs bsc#1245878 bsc#1264390 * Drop unused conditional %define with_shared refs jsc#PED-1962 * Uniqify %define go_libalternatives 1219 to accommodate parallel installed toolchain variants per go1.x major version. go1.x has highest alternatives priority and uses suffix 9. refs bsc#1245878 bsc#1264390 * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs bsc#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 - Prepare for removing old go versions from Factory: * Switch default for go1.21 to bootstrap with gcc-go using %bcond_without gccgo_go121 * Building go1.21 with gcc-go by default removes need for prjconf * Refs bsc#1247816 bootstrap go1.21 with gccgo The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - go1.25-openssl-doc-1.25.12-150600.13.24.1 updated - gawk-4.2.1-150000.3.6.1 updated - go1.25-openssl-1.25.12-150600.13.24.1 updated - go1.25-openssl-race-1.25.12-150600.13.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:47:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:47:35 +0200 (CEST) Subject: SUSE-CU-2026:7964-1: Security update of bci/golang Message-ID: <20260805074735.B6935FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7964-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.5 , bci/golang:1.26.5-1.75.27 , bci/golang:latest , bci/golang:stable Container Release : 75.27 Severity : moderate Type : security References : 1245878 1247816 1248082 1264390 1264391 1264392 1264393 1264394 1264395 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3481-1 Released: Tue Aug 4 13:44:40 2026 Summary: Recommended update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl Type: recommended Severity: moderate References: 1245878,1247816,1248082,1264390,1264391,1264392,1264393,1264394,1264395 This update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl fixes the following issues: - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs bsc#1245878 bsc#1264390 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs bsc#1245878 bsc#1264390 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs bsc#1245878 bsc#1264390 * Drop unused conditional %define with_shared refs jsc#PED-1962 * Uniqify %define go_libalternatives 1219 to accommodate parallel installed toolchain variants per go1.x major version. go1.x has highest alternatives priority and uses suffix 9. refs bsc#1245878 bsc#1264390 * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs bsc#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 - Prepare for removing old go versions from Factory: * Switch default for go1.21 to bootstrap with gcc-go using %bcond_without gccgo_go121 * Building go1.21 with gcc-go by default removes need for prjconf * Refs bsc#1247816 bootstrap go1.21 with gccgo The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - go1.26-doc-1.26.5-150000.1.21.1 updated - gawk-4.2.1-150000.3.6.1 updated - go1.26-1.26.5-150000.1.21.1 updated - go1.26-race-1.26.5-150000.1.21.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:48:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:48:42 +0200 (CEST) Subject: SUSE-CU-2026:7965-1: Recommended update of bci/golang Message-ID: <20260805074842.644CEFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7965-1 Container Tags : bci/golang:1.26-openssl , bci/golang:1.26-sles15-openssl , bci/golang:1.26.5-openssl , bci/golang:1.26.5-openssl-89.27 , bci/golang:latest , bci/golang:stable-openssl Container Release : 89.27 Severity : moderate Type : recommended References : 1245878 1247816 1248082 1264390 1264391 1264392 1264393 1264394 1264395 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3481-1 Released: Tue Aug 4 13:44:40 2026 Summary: Recommended update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl Type: recommended Severity: moderate References: 1245878,1247816,1248082,1264390,1264391,1264392,1264393,1264394,1264395 This update for go1.21, go1.22, go1.22-openssl, go1.23, go1.23-openssl, go1.24, go1.24-openssl, go1.25, go1.25-openssl, go1.26, go1.26-openssl fixes the following issues: - Packaging improvements: * Revert %ghost /usr/bin/go /usr/bin/gofmt which prevents install of a working go command. Refs bsc#1245878 bsc#1264390 * Based on feedback from Factory maintainers restore the original lifecycle for these files: Each go1.x toolchain shares ownership of a go and gofmt symlink managed by the alternatives system (update-alternatives and libalternatives). When the last go1.x package is uninstalled the symlinks will be removed. * Context: %ghost was introduced to prevent file conflicts among go1.x toolchain packages reported by installcheck dev tool. %ghost prevents the files from being installed, which results in no installed go command. The shared ownership of the go and gofmt symlinks is intentional. * Define go_bootstrap_version with digits without go1.x prefix. Correct path spelling to align with current toolchain layout GOROOT_BOOTSTRAP=%{_libdir}/go/%{go_bootstrap_version}, noting interstitial /go/ in path. Fixes bootstrap ERROR: Cannot find /usr/lib64/go1.x/bin/go. Set $GOROOT_BOOTSTRAP to a working Go tree >= Go 1.x.y. Bootstrap error first observed when using %ghost /usr/bin/go. Fixed by Eugenio Paolantonio. Refs bsc#1245878 bsc#1264390 * Mark %ghost /usr/bin/go /usr/bin/gofmt to avoid file conflicts among go1.x toolchain packages. These files are managed by the alternatives system. Refs bsc#1245878 bsc#1264390 * Drop unused conditional %define with_shared refs jsc#PED-1962 * Uniqify %define go_libalternatives 1219 to accommodate parallel installed toolchain variants per go1.x major version. go1.x has highest alternatives priority and uses suffix 9. refs bsc#1245878 bsc#1264390 * Drop subpackage go1.x-libstd std library .so refs jsc#PED-1962 * Use of Go standard library as .so and -buildmode=shared is not recommended or supported by upstream Go * Subpackage go1.x-libstd was only ever built for Factory and removal does not affect SLE * No Go application packages in Factory use go1.x-libstd - Use libalternatives only on suse_version >= 1610 and keep update-alternatives support for older distributions. - Drop the update-alternatives migration path for libalternatives builds. - Packaging: Enable libalternatives for SLE16.1 and Tumbleweed Refs bsc#1245878 * Drop go1.21 dependency on update-alternatives fixes bsc#1264390 - Prepare for removing old go versions from Factory: * Switch default for go1.21 to bootstrap with gcc-go using %bcond_without gccgo_go121 * Building go1.21 with gcc-go by default removes need for prjconf * Refs bsc#1247816 bootstrap go1.21 with gccgo The following package changes have been done: - go1.26-openssl-doc-1.26.5-150600.13.12.1 updated - go1.26-openssl-1.26.5-150600.13.12.1 updated - go1.26-openssl-race-1.26.5-150600.13.12.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:49:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:49:52 +0200 (CEST) Subject: SUSE-CU-2026:7966-1: Security update of bci/openjdk-devel Message-ID: <20260805074952.14BEEFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7966-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.0 , bci/openjdk-devel:17.0.20.0-21.34 Container Release : 21.34 Severity : important Type : security References : ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - container:bci-openjdk-17-15.7.17-20.30 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:50:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:50:58 +0200 (CEST) Subject: SUSE-CU-2026:7967-1: Security update of bci/openjdk Message-ID: <20260805075058.049A3FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7967-1 Container Tags : bci/openjdk:17 , bci/openjdk:17-sles15 , bci/openjdk:17.0.20.0 , bci/openjdk:17.0.20.0-20.30 Container Release : 20.30 Severity : important Type : security References : ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:51:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:51:57 +0200 (CEST) Subject: SUSE-CU-2026:7968-1: Security update of bci/openjdk-devel Message-ID: <20260805075157.23478FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7968-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.0 , bci/openjdk-devel:21.0.12.0-25.34 Container Release : 25.34 Severity : important Type : security References : ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - container:bci-openjdk-21-15.7.21-24.29 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:52:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:52:58 +0200 (CEST) Subject: SUSE-CU-2026:7969-1: Security update of bci/openjdk Message-ID: <20260805075258.C6B39FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7969-1 Container Tags : bci/openjdk:21 , bci/openjdk:21-sles15 , bci/openjdk:21.0.12.0 , bci/openjdk:21.0.12.0-24.29 Container Release : 24.29 Severity : important Type : security References : ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:53:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:53:41 +0200 (CEST) Subject: SUSE-CU-2026:7970-1: Security update of bci/openjdk-devel Message-ID: <20260805075341.4BFCCFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7970-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.0 , bci/openjdk-devel:25.0.4.0-9.35 , bci/openjdk-devel:latest Container Release : 9.35 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - container:bci-openjdk-25-15.7.25-9.29 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:54:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:54:23 +0200 (CEST) Subject: SUSE-CU-2026:7971-1: Security update of bci/openjdk Message-ID: <20260805075423.62491FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7971-1 Container Tags : bci/openjdk:25 , bci/openjdk:25-sles15 , bci/openjdk:25.0.4.0 , bci/openjdk:25.0.4.0-9.29 , bci/openjdk:latest Container Release : 9.29 Severity : important Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:57:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:57:28 +0200 (CEST) Subject: SUSE-CU-2026:7955-1: Security update of suse/rmt-server Message-ID: <20260805075728.C79C9FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7955-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.2 , suse/rmt-server:latest Container Release : 88.2 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:31 +0200 (CEST) Subject: SUSE-CU-2026:7973-1: Security update of bci/ruby Message-ID: <20260805075831.2C84DFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7973-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.9 , bci/ruby:2.5-sles15 Container Release : 26.9 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:32 +0200 (CEST) Subject: SUSE-CU-2026:7974-1: Security update of bci/ruby Message-ID: <20260805075832.28B18FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7974-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.10 , bci/ruby:2.5-sles15 Container Release : 26.10 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:33 +0200 (CEST) Subject: SUSE-CU-2026:7975-1: Security update of bci/ruby Message-ID: <20260805075833.5B9EBFDD1@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7975-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.12 , bci/ruby:2.5-sles15 Container Release : 26.12 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - glibc-devel-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:35 +0200 (CEST) Subject: SUSE-CU-2026:7977-1: Security update of bci/ruby Message-ID: <20260805075835.8E881FE0D@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7977-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.21 , bci/ruby:2.5-sles15 Container Release : 26.21 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:34 +0200 (CEST) Subject: SUSE-CU-2026:7976-1: Security update of bci/ruby Message-ID: <20260805075834.76DCDFDEC@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7976-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.20 , bci/ruby:2.5-sles15 Container Release : 26.20 Severity : important Type : security References : 1252306 1253043 1257463 1262684 1268290 1270393 CVE-2026-41989 CVE-2026-54411 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - libatomic1-15.3.0+git11272-150000.1.12.1 updated - libgomp1-15.3.0+git11272-150000.1.12.1 updated - libitm1-15.3.0+git11272-150000.1.12.1 updated - liblsan0-15.3.0+git11272-150000.1.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:39 +0200 (CEST) Subject: SUSE-CU-2026:7980-1: Security update of bci/ruby Message-ID: <20260805075839.1542FFEC4@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7980-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.27 , bci/ruby:2.5-sles15 Container Release : 26.27 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 07:58:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 09:58:37 +0200 (CEST) Subject: SUSE-CU-2026:7979-1: Security update of bci/ruby Message-ID: <20260805075837.7B873FE13@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7979-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.24 , bci/ruby:2.5-sles15 Container Release : 26.24 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:15:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:15:38 +0200 (CEST) Subject: SUSE-CU-2026:7980-1: Security update of bci/ruby Message-ID: <20260805091538.AA874FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7980-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.27 , bci/ruby:2.5-sles15 Container Release : 26.27 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:08 +0200 (CEST) Subject: SUSE-CU-2026:7982-1: Security update of bci/ruby Message-ID: <20260805091708.03E71FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7982-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.9 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.9 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:10 +0200 (CEST) Subject: SUSE-CU-2026:7984-1: Security update of bci/ruby Message-ID: <20260805091710.A35CCFDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7984-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.12 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.12 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - glibc-devel-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:09 +0200 (CEST) Subject: SUSE-CU-2026:7983-1: Security update of bci/ruby Message-ID: <20260805091709.6D912FDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7983-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.10 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.10 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:12 +0200 (CEST) Subject: SUSE-CU-2026:7985-1: Security update of bci/ruby Message-ID: <20260805091712.0F645FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7985-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.21 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.21 Severity : important Type : security References : 1252306 1253043 1257463 1262684 1268011 1268290 1268337 1268338 1268339 1270034 1270393 CVE-2025-61594 CVE-2026-41989 CVE-2026-42258 CVE-2026-47240 CVE-2026-47241 CVE-2026-47242 CVE-2026-54411 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3090-1 Released: Fri Jul 17 08:13:15 2026 Summary: Security update for ruby3.4 Type: security Severity: moderate References: 1268011,1268337,1268338,1268339,1270034,CVE-2025-61594,CVE-2026-42258,CVE-2026-47240,CVE-2026-47241,CVE-2026-47242 This update for ruby3.4 fixes the following issues - CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). - CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337). - CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). - CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). - CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: - Update to 3.4.10: - bundling net-imap 0.5.15. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - libatomic1-15.3.0+git11272-150000.1.12.1 updated - libgomp1-15.3.0+git11272-150000.1.12.1 updated - libitm1-15.3.0+git11272-150000.1.12.1 updated - liblsan0-15.3.0+git11272-150000.1.12.1 updated - libruby3_4-3_4-3.4.10-150700.3.4.1 updated - ruby3.4-3.4.10-150700.3.4.1 updated - ruby3.4-devel-3.4.10-150700.3.4.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:15 +0200 (CEST) Subject: SUSE-CU-2026:7988-1: Security update of bci/ruby Message-ID: <20260805091715.62D8DFEBF@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7988-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.25 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.25 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:13 +0200 (CEST) Subject: SUSE-CU-2026:7986-1: Security update of bci/ruby Message-ID: <20260805091713.604FCFE10@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7986-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.22 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.22 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:17:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:17:16 +0200 (CEST) Subject: SUSE-CU-2026:7989-1: Security update of bci/ruby Message-ID: <20260805091716.B9BE3FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7989-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.28 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.28 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:18:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:14 +0200 (CEST) Subject: SUSE-CU-2026:7991-1: Security update of bci/rust Message-ID: <20260805091814.66626FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7991-1 Container Tags : bci/rust:1.95 , bci/rust:1.95-sles15 , bci/rust:1.95.0 , bci/rust:1.95.0-2.4.7 , bci/rust:oldstable Container Release : 4.7 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:18:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:15 +0200 (CEST) Subject: SUSE-CU-2026:7992-1: Security update of bci/rust Message-ID: <20260805091815.C27AFFDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7992-1 Container Tags : bci/rust:1.95 , bci/rust:1.95-sles15 , bci/rust:1.95.0 , bci/rust:1.95.0-2.4.11 , bci/rust:oldstable Container Release : 4.11 Severity : important Type : security References : 1262631 1263656 1263658 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2972-1 Released: Tue Jul 14 13:33:14 2026 Summary: Recommended update for lifecycle-data-sle-module-development-tools Type: recommended Severity: moderate References: This update for lifecycle-data-sle-module-development-tools fixes the following issues: - lifecycle of gcc14 got extended until end of july. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated - glibc-devel-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:18:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:16 +0200 (CEST) Subject: SUSE-CU-2026:7993-1: Recommended update of bci/rust Message-ID: <20260805091816.D2A97FDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7993-1 Container Tags : bci/rust:1.95 , bci/rust:1.95-sles15 , bci/rust:1.95.0 , bci/rust:1.95.0-2.4.13 , bci/rust:oldstable Container Release : 4.13 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libatomic1-15.3.0+git11272-150000.1.12.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libgomp1-15.3.0+git11272-150000.1.12.1 updated - libitm1-15.3.0+git11272-150000.1.12.1 updated - libubsan1-15.3.0+git11272-150000.1.12.1 updated - libtsan2-15.3.0+git11272-150000.1.12.1 updated - liblsan0-15.3.0+git11272-150000.1.12.1 updated - libhwasan0-15.3.0+git11272-150000.1.12.1 updated - libasan8-15.3.0+git11272-150000.1.12.1 updated - cpp15-15.3.0+git11272-150000.1.12.1 updated - gcc15-15.3.0+git11272-150000.1.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:18:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:17 +0200 (CEST) Subject: SUSE-CU-2026:7994-1: Recommended update of bci/rust Message-ID: <20260805091817.E4F76FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7994-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-2.2.1 , bci/rust:oldstable Container Release : 2.1 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2379-1 Released: Thu Jun 11 18:12:09 2026 Summary: Recommended update for rust, rust1.96 Type: recommended Severity: moderate References: This update for rust, rust1.96 fixes the following issues: Changes in rust1.96: - Add rust1.96 - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.96.0 Changes in rust: - Update to version 1.96.0 - for details see the rust1.96 package ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3062-1 Released: Wed Jul 15 16:58:53 2026 Summary: Recommended update for rust, rust1.96 Type: recommended Severity: moderate References: This update for rust, rust1.96 fixes the following issues: Changes in rust1.96: - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.96.1 Changes in rust: - Update to version 1.96.1 - for details see the rust1.96 package The following package changes have been done: - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - rust1.96-1.96.1-150300.7.6.1 added - cargo1.96-1.96.1-150300.7.6.1 added - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated - cargo1.95-1.95.0-150300.7.3.1 removed - rust1.95-1.95.0-150300.7.3.1 removed From sle-container-updates at lists.suse.com Wed Aug 5 09:18:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:21 +0200 (CEST) Subject: SUSE-CU-2026:7997-1: Security update of bci/rust Message-ID: <20260805091821.6A0F2FEBF@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7997-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-2.2.6 , bci/rust:oldstable Container Release : 2.6 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:18:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:18:20 +0200 (CEST) Subject: SUSE-CU-2026:7996-1: Security update of bci/rust Message-ID: <20260805091820.17E65FE10@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7996-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-2.2.4 , bci/rust:oldstable Container Release : 2.4 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:37 +0200 (CEST) Subject: SUSE-CU-2026:6913-1: Security update of bci/rust Message-ID: <20260805091937.26036FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:6913-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.0 , bci/rust:1.96.0-1.4.5 , bci/rust:latest , bci/rust:stable Container Release : 4.5 Severity : important Type : security References : 1264971 1266340 1266341 1266342 1266343 1266345 1266349 1266350 1266351 1266352 1266353 1266355 1266356 1266357 CVE-2026-34180 CVE-2026-34181 CVE-2026-34183 CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 CVE-2026-45446 CVE-2026-45447 CVE-2026-7383 CVE-2026-9076 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2648-1 Released: Fri Jun 26 13:05:57 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1266340,1266341,1266342,1266343,1266345,1266349,1266350,1266351,1266352,1266353,1266355,1266356,1266357,CVE-2026-34180,CVE-2026-34181,CVE-2026-34183,CVE-2026-42766,CVE-2026-42767,CVE-2026-42768,CVE-2026-42769,CVE-2026-42770,CVE-2026-45445,CVE-2026-45446,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076 This update for openssl-3 fixes the following issues - CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). - CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). - CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). - CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343). - CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). - CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). - CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). - CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). - CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). - CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). - CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). - CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2661-1 Released: Fri Jun 26 15:15:48 2026 Summary: Recommended update for curl Type: recommended Severity: important References: 1264971 This update for curl fixes the following issues: - Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) The following package changes have been done: - libopenssl3-3.2.3-150700.5.36.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.36.1 updated - libcurl4-8.14.1-150700.7.17.1 updated - container:registry.suse.com-bci-bci-base-15.7-0180bc786e784f4f99302a008c5991e2d05f7fac404ce0fa2a07aaef564e6ef8-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:39 +0200 (CEST) Subject: SUSE-CU-2026:7999-1: Security update of bci/rust Message-ID: <20260805091939.727C5FDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7999-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-1.4.12 , bci/rust:latest , bci/rust:stable Container Release : 4.12 Severity : important Type : security References : 1262631 1263656 1263658 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:2972-1 Released: Tue Jul 14 13:33:14 2026 Summary: Recommended update for lifecycle-data-sle-module-development-tools Type: recommended Severity: moderate References: This update for lifecycle-data-sle-module-development-tools fixes the following issues: - lifecycle of gcc14 got extended until end of july. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3062-1 Released: Wed Jul 15 16:58:53 2026 Summary: Recommended update for rust, rust1.96 Type: recommended Severity: moderate References: This update for rust, rust1.96 fixes the following issues: Changes in rust1.96: - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.96.1 Changes in rust: - Update to version 1.96.1 - for details see the rust1.96 package The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated - glibc-devel-2.38-150600.14.52.1 updated - rust1.96-1.96.1-150300.7.6.1 updated - cargo1.96-1.96.1-150300.7.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:38 +0200 (CEST) Subject: SUSE-CU-2026:7998-1: Security update of bci/rust Message-ID: <20260805091938.1F2A2FDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:7998-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.0 , bci/rust:1.96.0-1.4.7 , bci/rust:latest , bci/rust:stable Container Release : 4.7 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:40 +0200 (CEST) Subject: SUSE-CU-2026:8000-1: Recommended update of bci/rust Message-ID: <20260805091940.BCA74FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8000-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-1.4.14 , bci/rust:latest , bci/rust:stable Container Release : 4.14 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libatomic1-15.3.0+git11272-150000.1.12.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libgomp1-15.3.0+git11272-150000.1.12.1 updated - libitm1-15.3.0+git11272-150000.1.12.1 updated - libubsan1-15.3.0+git11272-150000.1.12.1 updated - libtsan2-15.3.0+git11272-150000.1.12.1 updated - liblsan0-15.3.0+git11272-150000.1.12.1 updated - libhwasan0-15.3.0+git11272-150000.1.12.1 updated - libasan8-15.3.0+git11272-150000.1.12.1 updated - cpp15-15.3.0+git11272-150000.1.12.1 updated - gcc15-15.3.0+git11272-150000.1.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:45 +0200 (CEST) Subject: SUSE-CU-2026:8004-1: Security update of bci/rust Message-ID: <20260805091945.659B4FED5@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8004-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.6 , bci/rust:latest , bci/rust:stable Container Release : 2.6 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:44 +0200 (CEST) Subject: SUSE-CU-2026:8003-1: Security update of bci/rust Message-ID: <20260805091944.128BAFEBF@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8003-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.4 , bci/rust:latest , bci/rust:stable Container Release : 2.4 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 09:19:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 11:19:42 +0200 (CEST) Subject: SUSE-CU-2026:8001-1: Recommended update of bci/rust Message-ID: <20260805091942.15BB7FE10@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8001-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.1 , bci/rust:latest , bci/rust:stable Container Release : 2.1 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3170-1 Released: Tue Jul 21 23:15:49 2026 Summary: Recommended update for rust Type: recommended Severity: moderate References: This update for rust fixes the following issues: Update to rust1.97.1: - Release notes can be found externally: https://github.com/rust-lang/rust/releases/tag/1.97.1 Changes in rust: - Update to version 1.97.0 - for details see the rust1.97 package The following package changes have been done: - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - rust1.97-1.97.1-150300.7.5.1 added - cargo1.97-1.97.1-150300.7.5.1 added - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated - cargo1.96-1.96.1-150300.7.6.1 removed - rust1.96-1.96.1-150300.7.6.1 removed From sle-container-updates at lists.suse.com Wed Aug 5 10:20:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:20:23 +0200 (CEST) Subject: SUSE-CU-2026:8004-1: Security update of bci/rust Message-ID: <20260805102023.57574FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8004-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.6 , bci/rust:latest , bci/rust:stable Container Release : 2.6 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:15 +0200 (CEST) Subject: SUSE-CU-2026:8005-1: Security update of suse/samba-client Message-ID: <20260805102115.1F804FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8005-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-74.10 , suse/samba-client:latest Container Release : 74.10 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:16 +0200 (CEST) Subject: SUSE-CU-2026:8006-1: Security update of suse/samba-client Message-ID: <20260805102116.2053FFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8006-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-74.20 , suse/samba-client:latest Container Release : 74.20 Severity : important Type : security References : 1252306 1253043 1257463 1263656 1263658 1268290 1269790 CVE-2026-11979 CVE-2026-5435 CVE-2026-54411 CVE-2026-6238 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:17 +0200 (CEST) Subject: SUSE-CU-2026:8007-1: Security update of suse/samba-client Message-ID: <20260805102117.539D9FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8007-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-74.21 , suse/samba-client:latest Container Release : 74.21 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:19 +0200 (CEST) Subject: SUSE-CU-2026:8009-1: Security update of suse/samba-client Message-ID: <20260805102119.47286FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8009-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-74.24 , suse/samba-client:latest Container Release : 74.24 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:18 +0200 (CEST) Subject: SUSE-CU-2026:8008-1: Security update of suse/samba-client Message-ID: <20260805102118.6292DFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8008-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-74.23 , suse/samba-client:latest Container Release : 74.23 Severity : moderate Type : security References : 1255451 CVE-2025-59529 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). The following package changes have been done: - libavahi-common3-0.8-150600.15.21.1 updated - libavahi-client3-0.8-150600.15.21.1 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:20 +0200 (CEST) Subject: SUSE-CU-2026:8010-1: Security update of suse/samba-client Message-ID: <20260805102120.2D53DFE13@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8010-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.2 , suse/samba-client:latest Container Release : 75.2 Severity : important Type : security References : 1271469 1271672 1271673 1271674 1271675 1271676 1271677 CVE-2026-15779 CVE-2026-58216 CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-6949 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3363-1 Released: Tue Jul 28 14:19:01 2026 Summary: Security update for samba Type: security Severity: important References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949 This update for samba fixes the following issues - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). The following package changes have been done: - libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:21 +0200 (CEST) Subject: SUSE-CU-2026:8011-1: Security update of suse/samba-client Message-ID: <20260805102121.30A4EFEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8011-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.4 , suse/samba-client:latest Container Release : 75.4 Severity : moderate Type : security References : 1254340 1254341 1260998 1261002 1261003 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3429-1 Released: Thu Jul 30 13:18:04 2026 Summary: Security update for libarchive Type: security Severity: moderate References: 1254340,1254341,1260998,1261002,1261003 This update for libarchive fixes the following issues: - creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). - file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). - NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). - reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). - incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002). The following package changes have been done: - libarchive13-3.7.2-150600.3.23.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:21:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:21:22 +0200 (CEST) Subject: SUSE-CU-2026:8012-1: Security update of suse/samba-client Message-ID: <20260805102122.66FE7FEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8012-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.5 , suse/samba-client:latest Container Release : 75.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:14 +0200 (CEST) Subject: SUSE-CU-2026:8013-1: Security update of suse/samba-server Message-ID: <20260805102214.CDB2FFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8013-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-75.11 , suse/samba-server:latest Container Release : 75.11 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:16 +0200 (CEST) Subject: SUSE-CU-2026:8014-1: Security update of suse/samba-server Message-ID: <20260805102216.06659FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8014-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-75.22 , suse/samba-server:latest Container Release : 75.22 Severity : important Type : security References : 1252306 1253043 1257463 1263656 1263658 1268290 1269790 1270393 CVE-2026-11979 CVE-2026-5435 CVE-2026-54411 CVE-2026-6238 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:17 +0200 (CEST) Subject: SUSE-CU-2026:8015-1: Security update of suse/samba-server Message-ID: <20260805102217.31FCFFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8015-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-75.23 , suse/samba-server:latest Container Release : 75.23 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:18 +0200 (CEST) Subject: SUSE-CU-2026:8016-1: Security update of suse/samba-server Message-ID: <20260805102218.39FEFFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8016-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-75.25 , suse/samba-server:latest Container Release : 75.25 Severity : moderate Type : security References : 1255451 CVE-2025-59529 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). The following package changes have been done: - libavahi-common3-0.8-150600.15.21.1 updated - libavahi-client3-0.8-150600.15.21.1 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:19 +0200 (CEST) Subject: SUSE-CU-2026:8017-1: Security update of suse/samba-server Message-ID: <20260805102219.43603FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8017-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-75.26 , suse/samba-server:latest Container Release : 75.26 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:20 +0200 (CEST) Subject: SUSE-CU-2026:8018-1: Security update of suse/samba-server Message-ID: <20260805102220.76A0CFE13@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8018-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.2 , suse/samba-server:latest Container Release : 76.2 Severity : important Type : security References : 1271469 1271672 1271673 1271674 1271675 1271676 1271677 CVE-2026-15779 CVE-2026-58216 CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-6949 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3363-1 Released: Tue Jul 28 14:19:01 2026 Summary: Security update for samba Type: security Severity: important References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949 This update for samba fixes the following issues - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). The following package changes have been done: - libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-dcerpc-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:22 +0200 (CEST) Subject: SUSE-CU-2026:8020-1: Security update of suse/samba-server Message-ID: <20260805102222.D9E68FEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8020-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.6 , suse/samba-server:latest Container Release : 76.6 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:22:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:22:21 +0200 (CEST) Subject: SUSE-CU-2026:8019-1: Security update of suse/samba-server Message-ID: <20260805102221.A7C74FEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8019-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.4 , suse/samba-server:latest Container Release : 76.4 Severity : moderate Type : security References : 1254340 1254341 1260998 1261002 1261003 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3429-1 Released: Thu Jul 30 13:18:04 2026 Summary: Security update for libarchive Type: security Severity: moderate References: 1254340,1254341,1260998,1261002,1261003 This update for libarchive fixes the following issues: - creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). - file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). - NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). - reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). - incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002). The following package changes have been done: - libarchive13-3.7.2-150600.3.23.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:23:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:23:13 +0200 (CEST) Subject: SUSE-CU-2026:8021-1: Security update of suse/samba-toolbox Message-ID: <20260805102313.0AEC2FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8021-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.10 , suse/samba-toolbox:latest Container Release : 75.10 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:23:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:23:14 +0200 (CEST) Subject: SUSE-CU-2026:8022-1: Security update of suse/samba-toolbox Message-ID: <20260805102314.34E82FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8022-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.20 , suse/samba-toolbox:latest Container Release : 75.20 Severity : important Type : security References : 1252306 1253043 1257463 1263656 1263658 1268290 1269790 CVE-2026-11979 CVE-2026-5435 CVE-2026-54411 CVE-2026-6238 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - pam-1.3.0-150000.6.89.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:23:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:23:15 +0200 (CEST) Subject: SUSE-CU-2026:8023-1: Security update of suse/samba-toolbox Message-ID: <20260805102315.5BD60FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8023-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.21 , suse/samba-toolbox:latest Container Release : 75.21 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 10:23:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 12:23:16 +0200 (CEST) Subject: SUSE-CU-2026:8024-1: Security update of suse/samba-toolbox Message-ID: <20260805102316.77FD4FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8024-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.23 , suse/samba-toolbox:latest Container Release : 75.23 Severity : moderate Type : security References : 1255451 CVE-2025-59529 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). The following package changes have been done: - libavahi-common3-0.8-150600.15.21.1 updated - libavahi-client3-0.8-150600.15.21.1 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:21:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:21:58 +0200 (CEST) Subject: SUSE-CU-2026:8024-1: Security update of suse/samba-toolbox Message-ID: <20260805122158.7AB9AFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8024-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.23 , suse/samba-toolbox:latest Container Release : 75.23 Severity : moderate Type : security References : 1255451 CVE-2025-59529 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3218-1 Released: Thu Jul 23 19:34:12 2026 Summary: Security update for avahi Type: security Severity: moderate References: 1255451,CVE-2025-59529 This update for avahi fixes the following issue: - CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451). The following package changes have been done: - libavahi-common3-0.8-150600.15.21.1 updated - libavahi-client3-0.8-150600.15.21.1 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:21:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:21:59 +0200 (CEST) Subject: SUSE-CU-2026:8025-1: Security update of suse/samba-toolbox Message-ID: <20260805122159.853C8FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8025-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-75.24 , suse/samba-toolbox:latest Container Release : 75.24 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:22:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:22:00 +0200 (CEST) Subject: SUSE-CU-2026:8026-1: Security update of suse/samba-toolbox Message-ID: <20260805122200.98ECCFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8026-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.2 , suse/samba-toolbox:latest Container Release : 76.2 Severity : important Type : security References : 1271469 1271672 1271673 1271674 1271675 1271676 1271677 CVE-2026-15779 CVE-2026-58216 CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-6949 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3363-1 Released: Tue Jul 28 14:19:01 2026 Summary: Security update for samba Type: security Severity: important References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949 This update for samba fixes the following issues - CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). - CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). - CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). - CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). - CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). - CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). - CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). The following package changes have been done: - libldb2-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-libs-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - samba-client-4.21.10+git.533.31d7e5508d-150700.3.29.1 updated - container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:22:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:22:01 +0200 (CEST) Subject: SUSE-CU-2026:8027-1: Security update of suse/samba-toolbox Message-ID: <20260805122201.ACA1BFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8027-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.4 , suse/samba-toolbox:latest Container Release : 76.4 Severity : moderate Type : security References : 1254340 1254341 1260998 1261002 1261003 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3429-1 Released: Thu Jul 30 13:18:04 2026 Summary: Security update for libarchive Type: security Severity: moderate References: 1254340,1254341,1260998,1261002,1261003 This update for libarchive fixes the following issues: - creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). - file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). - NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). - reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). - incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002). The following package changes have been done: - libarchive13-3.7.2-150600.3.23.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:22:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:22:02 +0200 (CEST) Subject: SUSE-CU-2026:8028-1: Security update of suse/samba-toolbox Message-ID: <20260805122202.BE5A8FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8028-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.5 , suse/samba-toolbox:latest Container Release : 76.5 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:03 +0200 (CEST) Subject: SUSE-CU-2026:8029-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122303.44706FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8029-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.11 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.11 Severity : important Type : security References : 1236743 1255029 1259764 1261256 1261562 1261604 1262618 1262655 1263072 1263560 1263573 1263581 1263879 1263880 1263998 1264001 1264015 1264084 1264116 1264145 1264228 1264230 1264231 1264236 1264241 1264254 1264258 1264261 1264263 1264286 1264294 1264320 1264337 1264449 1264484 1264562 1264612 1264734 1264748 1264814 1264974 1265113 1265421 1265629 1266008 1266396 1266700 1266717 1266734 1266830 1266847 1266899 1266928 1266929 1267228 1267365 1267369 1267381 1267427 1267430 1267437 1267458 1267567 1267582 1267591 1267635 1267637 1267640 1267682 1267684 1267697 1267717 1267722 1267825 1267918 1267937 1267953 1267966 1267993 1268022 1268037 1268049 1268159 1268237 1268307 1268335 1268428 1268660 1268661 1269022 1269033 1269090 1269100 1269103 1269135 1269136 1269137 1269184 1269195 1269199 1269281 1269310 1269314 1269397 1269398 1269418 1269493 1269506 1269519 1269574 1269617 1269678 1269681 1269798 1269821 1269884 1270059 CVE-2025-40216 CVE-2025-40341 CVE-2025-71294 CVE-2026-23451 CVE-2026-31450 CVE-2026-31462 CVE-2026-31466 CVE-2026-31502 CVE-2026-31647 CVE-2026-31670 CVE-2026-31677 CVE-2026-31697 CVE-2026-31698 CVE-2026-31699 CVE-2026-31771 CVE-2026-43010 CVE-2026-43022 CVE-2026-43034 CVE-2026-43053 CVE-2026-43074 CVE-2026-43079 CVE-2026-43080 CVE-2026-43081 CVE-2026-43085 CVE-2026-43086 CVE-2026-43089 CVE-2026-43093 CVE-2026-43094 CVE-2026-43107 CVE-2026-43109 CVE-2026-43128 CVE-2026-43139 CVE-2026-43233 CVE-2026-43238 CVE-2026-43284 CVE-2026-43303 CVE-2026-43336 CVE-2026-43420 CVE-2026-43456 CVE-2026-43472 CVE-2026-43492 CVE-2026-43502 CVE-2026-45838 CVE-2026-45848 CVE-2026-45891 CVE-2026-45912 CVE-2026-45948 CVE-2026-45985 CVE-2026-46028 CVE-2026-46053 CVE-2026-46063 CVE-2026-46065 CVE-2026-46069 CVE-2026-46071 CVE-2026-46076 CVE-2026-46112 CVE-2026-46116 CVE-2026-46120 CVE-2026-46124 CVE-2026-46133 CVE-2026-46173 CVE-2026-46185 CVE-2026-46197 CVE-2026-46214 CVE-2026-46227 CVE-2026-46229 CVE-2026-46253 CVE-2026-46254 CVE-2026-46266 CVE-2026-46274 CVE-2026-46289 CVE-2026-46291 CVE-2026-46315 CVE-2026-46319 CVE-2026-46320 CVE-2026-46328 CVE-2026-46330 CVE-2026-46331 CVE-2026-52908 CVE-2026-52909 CVE-2026-52918 CVE-2026-52923 CVE-2026-52943 CVE-2026-52954 CVE-2026-52957 CVE-2026-52962 CVE-2026-52969 CVE-2026-52972 CVE-2026-53016 CVE-2026-53040 CVE-2026-53041 CVE-2026-53052 CVE-2026-53053 CVE-2026-53071 CVE-2026-53072 CVE-2026-53122 CVE-2026-53133 CVE-2026-53138 CVE-2026-53182 CVE-2026-53253 CVE-2026-53266 CVE-2026-53281 CVE-2026-53287 CVE-2026-53359 CVE-2026-53362 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2800-1 Released: Wed Jul 8 16:59:16 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1236743,1255029,1259764,1261256,1261562,1261604,1262618,1262655,1263072,1263560,1263573,1263581,1263879,1263880,1263998,1264001,1264015,1264084,1264116,1264145,1264228,1264230,1264231,1264236,1264241,1264254,1264258,1264261,1264263,1264286,1264294,1264320,1264337,1264449,1264484,1264562,1264612,1264734,1264748,1264814,1264974,1265113,1265421,1265629,1266008,1266396,1266700,1266717,1266734,1266830,1266847,1266899,1266928,1266929,1267228,1267365,1267369,1267381,1267427,1267430,1267437,1267458,1267567,1267582,1267591,1267635,1267637,1267640,1267682,1267684,1267697,1267717,1267722,1267825,1267918,1267937,1267953,1267966,1267993,1268022,1268037,1268049,1268159,1268237,1268307,1268335,1268428,1268660,1268661,1269022,1269033,1269090,1269100,1269103,1269135,1269136,1269137,1269184,1269195,1269199,1269281,1269310,1269314,1269397,1269398,1269418,1269493,1269506,1269519,1269574,1269617,1269678,1269681,1269798,1269821,1269884,1270059,CVE-2025-40216,CVE-2025-40341,CVE-2025-71294,CVE- 2026-23451,CVE-2026-31450,CVE-2026-31462,CVE-2026-31466,CVE-2026-31502,CVE-2026-31647,CVE-2026-31670,CVE-2026-31677,CVE-2026-31697,CVE-2026-31698,CVE-2026-31699,CVE-2026-31771,CVE-2026-43010,CVE-2026-43022,CVE-2026-43034,CVE-2026-43053,CVE-2026-43074,CVE-2026-43079,CVE-2026-43080,CVE-2026-43081,CVE-2026-43085,CVE-2026-43086,CVE-2026-43089,CVE-2026-43093,CVE-2026-43094,CVE-2026-43107,CVE-2026-43109,CVE-2026-43128,CVE-2026-43139,CVE-2026-43233,CVE-2026-43238,CVE-2026-43284,CVE-2026-43303,CVE-2026-43336,CVE-2026-43420,CVE-2026-43456,CVE-2026-43472,CVE-2026-43492,CVE-2026-43502,CVE-2026-45838,CVE-2026-45848,CVE-2026-45891,CVE-2026-45912,CVE-2026-45948,CVE-2026-45985,CVE-2026-46028,CVE-2026-46053,CVE-2026-46063,CVE-2026-46065,CVE-2026-46069,CVE-2026-46071,CVE-2026-46076,CVE-2026-46112,CVE-2026-46116,CVE-2026-46120,CVE-2026-46124,CVE-2026-46133,CVE-2026-46173,CVE-2026-46185,CVE-2026-46197,CVE-2026-46214,CVE-2026-46227,CVE-2026-46229,CVE-2026-46253,CVE-2026-46254,CVE-2026-46266,CVE-2026-46 274,CVE-2026-46289,CVE-2026-46291,CVE-2026-46315,CVE-2026-46319,CVE-2026-46320,CVE-2026-46328,CVE-2026-46330,CVE-2026-46331,CVE-2026-52908,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52943,CVE-2026-52954,CVE-2026-52957,CVE-2026-52962,CVE-2026-52969,CVE-2026-52972,CVE-2026-53016,CVE-2026-53040,CVE-2026-53041,CVE-2026-53052,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53122,CVE-2026-53133,CVE-2026-53138,CVE-2026-53182,CVE-2026-53253,CVE-2026-53266,CVE-2026-53281,CVE-2026-53287,CVE-2026-53359,CVE-2026-53362 The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: - CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). - CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). - CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). - CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). - CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). - CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). - CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). - CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). - CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). - CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). - CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). - CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). - CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). - CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). - CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). - CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). - CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). - CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). - CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). - CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). - CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). - CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). - CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). - CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). - CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). - CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). - CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). - CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). - CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). - CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). - CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). - CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). - CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). - CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). - CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). - CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). - CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). - CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). - CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). - CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). - CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). - CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). - CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). - CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). - CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). - CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). - CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). - CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). - CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). - CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). - CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). - CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). - CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). - CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). - CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). - CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). - CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). - CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). - CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). - CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). - CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). - CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). - CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). - CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). - CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). - CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). - CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). - CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). - CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). - CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). - CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). - CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). - CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). - CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). - CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049). - CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). - CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). - CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). - CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). - CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). - CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). - CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). - CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). - CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). - CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). - CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). - CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). - CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). - CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). - CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). - CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). - CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). - CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). - CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). - CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). - CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). - CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). - CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). - CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). - CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). - CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). - CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). - CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: - ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). - ACPI: resource: Amend kernel-doc style (git-fixes). - ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). - ALSA: firewire: isight: bound the sample count to the packet payload (git-fixes). - ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). - ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). - ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). - ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). - ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). - ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git-fixes). - ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git-fixes). - ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git-fixes). - Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable-fixes). - bnxt_en: Fix NULL pointer dereference (bsc#1268307). - bus: mhi: ep: Add missing state_lock protection for mhi_state access (git-fixes). - bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). - bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). - char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). - dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). - dmaengine: Fix possible use after free (git-fixes). - dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). - dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). - dmaengine: tegra: Fix burst size calculation (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable-fixes). - drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). - drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). - drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). - drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). - drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git-fixes). - drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). - drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). - drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git-fixes). - drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). - drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). - drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable-fixes). - drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). - drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). - drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). - drm/dp: Add eDP 1.5 bit definition (stable-fixes). - drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). - drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). - drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). - drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). - drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). - drm/nouveau: fix reversed error cleanup order in ucopy functions (git-fixes). - ethtool: provide customized dim profile management (bsc#1261256). - fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). - fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). - fpga: region: fix use-after-free in child_regions_with_firmware() (git-fixes). - HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). - HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). - HID: wacom: stop hardware after post-start probe failures (git-fixes). - HID: wiimote: Fix table layout and whitespace errors (git-fixes). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). - i2c: mpc: Fix timeout calculations (git-fixes). - i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). - i3c: master: Prevent reuse of dynamic address on device add failure (git-fixes). - iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). - iio: adc: npcm: Convert to platform remove callback returning void (stable-fixes). - iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). - iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). - iio: chemical: scd30: fix division by zero in write_raw (git-fixes). - iio: chemical: scd30: Use guard(mutex) to allow early returns (stable-fixes). - iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git-fixes). - iio: gyro: bmg160: wait full startup time after mode change at probe (git-fixes). - iio: light: opt3001: fix missing state reset on timeout (git-fixes). - iio: light: si1133: prevent race condition on timeout (git-fixes). - iio: light: si1133: reset counter to prevent race condition (git-fixes). - iio: light: veml6030: fix channel type when pushing events (git-fixes). - iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). - iio: magnetometer: ak8975: fix potential kernel stack memory leak (git-fixes). - iio: tcs3472: power down chip on probe failure (git-fixes). - iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). - Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). - Input: elan_i2c - validate firmware size before use (stable-fixes). - Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable-fixes). - Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). - Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git-fixes). - Input: xpad - add 'Nova 2 Lite' from GameSir (stable-fixes). - Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). - iommu/s390: allow larger region tables (jsc#PED-15880). - iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). - iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). - iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). - iommu/s390: set appropriate IOTA region type (jsc#PED-15880). - iommu/s390: support cleanup of additional table regions (jsc#PED-15880). - iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). - iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). - KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). - KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). - KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). - KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). - KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). - KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). - KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). - KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). - KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes). - KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). - KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). - KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). - leds: uleds: Fix potential buffer overread (git-fixes). - linux/dim: move useful macros to .h file (bsc#1261256). - loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). - loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). - mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). - media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). - media: cec: seco: unregister adapter on IR probe failure (git-fixes). - media: cedrus: Fix failure to clean up hardware on probe failure (git-fixes). - media: cedrus: Fix missing cleanup in error path (git-fixes). - media: cedrus: skip invalid H.264 reference list entries (git-fixes). - media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). - media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). - media: pci: dm1105: Free allocated workqueue (git-fixes). - media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). - media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). - media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). - media: vidtv: fix reference leak on failed device registration (git-fixes). - media: vimc: fix reference leak on failed device registration (git-fixes). - media: vpif_capture: fix OF node reference imbalance (git-fixes). - module: fix init_module_from_file() error handling (jsc#PED-16303). - module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). - module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). - module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). - module: warn about excessively long module waits (jsc#PED-16303). - modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). - mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git-fixes). - mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). - mtd: rawnand: pl353: fix probe resource allocation (git-fixes). - mtd: slram: remove failed entries from the device list (git-fixes). - mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). - mtd: spi-nor: swp: Improve locking user experience (git-fixes). - net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). - net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). - net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Add support for RX CQE Coalescing (bsc#1261256). - net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). - net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). - net: mana: Optimize irq affinity for low vcpu configs (git-fixes). - net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). - net: mana: Use GIC functions to allocate global EQs (git-fixes). - nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). - nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). - nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). - page_pool: Move pp_magic check into helper functions (bsc#1261562). - page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). - platform/x86: intel-hid: Protect ACPI notify handler against recursion (git-fixes). - platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). - power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). - power: supply: charger-manager: fix refcount leak in is_full_charged() (git-fixes). - power: supply: core: fix supplied_from allocations (git-fixes). - power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). - powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). - powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git-fixes). - RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). - rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). - rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). - rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). - rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git-fixes). - rtc: mpfs: fix counter upload completion condition (git-fixes). - rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). - s390/pci: check for relaxed translation capability (jsc#PED-15880). - s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). - s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). - selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). - selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). - selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). - selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). - selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). - selftests/bpf: Skip tests whose objects were not built (bsc#1269617). - selftests/bpf: Tolerate benchmark build failures (bsc#1269617). - selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). - selftests/bpf: Tolerate missing files during install (bsc#1269617). - selftests/bpf: Tolerate test file compilation failures (bsc#1269617). - serdev: make serdev_bus_type const (stable-fixes). - spi: dw: fix wrong BAUDR setting after resume (git-fixes). - spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). - spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). - Split off kABI workaround for bsc#1267458 (bsc#1267458). - staging: most: video: avoid double free on video register failure (git-fixes). - staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). - thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). - tpm: fix event_size output in tpm1_binary_bios_measurements_show (git-fixes). - tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). - usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). - usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). - usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). - usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git-fixes). - usb: host: max3421: Reject hub port requests for non-existent ports (git-fixes). - USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). - USB: serial: option: add MeiG SRM813Q (stable-fixes). - USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). - usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). - usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). - usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). - usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). - usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). - usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). - usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). - vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). - watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). - x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). - x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). The following package changes have been done: - kernel-macros-6.4.0-150700.53.66.1 updated - kernel-devel-6.4.0-150700.53.66.1 updated - kernel-default-devel-6.4.0-150700.53.66.1 updated - kernel-syms-6.4.0-150700.53.66.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:05 +0200 (CEST) Subject: SUSE-CU-2026:8031-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122305.D284EFD94@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8031-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.14 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.14 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:registry.suse.com-bci-bci-base-15.7-5ff809d19262d313d69f1ae0865ec528937c6413d54b48b7e5a70737c361767d-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:07 +0200 (CEST) Subject: SUSE-CU-2026:8032-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122307.BEA08FDD1@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8032-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.17 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.17 Severity : important Type : security References : 1262631 1263656 1263658 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - libcurl4-8.14.1-150700.7.20.1 updated - glibc-locale-base-2.38-150600.14.52.1 updated - glibc-locale-2.38-150600.14.52.1 updated - glibc-devel-2.38-150600.14.52.1 updated - container:registry.suse.com-bci-bci-base-15.7-f530e7e9d27a0df748164ea3fc458d4abcea505c44cd4a431fc6c44a7ebffc90-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:11 +0200 (CEST) Subject: SUSE-CU-2026:8034-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122311.CC133FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8034-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.28 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.28 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:13 +0200 (CEST) Subject: SUSE-CU-2026:8035-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122313.597BEFD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8035-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.31 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.31 Severity : important Type : security References : 1269622 1271405 CVE-2026-41991 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3202-1 Released: Thu Jul 23 15:12:34 2026 Summary: Recommended update for pesign Type: recommended Severity: important References: 1271405 This update for pesign fixes the following issues: - Set stricter permissions on /etc/pki/pesign (bsc#1271405) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gzip-1.10-150200.13.1 updated - pesign-0.112-150000.4.29.1 updated - container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:14 +0200 (CEST) Subject: SUSE-CU-2026:8036-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122314.DB174FDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8036-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.33 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.33 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libssh-config-0.9.8-150600.11.15.1 updated - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh4-0.9.8-150600.11.15.1 updated - container:registry.suse.com-bci-bci-base-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:23:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:23:16 +0200 (CEST) Subject: SUSE-CU-2026:8037-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260805122316.5F123FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8037-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.36 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.36 Severity : moderate Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:01 +0200 (CEST) Subject: SUSE-CU-2026:8038-1: Security update of suse/sle15 Message-ID: <20260805122401.E821EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8038-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.39 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.39 , suse/sle15:latest Container Release : 5.20.39 Severity : important Type : security References : 1261900 1265450 1267189 CVE-2026-5704 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2714-1 Released: Tue Jun 30 14:02:53 2026 Summary: Security update for tar Type: security Severity: important References: 1261900,1265450,1267189,CVE-2026-5704 This update for tar fixes the following issues Security fixes: - CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). Other fixes: - Fix tar changing dir permissions temporarily even when using --no-overwrite-dir. - Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). - Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2 implementation (bsc#1267189). The following package changes have been done: - container-suseconnect-2.5.6-150700.4.90.4 updated - tar-1.34-150000.3.42.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:02 +0200 (CEST) Subject: SUSE-CU-2026:8039-1: Security update of suse/sle15 Message-ID: <20260805122402.CA5ADFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8039-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.40 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.40 , suse/sle15:latest Container Release : 5.20.40 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:03 +0200 (CEST) Subject: SUSE-CU-2026:8040-1: Security update of suse/sle15 Message-ID: <20260805122403.DF64DFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8040-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.42 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.42 , suse/sle15:latest Container Release : 5.20.42 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - curl-8.14.1-150700.7.20.1 updated - libcurl4-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:07 +0200 (CEST) Subject: SUSE-CU-2026:8043-1: Security update of suse/sle15 Message-ID: <20260805122407.444A8FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8043-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.49 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.49 , suse/sle15:latest Container Release : 5.20.49 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:08 +0200 (CEST) Subject: SUSE-CU-2026:8044-1: Security update of suse/sle15 Message-ID: <20260805122408.60396FEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8044-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.50 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.50 , suse/sle15:latest Container Release : 5.20.50 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:05 +0200 (CEST) Subject: SUSE-CU-2026:8041-1: Security update of suse/sle15 Message-ID: <20260805122405.08B76FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8041-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.44 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.44 , suse/sle15:latest Container Release : 5.20.44 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - container-suseconnect-2.5.6-150700.4.92.1 updated - glibc-2.38-150600.14.52.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:06 +0200 (CEST) Subject: SUSE-CU-2026:8042-1: Security update of suse/sle15 Message-ID: <20260805122406.22FFCFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8042-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.48 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.48 , suse/sle15:latest Container Release : 5.20.48 Severity : important Type : security References : 1252306 1253043 1257463 1269790 1270393 CVE-2026-11979 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - login_defs-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:24:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:24:09 +0200 (CEST) Subject: SUSE-CU-2026:8045-1: Security update of suse/sle15 Message-ID: <20260805122409.7EF48FEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8045-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.53 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.53 , suse/sle15:latest Container Release : 5.20.53 Severity : important Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 1269279 1269622 CVE-2026-40226 CVE-2026-41991 CVE-2026-57062 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gpg2-2.4.4-150600.3.18.1 updated - gzip-1.10-150200.13.1 updated - libudev1-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:50:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:50:25 +0200 (CEST) Subject: SUSE-CU-2026:8045-1: Security update of suse/sle15 Message-ID: <20260805125025.77CE4FC32@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8045-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.53 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.53 , suse/sle15:latest Container Release : 5.20.53 Severity : important Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 1269279 1269622 CVE-2026-40226 CVE-2026-41991 CVE-2026-57062 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - gpg2-2.4.4-150600.3.18.1 updated - gzip-1.10-150200.13.1 updated - libudev1-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:50:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:50:26 +0200 (CEST) Subject: SUSE-CU-2026:8046-1: Security update of suse/sle15 Message-ID: <20260805125026.90739FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8046-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.2 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.2 , suse/sle15:latest Container Release : 5.23.2 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libssh-config-0.9.8-150600.11.15.1 updated - libssh4-0.9.8-150600.11.15.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:50:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:50:27 +0200 (CEST) Subject: SUSE-CU-2026:8047-1: Security update of suse/sle15 Message-ID: <20260805125027.A881AFDC9@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8047-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.3 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.3 , suse/sle15:latest Container Release : 5.23.3 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:27 +0200 (CEST) Subject: SUSE-CU-2026:8049-1: Security update of bci/spack Message-ID: <20260805125227.0A31AFC32@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8049-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.10 , bci/spack:latest Container Release : 25.10 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-devel-1.20.1-150600.11.19.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:29 +0200 (CEST) Subject: SUSE-CU-2026:8051-1: Security update of bci/spack Message-ID: <20260805125229.C7C29FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8051-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.12 , bci/spack:latest Container Release : 25.12 Severity : important Type : security References : 1262631 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-4873 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2925-1 Released: Mon Jul 13 19:53:23 2026 Summary: Security update for curl Type: security Severity: important References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - libcurl-devel-8.14.1-150700.7.20.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:32 +0200 (CEST) Subject: SUSE-CU-2026:8053-1: Security update of bci/spack Message-ID: <20260805125232.79CEDFDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8053-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.14 , bci/spack:latest Container Release : 25.14 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-devel-2.38-150600.14.52.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:35 +0200 (CEST) Subject: SUSE-CU-2026:8055-1: Recommended update of bci/spack Message-ID: <20260805125235.0AA21FDE2@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8055-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.17 , bci/spack:latest Container Release : 25.17 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libatomic1-15.3.0+git11272-150000.1.12.1 updated - libgomp1-15.3.0+git11272-150000.1.12.1 updated - libitm1-15.3.0+git11272-150000.1.12.1 updated - liblsan0-15.3.0+git11272-150000.1.12.1 updated - libquadmath0-15.3.0+git11272-150000.1.12.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:36 +0200 (CEST) Subject: SUSE-CU-2026:8056-1: Security update of bci/spack Message-ID: <20260805125236.37938FDFA@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8056-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.20 , bci/spack:latest Container Release : 25.20 Severity : important Type : security References : 1269790 1270393 1271166 1271167 CVE-2026-11979 CVE-2026-56288 CVE-2026-56289 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3161-1 Released: Tue Jul 21 16:30:29 2026 Summary: Security update for patch Type: security Severity: low References: 1271166,1271167,CVE-2026-56288,CVE-2026-56289 This update for patch fixes the following issues - CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). - CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.12.10-150700.4.14.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - patch-2.7.6-150000.5.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:37 +0200 (CEST) Subject: SUSE-CU-2026:8057-1: Security update of bci/spack Message-ID: <20260805125237.459DEFC32@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8057-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.21 , bci/spack:latest Container Release : 25.21 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.3.0-150000.6.89.1 updated - container:registry.suse.com-bci-bci-base-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:38 +0200 (CEST) Subject: SUSE-CU-2026:8058-1: Security update of bci/spack Message-ID: <20260805125238.4C5EBFE10@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8058-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.23 , bci/spack:latest Container Release : 25.23 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:39 +0200 (CEST) Subject: SUSE-CU-2026:8059-1: Security update of bci/spack Message-ID: <20260805125239.58F09FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8059-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.24 , bci/spack:latest Container Release : 25.24 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:40 +0200 (CEST) Subject: SUSE-CU-2026:8060-1: Security update of bci/spack Message-ID: <20260805125240.8B757FEBF@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8060-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.26 , bci/spack:latest Container Release : 25.26 Severity : important Type : security References : 1269279 1269622 CVE-2026-41991 CVE-2026-57062 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3243-1 Released: Fri Jul 24 15:09:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). The following package changes have been done: - libudev1-254.27-150600.4.71.2 updated - gpg2-2.4.4-150600.3.18.1 updated - gzip-1.10-150200.13.1 updated - container:registry.suse.com-bci-bci-base-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:41 +0200 (CEST) Subject: SUSE-CU-2026:8061-1: Security update of bci/spack Message-ID: <20260805125241.E132FFDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8061-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.27 , bci/spack:latest Container Release : 25.27 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3330-1 Released: Tue Jul 28 11:35:51 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated - libssh-devel-0.9.8-150600.11.15.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:44 +0200 (CEST) Subject: SUSE-CU-2026:8063-1: Security update of bci/spack Message-ID: <20260805125244.23762FEE1@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8063-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.29 , bci/spack:latest Container Release : 25.29 Severity : moderate Type : security References : 1254340 1254341 1260998 1261002 1261003 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3429-1 Released: Thu Jul 30 13:18:04 2026 Summary: Security update for libarchive Type: security Severity: moderate References: 1254340,1254341,1260998,1261002,1261003 This update for libarchive fixes the following issues: - creating temporary files in the current working directory instead of the target directory can lead to file creation failures when the working directory is not writable (bsc#1254340). - file descriptor leak in the mtree parser cleanup path could lead to file descriptor exhaustion and denial of service (bsc#1261003). - NULL pointer dereference in archive_acl_from_text_w() could lead to a segmentation fault (bsc#1260998). - reading from an invalid index when buffer size is smaller than H_LEVEL_OFFSET can lead to an out-of-bounds buffer overrun (bsc#1254341). - incorrect pointer handling for RAR5 files declaring over 8192 filters can lead to excessive resource usage and denial of service (bsc#1261002). The following package changes have been done: - libarchive13-3.7.2-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:45 +0200 (CEST) Subject: SUSE-CU-2026:8064-1: Security update of bci/spack Message-ID: <20260805125245.7D1E8FDD1@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8064-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.30 , bci/spack:latest Container Release : 25.30 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl-3-devel-3.2.3-150700.5.40.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:48 +0200 (CEST) Subject: SUSE-CU-2026:8066-1: Security update of bci/spack Message-ID: <20260805125248.0A1C0FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8066-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.32 , bci/spack:latest Container Release : 25.32 Severity : moderate Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:50 +0200 (CEST) Subject: SUSE-CU-2026:8068-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260805125250.A185BFC32@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8068-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-62.3 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 62.3 Severity : important Type : security References : 1268853 1269622 CVE-2026-41991 CVE-2026-56109 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3270-1 Released: Mon Jul 27 13:01:22 2026 Summary: Security update for alsa Type: security Severity: moderate References: 1268853,CVE-2026-56109 This update for alsa fixes the following issue - CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). The following package changes have been done: - libasound2-1.2.10-150600.4.3.1 updated - libatopology2-1.2.10-150600.4.3.1 updated - gzip-1.10-150200.13.1 updated - alsa-1.2.10-150600.4.3.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:53 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:53 +0200 (CEST) Subject: SUSE-CU-2026:8070-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260805125253.057C0FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8070-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.2 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.2 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:54 +0200 (CEST) Subject: SUSE-CU-2026:8071-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260805125254.57288FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8071-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.4 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - openssl-3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:52:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:52:55 +0200 (CEST) Subject: SUSE-CU-2026:8072-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260805125255.A3785FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8072-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.7 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.7 Severity : important Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - gawk-4.2.1-150000.3.6.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 12:53:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 14:53:50 +0200 (CEST) Subject: SUSE-CU-2026:8073-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805125350.265B0FC32@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8073-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.9 , suse/kiosk/xorg-client:latest Container Release : 78.9 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-0180bc786e784f4f99302a008c5991e2d05f7fac404ce0fa2a07aaef564e6ef8-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:07 +0200 (CEST) Subject: SUSE-CU-2026:8073-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140307.E5E08FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8073-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.9 , suse/kiosk/xorg-client:latest Container Release : 78.9 Severity : important Type : security References : 1263366 1263367 1268131 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). The following package changes have been done: - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-0180bc786e784f4f99302a008c5991e2d05f7fac404ce0fa2a07aaef564e6ef8-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:09 +0200 (CEST) Subject: SUSE-CU-2026:8074-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140309.02E28FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8074-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.14 , suse/kiosk/xorg-client:latest Container Release : 78.14 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:suse-sle15-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated - container:registry.suse.com-bci-bci-micro-15.7-cbe2687a5ef4608cef82a7e320e3b24974f14b1fd2e641e107ef12eb62001a09-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:10 +0200 (CEST) Subject: SUSE-CU-2026:8075-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140310.14202FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8075-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.19 , suse/kiosk/xorg-client:latest Container Release : 78.19 Severity : important Type : security References : 1252306 1253043 1257463 1268290 1270393 CVE-2026-54411 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:11 +0200 (CEST) Subject: SUSE-CU-2026:8077-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140311.BDD98FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8077-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.23 , suse/kiosk/xorg-client:latest Container Release : 78.23 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libsystemd0-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:10 +0200 (CEST) Subject: SUSE-CU-2026:8076-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140310.E9425FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8076-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-78.21 , suse/kiosk/xorg-client:latest Container Release : 78.21 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:13 +0200 (CEST) Subject: SUSE-CU-2026:8079-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140313.4E9CAFEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8079-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.3 , suse/kiosk/xorg-client:latest Container Release : 79.3 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:14 +0200 (CEST) Subject: SUSE-CU-2026:8080-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140314.3CEB7FEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8080-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.5 , suse/kiosk/xorg-client:latest Container Release : 79.5 Severity : moderate Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:03:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:03:15 +0200 (CEST) Subject: SUSE-CU-2026:8081-1: Security update of suse/kiosk/xorg-client Message-ID: <20260805140315.1217BFF12@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8081-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.6 , suse/kiosk/xorg-client:latest Container Release : 79.6 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:03 +0200 (CEST) Subject: SUSE-CU-2026:8082-1: Security update of suse/kiosk/xorg Message-ID: <20260805140403.1353EFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8082-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.14 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.14 Severity : important Type : security References : 1263366 1263367 1268131 1268434 1269779 CVE-2026-11850 CVE-2026-12912 CVE-2026-36849 CVE-2026-40355 CVE-2026-40356 CVE-2026-4775 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2848-1 Released: Fri Jul 10 13:38:57 2026 Summary: Security update for krb5, krb5-mini Type: security Severity: important References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356 This update for krb5, krb5-mini fixes the following issues - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). - CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). - CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2853-1 Released: Fri Jul 10 19:54:25 2026 Summary: Security update for tiff Type: security Severity: important References: 1268434,1269779,CVE-2026-12912,CVE-2026-36849,CVE-2026-4775 This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: - CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog-compressed TIFF image (bsc#1269779). - CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: - Version 4.7.2: - Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. - Library changes: * New/improved functionalities:: + Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) - Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. - Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow The following package changes have been done: - libtiff6-4.7.2-150600.3.29.1 updated - krb5-1.20.1-150600.11.19.1 updated - container:suse-sle15-15.7-0180bc786e784f4f99302a008c5991e2d05f7fac404ce0fa2a07aaef564e6ef8-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:04 +0200 (CEST) Subject: SUSE-CU-2026:8083-1: Security update of suse/kiosk/xorg Message-ID: <20260805140404.49CAEFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8083-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.19 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.19 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - container:suse-sle15-15.7-755494b8968bbc3fe68f3f00f84189bd9f49f79b716c514f0bf00867903ffa21-0 updated - container:registry.suse.com-bci-bci-micro-15.7-cbe2687a5ef4608cef82a7e320e3b24974f14b1fd2e641e107ef12eb62001a09-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:05 +0200 (CEST) Subject: SUSE-CU-2026:8084-1: Security update of suse/kiosk/xorg Message-ID: <20260805140405.7EC7FFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8084-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.20 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.20 Severity : important Type : security References : 1269790 CVE-2026-11979 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3097-1 Released: Fri Jul 17 13:39:27 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - libxml2-2-2.12.10-150700.4.14.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:06 +0200 (CEST) Subject: SUSE-CU-2026:8085-1: Recommended update of suse/kiosk/xorg Message-ID: <20260805140407.0C3AEFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8085-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.21 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.21 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3106-1 Released: Fri Jul 17 16:02:05 2026 Summary: Recommended update for kmod Type: recommended Severity: moderate References: This update for kmod fixes the following issues: - Use in-kernel decompression if available (jsc#PED-16303): * libkmod: + Add a separate function to load the file contents when it's needed. When it's not needed on the path of loading modules via finit_module(), there is no need to mmap the file. + Extract 2 functions to handle finit_module vs init_modules differences, with a fallback from the former to the latter. + Don't only set the type as direct, but also keep track of the compression being used. + When creating the context, read /sys/kernel/compression to check. what's the compression type supported by the kernel. + Use kernel decompression when available + add fallback MODULE_INIT_COMPRESSED_FILE define The following package changes have been done: - libkmod2-29-150600.13.6.1 updated - kmod-29-150600.13.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:08 +0200 (CEST) Subject: SUSE-CU-2026:8086-1: Security update of suse/kiosk/xorg Message-ID: <20260805140408.20F75FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8086-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.26 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.26 Severity : important Type : security References : 1252306 1253043 1257463 1268290 1270393 CVE-2026-54411 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3141-1 Released: Tue Jul 21 09:04:39 2026 Summary: Recommended update for shadow Type: recommended Severity: important References: 1270393 This update for shadow fixes the following issues: - Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3163-1 Released: Tue Jul 21 16:50:54 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - login_defs-4.17.2-150600.17.21.1 updated - pam-1.3.0-150000.6.89.1 updated - libsubid5-4.17.2-150600.17.21.1 updated - shadow-4.17.2-150600.17.21.1 updated - container:suse-sle15-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated - container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:09 +0200 (CEST) Subject: SUSE-CU-2026:8087-1: Security update of suse/kiosk/xorg Message-ID: <20260805140409.2CF5FFEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8087-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.28 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.28 Severity : moderate Type : security References : 1262684 CVE-2026-41989 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3182-1 Released: Wed Jul 22 09:25:44 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). The following package changes have been done: - libgcrypt20-1.11.0-150700.5.10.1 updated - container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:11 +0200 (CEST) Subject: SUSE-CU-2026:8089-1: Security update of suse/kiosk/xorg Message-ID: <20260805140411.11188FF12@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8089-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.31 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.31 Severity : important Type : security References : 1268853 1269622 CVE-2026-41991 CVE-2026-56109 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3269-1 Released: Mon Jul 27 13:00:16 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue: - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3270-1 Released: Mon Jul 27 13:01:22 2026 Summary: Security update for alsa Type: security Severity: moderate References: 1268853,CVE-2026-56109 This update for alsa fixes the following issue - CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). The following package changes have been done: - libasound2-1.2.10-150600.4.3.1 updated - libatopology2-1.2.10-150600.4.3.1 updated - gzip-1.10-150200.13.1 updated - alsa-1.2.10-150600.4.3.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:10 +0200 (CEST) Subject: SUSE-CU-2026:8088-1: Security update of suse/kiosk/xorg Message-ID: <20260805140410.228EFFEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8088-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-82.30 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 82.30 Severity : moderate Type : security References : 1261400 1261982 1261983 1262305 1267644 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). The following package changes have been done: - libudev1-254.27-150600.4.71.2 updated - libsystemd0-254.27-150600.4.71.2 updated - systemd-254.27-150600.4.71.2 updated - udev-254.27-150600.4.71.2 updated - container:suse-sle15-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:13 +0200 (CEST) Subject: SUSE-CU-2026:8091-1: Security update of suse/kiosk/xorg Message-ID: <20260805140413.03EE1FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8091-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.2 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.2 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3341-1 Released: Tue Jul 28 12:09:19 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libglib-2_0-0-2.78.6-150600.4.38.1 updated - libgobject-2_0-0-2.78.6-150600.4.38.1 updated - libgmodule-2_0-0-2.78.6-150600.4.38.1 updated - libgio-2_0-0-2.78.6-150600.4.38.1 updated - glib2-tools-2.78.6-150600.4.38.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:14 +0200 (CEST) Subject: SUSE-CU-2026:8092-1: Security update of suse/kiosk/xorg Message-ID: <20260805140414.1E41FFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8092-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.4 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.4 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3444-1 Released: Fri Jul 31 22:04:31 2026 Summary: Security update for openssl-3 Type: security Severity: moderate References: 1271712 This update for openssl-3 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.2.3-150700.5.40.1 updated - container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:04:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:04:15 +0200 (CEST) Subject: SUSE-CU-2026:8093-1: Security update of suse/kiosk/xorg Message-ID: <20260805140415.46C7CFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8093-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.6 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.6 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-150600.3.23.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:27:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:27:39 +0200 (CEST) Subject: SUSE-CU-2026:8380-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260805142739.51762FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8380-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.93 , suse/sles/16.0/toolbox:latest Container Release : 1.93 Severity : moderate Type : recommended References : 1270439 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1191 Released: Thu Jul 9 14:39:23 2026 Summary: Recommended update for systemd Type: recommended Severity: moderate References: 1270439 This update for systemd fixes the following issues: Changes in systemd: - do not make mounting of debugfs optional yet. The following package changes have been done: - libsystemd0-257.13-160000.3.1 updated - libudev1-257.13-160000.3.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 14:27:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 16:27:40 +0200 (CEST) Subject: SUSE-CU-2026:8381-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805142740.0E6C9FDC9@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8381-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.94 , suse/sles/16.0/toolbox:latest Container Release : 1.94 Severity : moderate Type : security References : 1269489 CVE-2026-58055 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1213 Released: Fri Jul 10 15:13:53 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue - CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). The following package changes have been done: - libnghttp2-14-1.64.0-160000.4.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 18:24:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 20:24:12 +0200 (CEST) Subject: SUSE-IU-2026:6056-1: Recommended update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260805182412.326B9FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6056-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.145 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.145 Severity : moderate Type : recommended References : 1271645 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 655 Released: Wed Aug 5 15:41:00 2026 Summary: Recommended update for policycoreutils Type: recommended Severity: moderate References: 1271645 This update for policycoreutils fixes the following issues: - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) * can be dropped once 'policycoreutils/scripts/fixfiles: drop /tmp cleanup' is in the upstream release The following package changes have been done: - policycoreutils-3.5-slfo.1.1_2.1 updated - python3-policycoreutils-3.5-slfo.1.1_2.1 updated - policycoreutils-python-utils-3.5-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.162 updated From sle-container-updates at lists.suse.com Wed Aug 5 18:26:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 20:26:38 +0200 (CEST) Subject: SUSE-IU-2026:6057-1: Recommended update of suse/sl-micro/6.1/base-os-container Message-ID: <20260805182638.CE8A4FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6057-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.162 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.162 Severity : important Type : recommended References : 1261038 1268321 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 656 Released: Wed Aug 5 16:49:57 2026 Summary: Recommended update for libzypp Type: recommended Severity: important References: 1261038,1268321 This update for libzypp fixes the following issues: - Update to version 17.38.14: * zypp.conf: add solver.NoUpdateProvide (default: false) option (bsc#1261038) * Use HttpHeader class for defining host specific http headers (bsc#1268321) * Compile and link with -fPIE to build on sparc64 The following package changes have been done: - libzypp-17.38.14-slfo.1.1_1.1 updated - container:suse-toolbox-image-1.0.0-5.83 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:04:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:04:44 +0200 (CEST) Subject: SUSE-CU-2026:8386-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260805190444.9328BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8386-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.60 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.60 , suse/ltss/sle15.5/sle15:latest Container Release : 8.60 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3502-1 Released: Wed Aug 5 14:45:05 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.0.8-150500.5.72.1 updated - openssl-3-3.0.8-150500.5.72.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:09:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:09:09 +0200 (CEST) Subject: SUSE-CU-2026:8387-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260805190909.07641FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8387-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.8 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.8 Severity : critical Type : security References : 1272660 1272661 CVE-2026-44950 CVE-2026-59679 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3500-1 Released: Wed Aug 5 13:57:26 2026 Summary: Security update for libXfont2 Type: security Severity: critical References: 1272660,1272661,CVE-2026-44950,CVE-2026-59679 This update for libXfont2 fixes the following issues: - CVE-2026-44950: fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (bsc#1272661). - CVE-2026-59679: fs_read_glyphs() heap OOB read/write via encoding array index mismatch (bsc#1272660). The following package changes have been done: - libXfont2-2-2.0.3-150000.3.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:10:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:10:25 +0200 (CEST) Subject: SUSE-CU-2026:8388-1: Security update of suse/kiosk/xorg Message-ID: <20260805191025.347A8FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8388-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.7 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.7 Severity : critical Type : security References : 1272660 1272661 CVE-2026-44950 CVE-2026-59679 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3500-1 Released: Wed Aug 5 13:57:26 2026 Summary: Security update for libXfont2 Type: security Severity: critical References: 1272660,1272661,CVE-2026-44950,CVE-2026-59679 This update for libXfont2 fixes the following issues: - CVE-2026-44950: fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (bsc#1272661). - CVE-2026-59679: fs_read_glyphs() heap OOB read/write via encoding array index mismatch (bsc#1272660). The following package changes have been done: - libXfont2-2-2.0.3-150000.3.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:23 +0200 (CEST) Subject: SUSE-CU-2026:8381-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191823.11F3BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8381-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.94 , suse/sles/16.0/toolbox:latest Container Release : 1.94 Severity : moderate Type : security References : 1269489 CVE-2026-58055 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1213 Released: Fri Jul 10 15:13:53 2026 Summary: Security update for nghttp2 Type: security Severity: moderate References: 1269489,CVE-2026-58055 This update for nghttp2 fixes the following issue - CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). The following package changes have been done: - libnghttp2-14-1.64.0-160000.4.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:24 +0200 (CEST) Subject: SUSE-CU-2026:8389-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20260805191824.A7FFAFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8389-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.95 , suse/sles/16.0/toolbox:latest Container Release : 1.95 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1215 Released: Sat Jul 11 21:15:31 2026 Summary: Recommended update for vim Type: recommended Severity: moderate References: This update for vim fixes the following issues: - Updated to version 9.2.0725: * fixes issues The following package changes have been done: - vim-data-common-9.2.0725-160000.1.1 updated - vim-9.2.0725-160000.1.1 updated - xxd-9.2.0725-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:26 +0200 (CEST) Subject: SUSE-CU-2026:8390-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191826.6E7A1FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8390-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.96 , suse/sles/16.0/toolbox:latest Container Release : 1.96 Severity : important Type : security References : 1262719 1269790 CVE-2026-11979 CVE-2026-6732 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1220 Released: Mon Jul 13 09:51:58 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1262719,1269790,CVE-2026-11979,CVE-2026-6732 This update for libxml2 fixes the following issues - CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - libxml2-2-2.13.8-160000.5.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:28 +0200 (CEST) Subject: SUSE-CU-2026:8391-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191828.3CE22FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8391-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.97 , suse/sles/16.0/toolbox:latest Container Release : 1.97 Severity : moderate Type : security References : 1268290 CVE-2026-54411 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1224 Released: Mon Jul 13 15:54:55 2026 Summary: Security update for pam Type: security Severity: moderate References: 1268290,CVE-2026-54411 This update for pam fixes the following issue - CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext-password comparison (bsc#1268290). The following package changes have been done: - pam-1.7.1-160000.5.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:31 +0200 (CEST) Subject: SUSE-CU-2026:8393-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191831.71ABAFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8393-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.100 , suse/sles/16.0/toolbox:latest Container Release : 1.100 Severity : important Type : security References : 1259859 1269622 1271193 1271193 1271194 1271194 1271195 1271195 CVE-2026-23268 CVE-2026-41991 CVE-2026-59856 CVE-2026-59856 CVE-2026-59857 CVE-2026-59857 CVE-2026-59858 CVE-2026-59858 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 633 Released: Thu Apr 23 10:07:27 2026 Summary: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Type: security Severity: important References: 1259859,1271193,1271194,1271195,CVE-2026-23268,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes one security issue The following security issue was fixed: - CVE-2026-23268: apparmor: fix unprivileged local user can do privileged policy management (bsc#1259859). ----------------------------------------------------------------- Advisory ID: 1280 Released: Sat Jul 18 10:12:44 2026 Summary: Security update for gzip Type: security Severity: important References: 1269622,CVE-2026-41991 This update for gzip fixes the following issue - CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622). ----------------------------------------------------------------- Advisory ID: 1283 Released: Sat Jul 18 13:51:36 2026 Summary: Security update for vim Type: security Severity: important References: 1271193,1271194,1271195,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858 This update for vim fixes the following issues: Update to version 9.2.0780. Security issues fixed: - CVE-2026-59856: arbitrary code execution via PHP omni-completion due to improper escaping (bsc#1271194). - CVE-2026-59857: out-of-bounds write in SAL soundfolding due to improper bounds check (bsc#1271195). - CVE-2026-59858: arbitrary code execution via C omni-completion due to improper escaping (bsc#1271193). Other updates and bugfixes: - Version 9.2.0780 changelog: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * tests: test_popupwin fails with zsh because of the prompt (9.2.0757). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * tests: style issue in test_plugin_netrw (9.2.0763). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). The following package changes have been done: - gzip-1.13-160000.3.1 updated - vim-data-common-9.2.0780-160000.1.1 updated - vim-9.2.0780-160000.1.1 updated - xxd-9.2.0780-160000.1.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:33 +0200 (CEST) Subject: SUSE-CU-2026:8394-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191833.70CC9FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8394-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.101 , suse/sles/16.0/toolbox:latest Container Release : 1.101 Severity : low Type : security References : 1269279 CVE-2026-57062 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1288 Released: Mon Jul 20 05:14:32 2026 Summary: Security update for gpg2 Type: security Severity: low References: 1269279,CVE-2026-57062 This update for gpg2 fixes the following issue: - CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279). The following package changes have been done: - gpg2-2.5.5-160000.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:18:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:18:35 +0200 (CEST) Subject: SUSE-CU-2026:8395-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260805191835.085CBFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8395-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.104 , suse/sles/16.0/toolbox:latest Container Release : 1.104 Severity : important Type : security References : 1254243 1261038 1261038 1262094 1262684 1266304 1266361 1268321 1268321 1268349 1270008 1270009 1270010 1270016 1270018 1270021 1271351 1271352 1271354 1271372 1271386 CVE-2025-15649 CVE-2026-12087 CVE-2026-13221 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-41989 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 656 Released: Wed Apr 29 14:59:08 2026 Summary: Recommended update for crmsh Type: recommended Severity: important References: 1254243,1261038,1262094,1268321 This update for crmsh fixes the following issues: - Update to version 5.0.0+20260420.f7e8ecad: * Dev: utils: Improve check_port_open to concurrently try all addresses (bsc#1262094) * Dev: qdevice: Remove unused codes * Fix: bootstrap: On join node, retrieve qdevice certification files before starting qdevice (bsc#1254243) ----------------------------------------------------------------- Advisory ID: 1294 Released: Mon Jul 20 11:26:51 2026 Summary: Security update for libgcrypt Type: security Severity: moderate References: 1262684,CVE-2026-41989 This update for libgcrypt fixes the following issue - CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). ----------------------------------------------------------------- Advisory ID: 1303 Released: Mon Jul 20 15:44:04 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free vulnerability within the do_getline_redir() routine could lead to a program crash (bsc#1271351). - CVE-2026-40468: use-after-free vulnerability in gawk's 'io.c' file could permit heap metadata manipulation and host memory exhaustion (bsc#1271352). - CVE-2026-40553: buffer overflow in the ftype() routine of the readdir extension could trigger a program crash (bsc#1271354). ----------------------------------------------------------------- Advisory ID: 1320 Released: Wed Jul 22 10:35:52 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). ----------------------------------------------------------------- Advisory ID: 1321 Released: Wed Jul 22 10:44:23 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1266361,1268349,1271372,1271386,CVE-2025-15649,CVE-2026-12087,CVE-2026-13221,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date (bsc#1266361). - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). - CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching (bsc#1271386). ----------------------------------------------------------------- Advisory ID: 1314 Released: Wed Jul 22 10:53:42 2026 Summary: Recommended update for libzypp Type: recommended Severity: important References: 1261038,1268321 This update for libzypp fixes the following issues: Changes in libzypp: Update to version 17.38.14 (35): - zypp.conf: add solver.NoUpdateProvide (default: false) option. In general, packages that obsolete another package are treated as update candidates for the obsoleted package. However, SUSE-specific update rules prefer candidates that also explicitly 'provide' the obsoleted package. Sometimes it is necessary or helpful to disable this rule. (may help in bsc#1261038) - Use HttpHeader class for defining host specific http headers (bsc#1268321) - Compile and link with -fPIE to build on sparc64 (fixes #742) The following package changes have been done: - gawk-5.3.2-160000.3.1 updated - libgcrypt20-1.12.1-160000.3.1 updated - libglib-2_0-0-2.84.4-160000.4.1 updated - libgmodule-2_0-0-2.84.4-160000.4.1 updated - libzypp-17.38.14-160000.1.1 updated - perl-base-5.42.0-160000.3.1 updated - perl-5.42.0-160000.3.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:17 +0200 (CEST) Subject: SUSE-CU-2026:8440-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192417.9F8C4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8440-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.2 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.2 Severity : moderate Type : security References : 1261400 1261982 1261983 1267647 CVE-2026-40226 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2809-1 Released: Thu Jul 9 08:08:18 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1267647,CVE-2026-40226 This update for systemd fixes the following issue Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Import commit 37508f8ec1 (bsc#1267647). - Import commit c7530fbea3 (bsc#1261982 bsc#1261983). - Import commit 5c4ed461a7 (bsc#1261982). - Import commit 4b963df038 (bsc#1261983). The following package changes have been done: - systemd-249.17-150400.8.64.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:18 +0200 (CEST) Subject: SUSE-CU-2026:8441-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192418.9FAB0FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8441-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.5 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.5 Severity : important Type : security References : 1241219 1263366 1263367 1268131 CVE-2025-3576 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3729-1 Released: Wed Oct 22 15:19:26 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2449-1 Released: Thu Jun 18 14:52:09 2026 Summary: Security update for krb5 Type: security Severity: moderate References: 1263366,1263367,CVE-2026-40355,CVE-2026-40356 This update for krb5 fixes the following issues ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2954-1 Released: Tue Jul 14 11:57:20 2026 Summary: Security update for krb5 Type: security Severity: important References: 1268131,CVE-2026-11850 This update for krb5 fixes the following issue - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). The following package changes have been done: - krb5-1.19.2-150400.3.24.1 updated - container:sles15-ltss-image-15.4.0-6.31 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:19 +0200 (CEST) Subject: SUSE-CU-2026:8442-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192419.9FB95FDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8442-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.8 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.8 Severity : important Type : security References : 1263656 1263658 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3029-1 Released: Wed Jul 15 11:52:19 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3043-1 Released: Wed Jul 15 13:51:04 2026 Summary: Security update for curl Type: security Severity: important References: 1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - glibc-2.31-150300.104.1 updated - libcurl4-8.14.1-150400.5.86.1 updated - curl-8.14.1-150400.5.86.1 updated - container:sles15-ltss-image-15.4.0-6.33 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:20 +0200 (CEST) Subject: SUSE-CU-2026:8443-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192420.A5F13FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8443-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.9 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.9 Severity : important Type : security References : 1269790 CVE-2026-11979 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3095-1 Released: Fri Jul 17 13:38:15 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). The following package changes have been done: - python3-libxml2-2.9.14-150400.5.58.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:21 +0200 (CEST) Subject: SUSE-CU-2026:8444-1: Recommended update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192421.D7260FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8444-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.11 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.11 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.9.14-150400.5.58.1 updated - container:sles15-ltss-image-15.4.0-6.35 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:25 +0200 (CEST) Subject: SUSE-CU-2026:8448-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192425.9E57BFEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8448-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.16 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.16 Severity : low Type : security References : 1259804 CVE-2026-27448 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3424-1 Released: Thu Jul 30 13:07:33 2026 Summary: Security update for python3-pyOpenSSL Type: security Severity: low References: 1259804,CVE-2026-27448 This update for python3-pyOpenSSL fixes the following issue: - CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being cancelled and allows for possible security measure bypassing (bsc#1259804). The following package changes have been done: - python3-pyOpenSSL-21.0.0-150400.22.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:22 +0200 (CEST) Subject: SUSE-CU-2026:8445-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192422.D47F6FE13@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8445-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.13 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.13 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3235-1 Released: Fri Jul 24 14:41:42 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libgmodule-2_0-0-2.70.5-150400.3.37.1 updated - libgobject-2_0-0-2.70.5-150400.3.37.1 updated - libgio-2_0-0-2.70.5-150400.3.37.1 updated - glib2-tools-2.70.5-150400.3.37.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:26 +0200 (CEST) Subject: SUSE-CU-2026:8449-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192426.C4A0AFEE1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8449-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.17 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.17 Severity : moderate Type : security References : 1271351 1271352 1271354 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). The following package changes have been done: - gawk-4.2.1-150000.3.6.1 updated From sle-container-updates at lists.suse.com Wed Aug 5 19:24:27 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 5 Aug 2026 21:24:27 +0200 (CEST) Subject: SUSE-CU-2026:8450-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260805192427.E6DEFFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8450-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.18 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.18 Severity : important Type : security References : 1246974 1249375 1258045 1258049 1258054 1258080 1258081 1259377 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2025-8114 CVE-2025-8277 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3788-1 Released: Fri Oct 24 15:28:50 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1565-1 Released: Thu Apr 23 09:08:29 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,1259377,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). - CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150400.3.20.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libssh4-0.9.8-150400.3.20.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:42:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:42:26 +0200 (CEST) Subject: SUSE-CU-2026:8450-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260806074226.A08F0FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8450-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.18 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.18 Severity : important Type : security References : 1246974 1249375 1258045 1258049 1258054 1258080 1258081 1259377 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2025-8114 CVE-2025-8277 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3788-1 Released: Fri Oct 24 15:28:50 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1565-1 Released: Thu Apr 23 09:08:29 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,1259377,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). - CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150400.3.20.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libssh4-0.9.8-150400.3.20.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:43:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:43:59 +0200 (CEST) Subject: SUSE-CU-2026:8451-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260806074359.9A52BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8451-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.6 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.6 Severity : important Type : security References : 1241219 1263366 1263367 1268131 CVE-2025-3576 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3729-1 Released: Wed Oct 22 15:19:26 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2449-1 Released: Thu Jun 18 14:52:09 2026 Summary: Security update for krb5 Type: security Severity: moderate References: 1263366,1263367,CVE-2026-40355,CVE-2026-40356 This update for krb5 fixes the following issues ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2954-1 Released: Tue Jul 14 11:57:20 2026 Summary: Security update for krb5 Type: security Severity: important References: 1268131,CVE-2026-11850 This update for krb5 fixes the following issue - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). The following package changes have been done: - krb5-1.19.2-150400.3.24.1 updated - container:sles15-ltss-image-15.4.0-6.31 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:44:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:44:00 +0200 (CEST) Subject: SUSE-CU-2026:8452-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260806074400.E6877FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8452-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.9 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.9 Severity : important Type : security References : 1263656 1263658 1268402 1268407 1268409 1268413 1268415 1268416 1268417 1268420 1268422 1268427 CVE-2026-10536 CVE-2026-12064 CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3029-1 Released: Wed Jul 15 11:52:19 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3043-1 Released: Wed Jul 15 13:51:04 2026 Summary: Security update for curl Type: security Severity: important References: 1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547 This update for curl fixes the following issues - CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). - CVE-2026-8458: wrong reuse for different services (bsc#1268407). - CVE-2026-8924: traling dot domain super cookie (bsc#1268409). - CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). - CVE-2026-9079: stale proxy password leak (bsc#1268415). - CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). - CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). - CVE-2026-9547: SSH improper host validation (bsc#1268420). - CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). - CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). The following package changes have been done: - glibc-2.31-150300.104.1 updated - libcurl4-8.14.1-150400.5.86.1 updated - curl-8.14.1-150400.5.86.1 updated - container:sles15-ltss-image-15.4.0-6.33 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:44:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:44:02 +0200 (CEST) Subject: SUSE-CU-2026:8453-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260806074402.1C71FFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8453-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.13 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.13 Severity : important Type : security References : 1247850 1249076 1250553 1252306 1253043 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257463 1257593 1257594 1257595 1269790 CVE-2025-10911 CVE-2025-8732 CVE-2025-9714 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11979 CVE-2026-1757 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4116-1 Released: Mon Nov 17 08:26:11 2025 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1249076,CVE-2025-8732,CVE-2025-9714 This update for libxml2 fixes the following issues: - CVE-2025-9714: Fixed inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c (bsc#1249076) - CVE-2025-8732: Fixed infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247850) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:606-1 Released: Tue Feb 24 12:19:29 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3095-1 Released: Fri Jul 17 13:38:15 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.9.14-150400.5.58.1 updated - container:sles15-ltss-image-15.4.0-6.35 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:44:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:44:03 +0200 (CEST) Subject: SUSE-CU-2026:8454-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260806074403.21F02FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8454-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.17 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.17 Severity : important Type : security References : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3235-1 Released: Fri Jul 24 14:41:42 2026 Summary: Security update for glib2 Type: security Severity: important References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016 This update for glib2 fixes the following issues: - CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read (bsc#1270009). - CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010). - CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of- bounds read (bsc#1270016). - CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds read (bsc#1270018). - CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of- bounds access (bsc#1270021). - CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008). The following package changes have been done: - libglib-2_0-0-2.70.5-150400.3.37.1 updated - container:sles15-ltss-image-15.4.0-6.37 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:44:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:44:05 +0200 (CEST) Subject: SUSE-CU-2026:8456-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260806074405.2FB6CFE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8456-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.21 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.21 Severity : important Type : security References : 1246974 1249375 1258045 1258049 1258054 1258080 1258081 1259377 1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2025-8114 CVE-2025-8277 CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3788-1 Released: Fri Oct 24 15:28:50 2025 Summary: Security update for libssh Type: security Severity: moderate References: 1246974,1249375,CVE-2025-8114,CVE-2025-8277 This update for libssh fixes the following issues: - CVE-2025-8277: memory exhaustion leading to client-side DoS due to improper memory management when KEX process is repeated with incorrect guesses (bsc#1249375). - CVE-2025-8114: NULL pointer dereference when an allocation error happens during the calculation of the KEX session ID (bsc#1246974). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:1565-1 Released: Thu Apr 23 09:08:29 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1258045,1258049,1258054,1258080,1258081,1259377,CVE-2026-0964,CVE-2026-0965,CVE-2026-0966,CVE-2026-0967,CVE-2026-0968,CVE-2026-3731 This update for libssh fixes the following issues: - CVE-2026-0964: improper sanitation of paths received from SCP servers can cause path traversal (bsc#1258049). - CVE-2026-0965: possible denial of service when parsing unexpected configuration files (bsc#1258045). - CVE-2026-0966: buffer underflow in ssh_get_hexa() on invalid input (bsc#1258054). - CVE-2026-0967: specially crafted patterns could cause denial of service (bsc#1258081). - CVE-2026-0968: malformed SFTP message can lead to out of bound read (bsc#1258080). - CVE-2026-3731: denial of service via out-of-bounds read in SFTP extension name handler (bsc#1259377). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3463-1 Released: Mon Aug 3 14:18:06 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues: - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - libssh-config-0.9.8-150400.3.20.1 updated - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - libssh4-0.9.8-150400.3.20.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:45:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:45:44 +0200 (CEST) Subject: SUSE-CU-2026:8457-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260806074544.73345FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8457-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.3 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.3 Severity : important Type : security References : 1241219 1263366 1263367 1268131 CVE-2025-3576 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3729-1 Released: Wed Oct 22 15:19:26 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2449-1 Released: Thu Jun 18 14:52:09 2026 Summary: Security update for krb5 Type: security Severity: moderate References: 1263366,1263367,CVE-2026-40355,CVE-2026-40356 This update for krb5 fixes the following issues ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2954-1 Released: Tue Jul 14 11:57:20 2026 Summary: Security update for krb5 Type: security Severity: important References: 1268131,CVE-2026-11850 This update for krb5 fixes the following issue - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). The following package changes have been done: - krb5-1.19.2-150400.3.24.1 updated - container:sles15-ltss-image-15.4.0-6.31 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:45:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:45:46 +0200 (CEST) Subject: SUSE-CU-2026:8459-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260806074546.4860DFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8459-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.8 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.8 Severity : important Type : security References : 1247850 1249076 1250553 1252306 1253043 1256804 1256805 1256807 1256808 1256809 1256810 1256811 1256812 1257463 1257593 1257594 1257595 1269790 CVE-2025-10911 CVE-2025-8732 CVE-2025-9714 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992 CVE-2026-11979 CVE-2026-1757 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:4116-1 Released: Mon Nov 17 08:26:11 2025 Summary: Security update for libxml2 Type: security Severity: moderate References: 1247850,1249076,CVE-2025-8732,CVE-2025-9714 This update for libxml2 fixes the following issues: - CVE-2025-9714: Fixed inifinite recursion at exsltDynMapFunction function in libexslt/dynamic.c (bsc#1249076) - CVE-2025-8732: Fixed infinite recursion in catalog parsing functions when processing malformed SGML catalog files (bsc#1247850) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:606-1 Released: Tue Feb 24 12:19:29 2026 Summary: Security update for libxml2 Type: security Severity: moderate References: 1250553,1256804,1256805,1256807,1256808,1256809,1256810,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2026-0989,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757 This update for libxml2 fixes the following issues: - CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811) - CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812) - CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595) - CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553) - CVE-2026-0989: Fixe a call stack exhaustion leading to application crash due to RelaxNG parser not limiting the recursion depth. (bsc#1256805, bsc#1256810) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3095-1 Released: Fri Jul 17 13:38:15 2026 Summary: Security update for libxml2 Type: security Severity: important References: 1269790,CVE-2026-11979 This update for libxml2 fixes the following issue - CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libxml2-2-2.9.14-150400.5.58.1 updated - container:sles15-ltss-image-15.4.0-6.35 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:45:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:45:45 +0200 (CEST) Subject: SUSE-CU-2026:8458-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260806074545.5C44BFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8458-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.5 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.5 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3029-1 Released: Wed Jul 15 11:52:19 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.31-150300.104.1 updated - container:sles15-ltss-image-15.4.0-6.33 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:45:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:45:48 +0200 (CEST) Subject: SUSE-CU-2026:8462-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260806074548.B528FFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8462-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.13 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.13 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:47:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:47:33 +0200 (CEST) Subject: SUSE-CU-2026:8463-1: Security update of suse/manager/4.3/proxy-ssh Message-ID: <20260806074733.695EDFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8463-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.4 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.4 Severity : important Type : security References : 1241219 1263366 1263367 1268131 CVE-2025-3576 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3729-1 Released: Wed Oct 22 15:19:26 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2449-1 Released: Thu Jun 18 14:52:09 2026 Summary: Security update for krb5 Type: security Severity: moderate References: 1263366,1263367,CVE-2026-40355,CVE-2026-40356 This update for krb5 fixes the following issues ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2954-1 Released: Tue Jul 14 11:57:20 2026 Summary: Security update for krb5 Type: security Severity: important References: 1268131,CVE-2026-11850 This update for krb5 fixes the following issue - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). The following package changes have been done: - krb5-1.19.2-150400.3.24.1 updated - container:sles15-ltss-image-15.4.0-6.31 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:47:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:47:34 +0200 (CEST) Subject: SUSE-CU-2026:8464-1: Security update of suse/manager/4.3/proxy-ssh Message-ID: <20260806074734.5F376FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8464-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.6 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.6 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3029-1 Released: Wed Jul 15 11:52:19 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.31-150300.104.1 updated - container:sles15-ltss-image-15.4.0-6.33 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:47:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:47:35 +0200 (CEST) Subject: SUSE-CU-2026:8465-1: Recommended update of suse/manager/4.3/proxy-ssh Message-ID: <20260806074735.5726BFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8465-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.8 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.8 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - container:sles15-ltss-image-15.4.0-6.35 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:47:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:47:37 +0200 (CEST) Subject: SUSE-CU-2026:8468-1: Security update of suse/manager/4.3/proxy-ssh Message-ID: <20260806074737.B57DCFDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-ssh ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8468-1 Container Tags : suse/manager/4.3/proxy-ssh:4.3.19 , suse/manager/4.3/proxy-ssh:4.3.19.9.72.13 , suse/manager/4.3/proxy-ssh:latest Container Release : 9.72.13 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-ssh was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:16 +0200 (CEST) Subject: SUSE-CU-2026:8470-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074916.C493FFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8470-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.4 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.4 Severity : important Type : security References : 1241219 1263366 1263367 1268131 CVE-2025-3576 CVE-2026-11850 CVE-2026-40355 CVE-2026-40356 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2025:3729-1 Released: Wed Oct 22 15:19:26 2025 Summary: Security update for krb5 Type: security Severity: moderate References: 1241219,CVE-2025-3576 This update for krb5 fixes the following issues: - CVE-2025-3576: weakness in the MD5 checksum design allows for spoofing of GSSAPI-protected messages that are using RC4-HMAC-MD5 (bsc#1241219). Krb5 as very old protocol supported quite a number of ciphers that are not longer up to current cryptographic standards. To avoid problems with those, SUSE has by default now disabled those alorithms. The following algorithms have been removed from valid krb5 enctypes: - des3-cbc-sha1 - arcfour-hmac-md5 To reenable those algorithms, you can use allow options in krb5.conf: [libdefaults] allow_des3 = true allow_rc4 = true to reenable them. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2449-1 Released: Thu Jun 18 14:52:09 2026 Summary: Security update for krb5 Type: security Severity: moderate References: 1263366,1263367,CVE-2026-40355,CVE-2026-40356 This update for krb5 fixes the following issues ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2954-1 Released: Tue Jul 14 11:57:20 2026 Summary: Security update for krb5 Type: security Severity: important References: 1268131,CVE-2026-11850 This update for krb5 fixes the following issue - CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131). The following package changes have been done: - krb5-1.19.2-150400.3.24.1 updated - container:sles15-ltss-image-15.4.0-6.31 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:15 +0200 (CEST) Subject: SUSE-CU-2026:8469-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074915.DAB7EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8469-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.2 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.2 Severity : moderate Type : security References : 1254867 1270365 CVE-2025-66471 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:2854-1 Released: Fri Jul 10 19:58:37 2026 Summary: Security update for python-urllib3 Type: security Severity: moderate References: 1254867,1270365,CVE-2025-66471 This update for python-urllib3 fixes the following issue - egression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365). The following package changes have been done: - python3-urllib3-1.25.10-150300.4.30.1 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:17 +0200 (CEST) Subject: SUSE-CU-2026:8471-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074917.A96EDFDD1@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8471-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.6 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.6 Severity : moderate Type : security References : 1263656 1263658 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3029-1 Released: Wed Jul 15 11:52:19 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). The following package changes have been done: - glibc-2.31-150300.104.1 updated - container:sles15-ltss-image-15.4.0-6.33 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:18 +0200 (CEST) Subject: SUSE-CU-2026:8472-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074918.8E768FDEC@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8472-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.7 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.7 Severity : moderate Type : security References : 1265413 CVE-2026-45409 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3100-1 Released: Fri Jul 17 13:41:45 2026 Summary: Security update for python-idna Type: security Severity: moderate References: 1265413,CVE-2026-45409 This update for python-idna fixes the following issue - CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). The following package changes have been done: - python3-idna-2.6-150000.3.9.1 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:19 +0200 (CEST) Subject: SUSE-CU-2026:8473-1: Recommended update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074919.79149FE0D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8473-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.9 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.9 Severity : moderate Type : recommended References : 1252306 1253043 1257463 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time The following package changes have been done: - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - container:sles15-ltss-image-15.4.0-6.35 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:22 +0200 (CEST) Subject: SUSE-CU-2026:8477-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074922.9D3C2FEC4@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8477-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.14 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.14 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Thu Aug 6 07:49:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 6 Aug 2026 09:49:21 +0200 (CEST) Subject: SUSE-CU-2026:8476-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260806074921.AE7DBFE13@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8476-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.12 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.12 Severity : low Type : security References : 1259804 CVE-2026-27448 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3424-1 Released: Thu Jul 30 13:07:33 2026 Summary: Security update for python3-pyOpenSSL Type: security Severity: low References: 1259804,CVE-2026-27448 This update for python3-pyOpenSSL fixes the following issue: - CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being cancelled and allows for possible security measure bypassing (bsc#1259804). The following package changes have been done: - python3-pyOpenSSL-21.0.0-150400.22.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 07:10:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 09:10:11 +0200 (CEST) Subject: SUSE-IU-2026:6072-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260807071011.A19DEFD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6072-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.220 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.220 Severity : critical Type : security References : 1212854 1213265 1213809 1217377 1218326 1219142 1219289 1219348 1219796 1220374 1220810 1222458 1228926 1229898 1232063 1232227 1236321 1236390 1236392 1253260 1254094 1255285 1257007 1257153 1257244 1268144 1268145 1268275 CVE-2026-41579 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 827 Released: Mon Aug 3 09:15:23 2026 Summary: Security update for runc Type: security Severity: low References: 1268275,CVE-2026-41579 This update for runc fixes the following issues: - CVE-2026-41579: runc allows a malicious image with a /dev symlink to trigger limited host filesystem integrity violations (bsc#1268275). Changes for runc: - update to 1.3.6: * Various integration test improvements. (#5222, #5237, #5226, #5229, #5239, #5249, #5269, #5287, #5295, #5304) * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable) to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes applies masks to per-CPU sysfs directories which get expensive quickly). - update to 1.3.5 * Recursive atime-related mount flags (rrelatime et al.) are now applied properly. (#5115, #5098) * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when running runc create and has thus been reverted. (#5158, #5153, #5151, #4645, #4757) * Updated builds to Go 1.25, libseccomp v2.6.0. (#5111, #5053) * Minor signing keyring updates. (#5146, #5139, #5144, #5148) ----------------------------------------------------------------- Advisory ID: 832 Released: Thu Aug 6 10:40:43 2026 Summary: Security update for multipath-tools Type: security Severity: critical References: 1212854,1213265,1213809,1217377,1218326,1219142,1219289,1219348,1219796,1220374,1220810,1222458,1228926,1229898,1232063,1232227,1236321,1236390,1236392,1253260,1254094,1255285,1257007,1257153,1257244,1268144,1268145 This update for multipath-tools fixes the following issues: Update to version 0.9.8+292+suse.c0523c1. Security issues fixed: - kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image(bsc#1268145). - kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). Other updates and bugfixes: - [Build 32.2] System with multipath fails to boot during first boot during the installation (bsc#1232063). - [Build 50.1] multipath btrfs i/o error on both Leap 15.6 and SLES 15 SP6 (bsc#1219289). - Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 >= 0` message showing up in syslog (bsc#1255285). - Version 0.9.8+266+suse.53479977 (bsc#1257007): * kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153) * multipathd: print path offline message even without a checker (bsc#1254094) * Fix command descriptions in the multipathd man page. * Fix ISO C23 compatibility issue causing errors with new compilers. * Fix memory leak caused by not joining the 'init unwinder' thread. * Fix memory leaks in kpartx. * Print the warning 'setting scsi timeouts is unsupported for protocol' only once per protocol. * Make sure multipath-tools is compiled with the compiler flag `-fno-strict-aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285) - Version 0.9.8+247+suse.863ae86f: * Log offline path state if 'log_checker_err always' is set - Version 0.9.8+246+suse.fb81edd2: * CI: GitHub workflow updates. No code changes. - Version 0.9.8+166+suse.95399ce1: - Backported fixes from upstream 0.9.9 ... 0.10.5 (bsc#1253260) * Updates to the built-in hardware table: - add some NVMe storage array (VASTData, Infinidat, HITACHI VSP) - add QSAN - add EqualLogic PS - Add Quantum devices - Enable ALUA for AStor/NeoSapphire - Update NFINIDAT/InfiniBox config - Fix product blacklist of S/390 devices - Add Seagate Lyve - Add HITACHI VSP One SDS Block - Add SCST (SCSI Target Subsystem for Linux) - Huawei storage arrays - XSG1 vendors * Avoid a possible system hang during shutdown with queueing multipath maps. * Failed paths should be checked every `polling_interval`. In certain cases, this wouldn't happen, because the check interval wasn't reset by multipathd. * It could happen that multipathd would accidentally release a SCSI persistent reservation held by another node. Fix it. * After manually failing some paths and then reinstating them, sometimes the reinstated paths were immediately failed again by multipathd. * Fixed the problem that, if there were multiple maps with deferred failback (`failback` value > 0 in `multipath.conf`), some maps might fail back later than configured. * Fixed a problem in the marginal path detection algorithm that could cause the io error check for a recently failed path to be delayed. * Fixed a minor bug in the config file parser * Fixed minor issues detected by coverity. - Version 0.9.8+111+suse.b7ee850: - Backported bug fixes from upstream 0.9.9 - 0.10.2 * Fixed old mpathpersist bug leading to the error message 'configured reservation key doesn't match: 0x0' when `reservation_key` was configured in the multipaths section of `multipath.conf`. (bsc#1228926, gh#opensvc/multipath-tools#92) * Fixed bug that caused queueing to be always disabled if flushing a map failed (bug introduced in 0.9.8). (bsc#1229898) * Fixed output of `multipath -t` and `multipath -T` for the options `force_sync` and `retrigger_tries`. (bsc#1229898, gh#opensvc/multipath-tools#88) * libmultipath: don't print error message if WATCHDOG_USEC is 0 (bsc#1232227) * Fix map failure count for no_path_retry > 0 (bsc#1229898) * Fix reboot hang if uevent is processed for suspended device (bsc#1232063) * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL (bsc#1229898) * Fixed a memory leak in the nvme foreign library. (bsc#1229898, bsc#1236390) * Fix multipathd crash because of invalid path group index value, for example if an invalid path device was removed from a map. (gh#opensvc/multipath-tools#105, bsc#1236392) * Fix the problem that `group_by_tpg` might be disabled if one or more paths were offline during initial configuration (bsc#1236392) * Make sure udev and systemd notice changes in multipath path state when devices are added to or removed from multipath maps (bsc#1236321) - Version 0.9.8+88+suse.d504d83: * Revert 'libmultipath: fix max_sectors_kb on adding path' (bsc#1222458) - Update to version 0.9.8+87+suse.f72b9f3: * fix misspelled DM_UDEV_DISABLE_OTHER_RULES_FLAG in udev rules (bsc#1220810) - Remove libmpathpersist-example-old.c, which has been obsolete since multipath-tools 0.8.6. - Version 0.9.8+83+suse.bcae610 (bsc#1220374): * multipath-tools: added NEWS.md - Version 0.9.8~1+82+suse.dcd98a3: * Adapt package version such that it shows as a 0.9.8 prerelease * Add missing udev rules file - Version 0.9.7+148+suse.9780ae0: * 11-dm-mpath.rules: Fix quoting mistake (bsc#1219142) - Version 0.9.7+148+suse.7d9953e.obscpio * This is a multipath-tools 0.9.8 pre-release * fix fast_io_fail for Infinibox (bsc#1219348) * Fix activation of LVM volume groups during coldplug (bsc#1219142) - Version 0.9.7+140+suse.2d78457: * Socket activation via multipathd.socket has been disabled by default because it has undesirable side effects on systems without multipath. Users with multipath hardware should enable multipathd.service * The restorequeueing CLI command now only enables queueing if disablequeueing had been sent before * Avoid multipathd hang during map flush * multipathd now tracks the queueing mode of maps in its internal features string * Improve error messages in 'multipathd -k' * Fix segfault in autoresize code (bsc#1219289) * Fix missing map reloads (bsc#1219796) * Documentation fixes, spelling fixes, minor code fixes - Version 0.9.7+93+suse.e2f2272: * fix ANA prioritizer enablement logic (bsc#1218326) * avoid setting queue_if_no_path on multipath maps for which the no_path_retry timeout has expired * the interactive commands 'restorequeueing map X' and 'restorequeing maps' now only affect maps that had queueing manually disabled using 'disablequeuing maps' or 'disablequeuing map X' beforehand * Spelling fixes - Version 0.9.7+76+suse.5f857af: * Update to upstream 0.9.7 (jsc#PED-6464) * added max_retries config option to limit SCSI retries * added auto_resize config option to enable resizing multipath maps automatically * fixed memory and error handling for code using aio (marginal path code, directio path checker) * dropped modules-load.d/multipath.conf; replaced by a dependency on modprobe at dm-multipath.service (systemd >= 245: SLE15-SP3 and later only) and a softdep on sd_mod for the SCSI device handlers (bsc#1217377) * On SLE/Leap suse-module-tools doesn't ship a scsi_mod->sd_mod softdep yet. Add it here, too. It will be overridden by s-m-t when it's added there. * drop usr_prefix= setting in SLE build recipes (set to /usr by upstream automatically) - Version 0.9.6+115+suse.07776fb * multipathd: Added support to handle FPIN-Li events for FC-NVMe - Update to version 0.9.6+110+suse.5dfdf35: * The options 'bindings_file', 'prkeys_file', and 'wwids_file', which have been deprecated since multipath-tools 0.8.8, aren't supported any more. The paths to these files are now hard-coded to 'bindings', 'prkeys' and 'wwids' under /etc/multipath. * Strictly avoid assigning map aliases that are already taken (bsc#1213265) * Improve handling of user-friendly names * avoid 'multipath -d' (dry-run) changing SCSI timeouts in sysfs (bsc#1213809) - `spec` file: * adapt prefix values to upstream changes * fix compilation flags for `make check` * pass EXTRAVERSION to build (bsc#1212854) The following package changes have been done: - kpartx-0.9.8+292+suse.c0523c1-1.1 updated - runc-1.3.6-1.1 updated - libmpath0-0.9.8+292+suse.c0523c1-1.1 updated - multipath-tools-0.9.8+292+suse.c0523c1-1.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 07:24:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 09:24:49 +0200 (CEST) Subject: SUSE-IU-2026:6074-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260807072449.2B685FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6074-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.146 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.146 Severity : moderate Type : security References : 1260078 1260082 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-4437 CVE-2026-4438 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 659 Released: Thu Aug 6 13:30:24 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1260078,1260082,1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-4437,CVE-2026-4438,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.61 updated - libssh-config-0.10.6-slfo.1.1_6.1 updated - libssh4-0.10.6-slfo.1.1_6.1 updated - container:SL-Micro-base-container-2.2.1-5.163 updated From sle-container-updates at lists.suse.com Fri Aug 7 07:27:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 09:27:26 +0200 (CEST) Subject: SUSE-IU-2026:6075-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260807072726.894F7FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6075-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.163 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.163 Severity : moderate Type : security References : 1260078 1260082 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-4437 CVE-2026-4438 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 659 Released: Thu Aug 6 13:30:24 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1260078,1260082,1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-4437,CVE-2026-4438,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.61 updated - libssh-config-0.10.6-slfo.1.1_6.1 updated - libssh4-0.10.6-slfo.1.1_6.1 updated - container:suse-toolbox-image-1.0.0-5.84 updated From sle-container-updates at lists.suse.com Fri Aug 7 07:30:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 09:30:16 +0200 (CEST) Subject: SUSE-IU-2026:6076-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260807073016.02EC6FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6076-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.165 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.165 Severity : moderate Type : security References : 1260078 1260082 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-4437 CVE-2026-4438 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 659 Released: Thu Aug 6 13:30:24 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1260078,1260082,1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-4437,CVE-2026-4438,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.61 updated - libssh-config-0.10.6-slfo.1.1_6.1 updated - libssh4-0.10.6-slfo.1.1_6.1 updated - container:SL-Micro-base-container-2.2.1-5.163 updated From sle-container-updates at lists.suse.com Fri Aug 7 07:33:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 09:33:20 +0200 (CEST) Subject: SUSE-IU-2026:6077-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260807073320.3627FFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6077-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.160 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.160 Severity : moderate Type : security References : 1260078 1260082 1272164 1272165 1272166 1272167 1272168 1272169 1272171 CVE-2026-4437 CVE-2026-4438 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 659 Released: Thu Aug 6 13:30:24 2026 Summary: Security update for libssh Type: security Severity: moderate References: 1260078,1260082,1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-4437,CVE-2026-4438,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850 This update for libssh fixes the following issues - CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). - CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). - CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). - CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). - CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). - CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). - CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.61 updated - libssh-config-0.10.6-slfo.1.1_6.1 updated - libssh4-0.10.6-slfo.1.1_6.1 updated - container:SL-Micro-container-2.2.1-7.146 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:04:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:04:43 +0200 (CEST) Subject: SUSE-CU-2026:8493-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260807080443.ACD88FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8493-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.88 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.88 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3516-1 Released: Thu Aug 6 13:09:13 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-150600.5.59.1 updated - container:sles15-ltss-image-15.6.0-5.79 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:07:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:07:13 +0200 (CEST) Subject: SUSE-CU-2026:8494-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260807080713.680DBFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8494-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.79 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.79 , suse/ltss/sle15.6/sle15:latest Container Release : 5.79 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3516-1 Released: Thu Aug 6 13:09:13 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl-3-fips-provider-3.1.4-150600.5.59.1 updated - libopenssl3-3.1.4-150600.5.59.1 updated - openssl-3-3.1.4-150600.5.59.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:08:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:08:45 +0200 (CEST) Subject: SUSE-CU-2026:8495-1: Security update of bci/php-apache Message-ID: <20260807080845.1AB4EFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8495-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-25.6 , bci/php-apache:latest Container Release : 25.6 Severity : critical Type : security References : 1273075 1273077 1273078 CVE-2026-17543 CVE-2026-7260 CVE-2026-9672 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3509-1 Released: Wed Aug 5 15:48:15 2026 Summary: Security update for php8 Type: security Severity: critical References: 1273075,1273077,1273078,CVE-2026-17543,CVE-2026-7260,CVE-2026-9672 This update for php8 fixes the following issues: Update to version 8.3.33. Security issues fixed: - CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). - CVE-2026-9672: security issues in `libgd` (bsc#1273078). - CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). The following package changes have been done: - php8-cli-8.3.33-150700.3.18.1 updated - php8-8.3.33-150700.3.18.1 updated - apache2-mod_php8-8.3.33-150700.3.18.1 updated - php8-openssl-8.3.33-150700.3.18.1 updated - php8-mbstring-8.3.33-150700.3.18.1 updated - php8-zlib-8.3.33-150700.3.18.1 updated - php8-zip-8.3.33-150700.3.18.1 updated - php8-curl-8.3.33-150700.3.18.1 updated - php8-phar-8.3.33-150700.3.18.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:10:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:10:03 +0200 (CEST) Subject: SUSE-CU-2026:8496-1: Security update of bci/php-fpm Message-ID: <20260807081003.423DDFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8496-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.33 , bci/php-fpm:8.3.33-25.6 , bci/php-fpm:latest Container Release : 25.6 Severity : critical Type : security References : 1273075 1273077 1273078 CVE-2026-17543 CVE-2026-7260 CVE-2026-9672 ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3509-1 Released: Wed Aug 5 15:48:15 2026 Summary: Security update for php8 Type: security Severity: critical References: 1273075,1273077,1273078,CVE-2026-17543,CVE-2026-7260,CVE-2026-9672 This update for php8 fixes the following issues: Update to version 8.3.33. Security issues fixed: - CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). - CVE-2026-9672: security issues in `libgd` (bsc#1273078). - CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). The following package changes have been done: - php8-cli-8.3.33-150700.3.18.1 updated - php8-8.3.33-150700.3.18.1 updated - php8-fpm-8.3.33-150700.3.18.1 updated - php8-openssl-8.3.33-150700.3.18.1 updated - php8-mbstring-8.3.33-150700.3.18.1 updated - php8-zlib-8.3.33-150700.3.18.1 updated - php8-zip-8.3.33-150700.3.18.1 updated - php8-curl-8.3.33-150700.3.18.1 updated - php8-phar-8.3.33-150700.3.18.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:11:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:11:19 +0200 (CEST) Subject: SUSE-CU-2026:8497-1: Security update of bci/php Message-ID: <20260807081119.7CD46FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8497-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.33 , bci/php:8.3.33-25.6 , bci/php:latest Container Release : 25.6 Severity : critical Type : security References : 1273075 1273077 1273078 CVE-2026-17543 CVE-2026-7260 CVE-2026-9672 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3509-1 Released: Wed Aug 5 15:48:15 2026 Summary: Security update for php8 Type: security Severity: critical References: 1273075,1273077,1273078,CVE-2026-17543,CVE-2026-7260,CVE-2026-9672 This update for php8 fixes the following issues: Update to version 8.3.33. Security issues fixed: - CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). - CVE-2026-9672: security issues in `libgd` (bsc#1273078). - CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). The following package changes have been done: - php8-cli-8.3.33-150700.3.18.1 updated - php8-8.3.33-150700.3.18.1 updated - php8-openssl-8.3.33-150700.3.18.1 updated - php8-mbstring-8.3.33-150700.3.18.1 updated - php8-zlib-8.3.33-150700.3.18.1 updated - php8-readline-8.3.33-150700.3.18.1 updated - php8-curl-8.3.33-150700.3.18.1 updated - php8-zip-8.3.33-150700.3.18.1 updated - php8-phar-8.3.33-150700.3.18.1 updated From sle-container-updates at lists.suse.com Fri Aug 7 08:25:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 7 Aug 2026 10:25:29 +0200 (CEST) Subject: SUSE-CU-2026:8477-1: Security update of suse/manager/4.3/proxy-tftpd Message-ID: <20260807082529.C7D84FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-tftpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8477-1 Container Tags : suse/manager/4.3/proxy-tftpd:4.3.19 , suse/manager/4.3/proxy-tftpd:4.3.19.9.72.14 , suse/manager/4.3/proxy-tftpd:latest Container Release : 9.72.14 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-tftpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3457-1 Released: Mon Aug 3 13:51:05 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.99.1 updated - libopenssl1_1-hmac-1.1.1l-150400.7.99.1 updated - openssl-1_1-1.1.1l-150400.7.99.1 updated - container:sles15-ltss-image-15.4.0-6.39 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:12:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:12:01 +0200 (CEST) Subject: SUSE-IU-2026:6170-1: Recommended update of suse/sle-micro/5.5 Message-ID: <20260808071201.CFCC3FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6170-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.79 , suse/sle-micro/5.5:latest Image Release : 5.8.79 Severity : moderate Type : recommended References : 1271645 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3523-1 Released: Fri Aug 7 11:10:48 2026 Summary: Recommended update for policycoreutils Type: recommended Severity: moderate References: 1271645 This update for policycoreutils fixes the following issues: - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645): * can be dropped once 'policycoreutils/scripts/fixfiles: drop /tmp cleanup' is in the upstream release The following package changes have been done: - policycoreutils-3.4-150500.3.3.1 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:12:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:12:02 +0200 (CEST) Subject: SUSE-IU-2026:6171-1: Security update of suse/sle-micro/5.5 Message-ID: <20260808071202.F2A55FDC9@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6171-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.80 , suse/sle-micro/5.5:latest Image Release : 5.8.80 Severity : important Type : security References : 1268579 1269471 CVE-2026-55686 CVE-2026-57231 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3536-1 Released: Fri Aug 7 22:09:26 2026 Summary: Security update for podman Type: security Severity: important References: 1268579,1269471,CVE-2026-55686,CVE-2026-57231 This update for podman fixes the following issues: - CVE-2026-55686: specially crafted image where the `WORKDIR` path contains a symlink allows for directory creation and ownership modification on the host filesystem (bsc#1268579). - CVE-2026-57231: specially crafted image can trick podman run into leaking host environment variables into the container (bsc#1269471). The following package changes have been done: - podman-4.9.5-150500.3.78.1 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:23:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:23:34 +0200 (CEST) Subject: SUSE-CU-2026:8558-1: Recommended update of suse/sle-micro-rancher/5.4 Message-ID: <20260808072334.30A21FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8558-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.163 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.163 Severity : moderate Type : recommended References : 1271645 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3524-1 Released: Fri Aug 7 11:11:07 2026 Summary: Recommended update for policycoreutils Type: recommended Severity: moderate References: 1271645 This update for policycoreutils fixes the following issues: - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645): * can be dropped once 'policycoreutils/scripts/fixfiles: drop /tmp cleanup' is in the upstream release The following package changes have been done: - policycoreutils-3.4-150400.3.3.1 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:26:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:26:07 +0200 (CEST) Subject: SUSE-IU-2026:6172-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260808072607.48076FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6172-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.221 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.221 Severity : important Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 824 Released: Thu Jul 30 12:56:11 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: 836 Released: Fri Aug 7 13:16:33 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-16.1 updated - gawk-5.3.0-2.1 updated - SL-Micro-release-6.0-25.119 updated - container:SL-Micro-base-container-2.1.3-7.185 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:28:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:28:23 +0200 (CEST) Subject: SUSE-IU-2026:6173-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260808072823.C2AE7FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6173-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.185 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.185 Severity : important Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 824 Released: Thu Jul 30 12:56:11 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: 836 Released: Fri Aug 7 13:16:33 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-16.1 updated - gawk-5.3.0-2.1 updated - SL-Micro-release-6.0-25.119 updated - openssl-3-3.1.4-16.1 updated - container:suse-toolbox-image-1.0.0-9.146 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:31:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:31:07 +0200 (CEST) Subject: SUSE-IU-2026:6174-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260808073107.1D776FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6174-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.195 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.195 Severity : important Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 824 Released: Thu Jul 30 12:56:11 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: 836 Released: Fri Aug 7 13:16:33 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-16.1 updated - gawk-5.3.0-2.1 updated - SL-Micro-release-6.0-25.119 updated - container:SL-Micro-base-container-2.1.3-7.185 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:33:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:33:59 +0200 (CEST) Subject: SUSE-IU-2026:6175-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260808073359.C3FACFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6175-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.214 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.214 Severity : important Type : security References : 1271351 1271352 1271354 1271712 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 824 Released: Thu Jul 30 12:56:11 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: 836 Released: Fri Aug 7 13:16:33 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-16.1 updated - gawk-5.3.0-2.1 updated - SL-Micro-release-6.0-25.119 updated - container:SL-Micro-container-2.1.3-6.221 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:42:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:42:16 +0200 (CEST) Subject: SUSE-CU-2026:8563-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260808074216.2F79EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8563-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.146 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.146 Severity : important Type : security References : 1271712 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 836 Released: Fri Aug 7 13:16:33 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1271712 This update for openssl-3 fixes the following issue: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - SL-Micro-release-6.0-25.119 updated - libopenssl3-3.1.4-16.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.118 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:44:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:44:16 +0200 (CEST) Subject: SUSE-IU-2026:6176-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260808074416.9AE1BFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6176-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.147 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.147 Severity : important Type : security References : 1244485 1261653 1261654 1261655 1261656 1261657 1261658 1261659 1261660 1261661 1271712 CVE-2026-27140 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 663 Released: Fri Aug 7 21:54:07 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1244485,1261653,1261654,1261655,1261656,1261657,1261658,1261659,1261660,1261661,1271712,CVE-2026-27140,CVE-2026-27143,CVE-2026-27144,CVE-2026-32280,CVE-2026-32281,CVE-2026-32282,CVE-2026-32283,CVE-2026-32288,CVE-2026-32289 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_12.1 updated - SL-Micro-release-6.1-slfo.1.12.62 updated - container:SL-Micro-base-container-2.2.1-5.164 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:46:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:46:29 +0200 (CEST) Subject: SUSE-IU-2026:6177-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260808074629.A478DFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6177-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.164 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.164 Severity : important Type : security References : 1244485 1261653 1261654 1261655 1261656 1261657 1261658 1261659 1261660 1261661 1271712 CVE-2026-27140 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 663 Released: Fri Aug 7 21:54:07 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1244485,1261653,1261654,1261655,1261656,1261657,1261658,1261659,1261660,1261661,1271712,CVE-2026-27140,CVE-2026-27143,CVE-2026-27144,CVE-2026-32280,CVE-2026-32281,CVE-2026-32282,CVE-2026-32283,CVE-2026-32288,CVE-2026-32289 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_12.1 updated - SL-Micro-release-6.1-slfo.1.12.62 updated - openssl-3-3.1.4-slfo.1.1_12.1 updated - container:suse-toolbox-image-1.0.0-5.85 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:48:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:48:52 +0200 (CEST) Subject: SUSE-IU-2026:6178-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260808074852.E8E47FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6178-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.166 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.166 Severity : important Type : security References : 1244485 1261653 1261654 1261655 1261656 1261657 1261658 1261659 1261660 1261661 1271712 CVE-2026-27140 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 663 Released: Fri Aug 7 21:54:07 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1244485,1261653,1261654,1261655,1261656,1261657,1261658,1261659,1261660,1261661,1271712,CVE-2026-27140,CVE-2026-27143,CVE-2026-27144,CVE-2026-32280,CVE-2026-32281,CVE-2026-32282,CVE-2026-32283,CVE-2026-32288,CVE-2026-32289 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_12.1 updated - SL-Micro-release-6.1-slfo.1.12.62 updated - container:SL-Micro-base-container-2.2.1-5.164 updated From sle-container-updates at lists.suse.com Sat Aug 8 07:51:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 8 Aug 2026 09:51:15 +0200 (CEST) Subject: SUSE-IU-2026:6179-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260808075115.994C1FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6179-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.161 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.161 Severity : important Type : security References : 1244485 1261653 1261654 1261655 1261656 1261657 1261658 1261659 1261660 1261661 1271712 CVE-2026-27140 CVE-2026-27143 CVE-2026-27144 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 CVE-2026-32288 CVE-2026-32289 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 663 Released: Fri Aug 7 21:54:07 2026 Summary: Security update for openssl-3 Type: security Severity: important References: 1244485,1261653,1261654,1261655,1261656,1261657,1261658,1261659,1261660,1261661,1271712,CVE-2026-27140,CVE-2026-27143,CVE-2026-27144,CVE-2026-32280,CVE-2026-32281,CVE-2026-32282,CVE-2026-32283,CVE-2026-32288,CVE-2026-32289 This update for openssl-3 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl3-3.1.4-slfo.1.1_12.1 updated - SL-Micro-release-6.1-slfo.1.12.62 updated - container:SL-Micro-container-2.2.1-7.147 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:14:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:14:06 +0200 (CEST) Subject: SUSE-IU-2026:6228-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260811071406.4859EFDC9@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6228-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.683 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.683 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.82 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:07:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:07:19 +0200 (CEST) Subject: SUSE-IU-2026:6226-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260811070719.70D17FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6226-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.304 , suse/sle-micro/base-5.5:latest Image Release : 5.8.304 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:17:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:17:16 +0200 (CEST) Subject: SUSE-IU-2026:6229-1: Security update of suse/sle-micro/5.5 Message-ID: <20260811071716.E655DFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6229-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.82 , suse/sle-micro/5.5:latest Image Release : 5.8.82 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.304 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:10:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:10:11 +0200 (CEST) Subject: SUSE-IU-2026:6227-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260811071011.0FD02FD94@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6227-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.586 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.586 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.304 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:30:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:30:36 +0200 (CEST) Subject: SUSE-CU-2026:8590-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260811073036.68F10FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8590-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.262 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.262 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:34:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:34:51 +0200 (CEST) Subject: SUSE-CU-2026:8591-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260811073451.ACF2AFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8591-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.164 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.164 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:37:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:37:19 +0200 (CEST) Subject: SUSE-CU-2026:8592-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260811073719.64EC9FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8592-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.263 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.263 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:39:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:39:28 +0200 (CEST) Subject: SUSE-CU-2026:8593-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260811073928.F0B7EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8593-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.172 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.172 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 07:41:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 09:41:54 +0200 (CEST) Subject: SUSE-IU-2026:6230-1: Recommended update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260811074154.90E6CFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6230-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.222 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.222 Severity : moderate Type : recommended References : 1271645 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 838 Released: Mon Aug 10 07:52:04 2026 Summary: Recommended update for policycoreutils Type: recommended Severity: moderate References: 1271645 This update for policycoreutils fixes the following issues: - Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645) * can be dropped once 'policycoreutils/scripts/fixfiles: drop /tmp cleanup' is in the upstream release The following package changes have been done: - policycoreutils-3.5-7.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:12:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:12:22 +0200 (CEST) Subject: SUSE-CU-2026:8599-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260811081222.BB022FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8599-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.40 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.40 , suse/ltss/sle15.4/sle15:latest Container Release : 6.40 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:16:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:16:55 +0200 (CEST) Subject: SUSE-CU-2026:8600-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260811081655.4CD77FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8600-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.61 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.61 , suse/ltss/sle15.5/sle15:latest Container Release : 8.61 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:17:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:17:36 +0200 (CEST) Subject: SUSE-CU-2026:8601-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260811081736.5745AFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8601-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.89 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.89 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:sles15-ltss-image-15.6.0-5.80 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:20:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:20:02 +0200 (CEST) Subject: SUSE-CU-2026:8602-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260811082002.9BB0EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8602-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.80 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.80 , suse/ltss/sle15.6/sle15:latest Container Release : 5.80 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:20:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:20:37 +0200 (CEST) Subject: SUSE-CU-2026:8603-1: Security update of bci/bci-minimal Message-ID: <20260811082037.B30DAFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8603-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.32 , bci/bci-minimal:latest Container Release : 26.32 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:32:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:32:59 +0200 (CEST) Subject: SUSE-CU-2026:8611-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260811083259.7979FFD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8611-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.20 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.20 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:sles15-ltss-image-15.4.0-6.40 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:35:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:35:17 +0200 (CEST) Subject: SUSE-CU-2026:8612-1: Security update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260811083517.0CF23FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8612-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.23 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.23 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:sles15-ltss-image-15.4.0-6.40 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:37:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:37:35 +0200 (CEST) Subject: SUSE-CU-2026:8613-1: Security update of suse/manager/4.3/proxy-squid Message-ID: <20260811083735.A969DFD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-squid ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8613-1 Container Tags : suse/manager/4.3/proxy-squid:4.3.19 , suse/manager/4.3/proxy-squid:4.3.19.9.81.15 , suse/manager/4.3/proxy-squid:latest Container Release : 9.81.15 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:sles15-ltss-image-15.4.0-6.40 updated From sle-container-updates at lists.suse.com Tue Aug 11 08:45:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 11 Aug 2026 10:45:17 +0200 (CEST) Subject: SUSE-CU-2026:8617-1: Security update of trento/trento-web Message-ID: <20260811084517.A7719FD2F@maintenance.suse.de> SUSE Container Update Advisory: trento/trento-web ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8617-1 Container Tags : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.1 , trento/trento-web:latest Container Release : 4.62.1 Severity : important Type : security References : 1252306 1253043 1257463 1261400 1261982 1261983 1262305 1263656 1263658 1267644 1267647 1271712 CVE-2026-40226 CVE-2026-5435 CVE-2026-6238 ----------------------------------------------------------------- The container trento/trento-web was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3030-1 Released: Wed Jul 15 11:53:06 2026 Summary: Security update for glibc Type: security Severity: moderate References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238 This update for glibc fixes the following issues - CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656). - CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3118-1 Released: Fri Jul 17 22:18:41 2026 Summary: Recommended update for gcc15 Type: recommended Severity: moderate References: 1252306,1253043,1257463 This update for gcc15 fixes the following issues: - Update to GCC 15.3 release - Drop -fhardened from RPM_OPT_FLAGS - Avoid conflicts between %gcc_libc_bootstrap packages of different versions if update-alternatives are still in use (SLE 15 and older) - Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion from flags to build D target library files. [jsc#PED-15601] - Remove loongarch64 from quadmath_arch. On LoongArch long double is IEEE quad, so libquadmath is not needed and no longer built. - includes fix for bogus expression simplification [bsc#1257463] even when not available at build time. [bsc#1253043] - Backport fix that cures a miscompile of libgo on arm. [bsc#1252306] - Check availability of builtins at expand time ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3244-1 Released: Fri Jul 24 15:11:25 2026 Summary: Security update for systemd Type: security Severity: moderate References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226 This update for systemd fixes the following issues Security issues fixed: - CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: - Fix soft reboot not restarting user services with default.target (bsc#1262305). - Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644). - Import commit 429043ca9a (bsc#1261982 bsc#1261983). - Import commit 58e5d2e21e (bsc#1261982). - Import commit 4bd91117cc (bsc#1261983). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3515-1 Released: Thu Aug 6 13:08:56 2026 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1271712 This update for openssl-1_1 fixes the following issue - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3563-1 Released: Tue Aug 11 05:44:13 2026 Summary: Recommended update for trento-agent, trento-server-helm, trento-web Type: recommended Severity: moderate References: This update for trento-agent, trento-server-helm, trento-web fixes the following issues: trento-agent: - Release 3.1.2 * Bump github.com/prometheus-community/pro-bing from 0.8.0 to 0.9.0 * Bump golang.org/x/sync from 0.20.0 to 0.21.0 * Bump golang.org/x/mod from 0.36.0 to 0.37.0 * Bump gopkg.in/ini.v1 from 1.67.2 to 1.67.3 * Bump the common-workflows group across 1 directory with 2 updates * Bump github.com/hashicorp/go-plugin from 1.7.0 to 1.8.0 * Bump isbang/compose-action from 2.5.0 to 2.6.0 **Full Changelog**: https://github.com/trento-project/agent/compare/3.1.1...3.1.2 trento-server-helm: - Release 3.1.4 * Trigger release 3.1.4 **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.3...3.1.4 - Release 3.1.3 * Update trento-web to 3.1.5 * Update kubectl to 1.35.4 **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.2...3.1.3 - Release 3.1.2 * Proper name of the check container image * Update busybox and kubectl images to BCI * Add liveness and readiness probes in Web and Wanda * After release fixes **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.1...3.1.2 trento-web: - Release 3.1.5 * Trigger release 3.1.5 * Regenerate package lock **Full Changelog**: https://github.com/trento-project/web/compare/3.1.4...3.1.5 - Release 3.1.4 * Create SIDs list properly using filtered array IDs * Update /assets npm lockfile to remediate transitive vulnerabilities **Full Changelog**: https://github.com/trento-project/web/compare/3.1.3...3.1.4 - Release 3.1.3 * Bump `fast-uri` to 3.1.3 * Bump redux-saga from 1.4.2 to 1.5.0 in /assets * Relax gcp image metadata requirement * Make only SAPSYSTEM and SAPLOCALHOST properties mandatory * Bump brace-expansion to 2.1.2 and 1.1.16 **Full Changelog**: https://github.com/trento-project/web/compare/3.1.2...3.1.3 The following package changes have been done: - glibc-2.38-150600.14.52.1 updated - libgcc_s1-15.3.0+git11272-150000.1.12.1 updated - libstdc++6-15.3.0+git11272-150000.1.12.1 updated - libgcrypt20-1.11.0-150700.5.10.1 updated - libopenssl1_1-1.1.1w-150600.5.35.2 updated - libsystemd0-254.27-150600.4.71.2 updated - trento-web-3.1.5-150300.1.28.2 updated - container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Wed Aug 12 07:08:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 12 Aug 2026 09:08:17 +0200 (CEST) Subject: SUSE-IU-2026:6242-1: Recommended update of suse/sle-micro/base-5.5 Message-ID: <20260812070817.61AC0FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6242-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.305 , suse/sle-micro/base-5.5:latest Image Release : 5.8.305 Severity : important Type : recommended References : 1271980 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3565-1 Released: Tue Aug 11 07:33:35 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) The following package changes have been done: - grub2-2.06-150500.29.68.1 updated - grub2-i386-pc-2.06-150500.29.68.1 updated - grub2-x86_64-efi-2.06-150500.29.68.1 updated From sle-container-updates at lists.suse.com Wed Aug 12 07:38:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 12 Aug 2026 09:38:15 +0200 (CEST) Subject: SUSE-CU-2026:8622-1: Recommended update of suse/sle-micro-rancher/5.4 Message-ID: <20260812073815.9124DFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8622-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.165 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.165 Severity : important Type : recommended References : 1271980 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3564-1 Released: Tue Aug 11 07:33:00 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) The following package changes have been done: - grub2-i386-pc-2.06-150400.11.75.1 updated - grub2-x86_64-efi-2.06-150400.11.75.1 updated - grub2-2.06-150400.11.75.1 updated From sle-container-updates at lists.suse.com Wed Aug 12 07:59:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 12 Aug 2026 09:59:00 +0200 (CEST) Subject: SUSE-CU-2026:8623-1: Security update of bci/nodejs Message-ID: <20260812075901.026E8FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8623-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.28 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.28 Container Release : 24.28 Severity : important Type : security References : 1272882 1272941 1272942 1272943 1272944 1272945 1272947 1272948 1272949 1272950 1272951 CVE-2026-54272 CVE-2026-56846 CVE-2026-56847 CVE-2026-56848 CVE-2026-56850 CVE-2026-58039 CVE-2026-58040 CVE-2026-58042 CVE-2026-58043 CVE-2026-58044 CVE-2026-58045 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3557-1 Released: Mon Aug 10 19:59:13 2026 Summary: Security update for nodejs22 Type: security Severity: important References: 1272882,1272941,1272942,1272943,1272944,1272945,1272947,1272948,1272949,1272950,1272951,CVE-2026-54272,CVE-2026-56846,CVE-2026-56847,CVE-2026-56848,CVE-2026-56850,CVE-2026-58039,CVE-2026-58040,CVE-2026-58042,CVE-2026-58043,CVE-2026-58044,CVE-2026-58045 This update for nodejs22 fixes the following issues: Update to 22.23.2. - CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). - CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). - CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). - CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). - CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). - CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). - CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). - CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). - CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). - CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). - CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). The following package changes have been done: - nodejs22-22.23.2-150700.3.18.1 updated - npm22-22.23.2-150700.3.18.1 updated From sle-container-updates at lists.suse.com Wed Aug 12 08:02:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 12 Aug 2026 10:02:15 +0200 (CEST) Subject: SUSE-CU-2026:8624-1: Security update of suse/samba-client Message-ID: <20260812080215.390E8FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8624-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.7 , suse/samba-client:latest Container Release : 75.7 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:07:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:07:31 +0200 (CEST) Subject: SUSE-IU-2026:6268-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260813070731.AD498FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6268-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.306 , suse/sle-micro/base-5.5:latest Image Release : 5.8.306 Severity : important Type : security References : 1185845 1226591 1237888 1239015 1240054 1240552 1240727 1243603 1244229 1245457 1245728 1245729 1245730 1245731 1246203 1246212 1251135 1251971 1252266 1253049 1254767 1255616 1256690 1257466 1257472 1257541 1258718 1259580 1260347 1261648 1262573 1263010 1263718 1263788 1264013 1264053 1264076 1264089 1264387 1264558 1264779 1265308 1265928 1266238 1266402 1266414 1266758 1266765 1266850 1266913 1267375 1267384 1267435 1267494 1267584 1267596 1267656 1267715 1268029 1268237 1268750 1268989 1269172 1269174 1269181 1269188 1269289 1269512 1269513 1269577 1269584 1269623 1269731 1269773 1269798 1269986 1269988 1269993 1269997 1270257 1271011 1271526 1271825 1271866 1271899 1271904 1271908 1271912 1271964 1272176 1272180 1272207 1272242 1272263 1272268 1272554 1272573 1272607 1272665 1272678 1272693 1272694 1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273097 1273231 1274072 CVE-2022-4994 CVE-2023-2058 CVE-2023-53995 CVE-2024-38542 CVE-2025-21710 CVE-2025-21953 CVE-2025-54518 CVE-2026-31431 CVE-2026-31542 CVE-2026-31598 CVE-2026-31628 CVE-2026-31759 CVE-2026-41992 CVE-2026-43033 CVE-2026-43056 CVE-2026-43211 CVE-2026-43276 CVE-2026-43440 CVE-2026-44605 CVE-2026-46052 CVE-2026-46056 CVE-2026-46080 CVE-2026-46084 CVE-2026-46109 CVE-2026-46117 CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46174 CVE-2026-46193 CVE-2026-46243 CVE-2026-46323 CVE-2026-46333 CVE-2026-52933 CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050 CVE-2026-53131 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256 CVE-2026-53260 CVE-2026-53267 CVE-2026-53297 CVE-2026-53324 CVE-2026-53357 CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806 CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63946 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3595-1 Released: Wed Aug 12 13:33:11 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1226591,1237888,1239015,1240552,1240727,1243603,1244229,1245457,1245728,1245729,1245730,1245731,1246203,1246212,1251135,1251971,1252266,1253049,1254767,1255616,1256690,1257466,1257472,1257541,1258718,1259580,1260347,1261648,1262573,1263010,1263718,1263788,1264013,1264053,1264076,1264089,1264387,1264558,1264779,1265308,1265928,1266238,1266402,1266414,1266758,1266765,1266850,1266913,1267375,1267384,1267435,1267494,1267584,1267596,1267656,1267715,1268029,1268237,1268750,1268989,1269172,1269174,1269181,1269188,1269289,1269512,1269513,1269577,1269731,1269773,1269798,1269986,1269988,1269993,1269997,1270257,1271011,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272573,1272607,1272665,1272678,1272693,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2024-38542,CVE-2025-21710,CVE-2025-21953,CVE-2025-54518,CVE-2026-31431,CVE -2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43056,CVE-2026-43211,CVE-2026-43276,CVE-2026-43440,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52933,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-6 4600 The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097). - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2024-38542: RDMA/mana_ib: boundary check before installing cq callbacks (bsc#1226591). - CVE-2025-21953: net: mana: cleanup mana struct after debugfs_remove() (bsc#1240727). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435). - CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573). - CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855). - CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - block: fix use-after-free of q->q_usage_counter (bsc#1268750). - cpumask: add cpumask_weight_andnot() (bsc#1239015). - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes). - Drivers: hv: remove stale comment (git-fixes). - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes). - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes). - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - Drivers: hv: vmbus: Remove duplication and cleanup code in create_gpadl_header() (git-fixes). - Drivers: hv: vmbus: Update indentation in create_gpadl_header() (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - ethtool: Implement ethtool_puts() (git-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203). - hv_sock: fix ARM64 support (git-fixes). - hv_utils: Allow implicit ICTIMESYNCFLAG_SYNC (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - IPv6/GRO: generic helper to remove temporary HBH/jumbo header in (bsc#1246203). - ipv6/gso: remove temporary HBH/jumbo header (bsc#1246203). - ipv6: add struct hop_jumbo_hdr definition (bsc#1246203). - jiffies: Cast to unsigned long in secs_to_jiffies() conversion (bsc#1257466). - jiffies: Define secs_to_jiffies() (bsc#1257466). - lib/bitmap: add bitmap_weight_and() (bsc#1239015). - mkspec-dtb: Skip missing DTBs. - net/mana: fix warning in the writer of client oob (git-fixes). - net/mana: Null service_wq on setup error to prevent double destroy (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net: mana: add a function to spread IRQs per CPUs (bsc#1239015). - net: mana: Add debug logs in MANA network driver (bsc#1246212). - net: mana: Add handler for hardware servicing events (bsc#1245730 bsc#1251971). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - net: mana: Add metadata support for xdp mode (git-fixes). - net: mana: add msix index sharing between EQs (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - net: mana: Add standard counter rx_missed_errors (git-fixes). - net: mana: Add support for auxiliary device servicing events (bsc#1251971). - net: mana: Add support for Multi Vports on Bare metal (bsc#1244229). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457). - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203). - net: mana: Assigning IRQ affinity on HT cores (bsc#1239015). - net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes). - net: mana: explain irq_setup() algorithm (bsc#1245457). - net: mana: Expose additional hardware counters for drop and TC via ethtool (bsc#1245729). - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (git-fixes). - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes). - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: Fix memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes). - net: mana: Fix spelling mistake 'enforecement' -> 'enforcement' (git-fixes). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - net: mana: fix use-after-free in add_adev() error path (git-fixes). - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes). - net: mana: Fix use-after-free in reset service rescan path (git-fixes). - net: mana: Fix warnings for missing export.h header inclusion (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (bsc#1269798). - net: mana: Handle hardware recovery events when probing the device (bsc#1257466). - net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971). - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes). - net: mana: Handle unsupported HWC commands (git-fixes). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1269798). - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes). - net: mana: Probe rdma device in mana driver (git-fixes). - net: mana: Record doorbell physical address in PF mode (bsc#1244229). - net: mana: Reduce waiting time if HWC not responding (bsc#1252266). - net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - net: mana: Set tx_packets to post gso processing packet count (bsc#1245731). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes). - net: mana: Support HW link state events (bsc#1253049). - net: mana: Switch to page pool for jumbo frames (git-fixes). - net: mana: Trigger VF reset/recovery on health check failure due to HWC timeout (bsc#1259580). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: use ethtool string helpers (git-fixes). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Validate the packet length reported by the NIC (git-fixes). - PCI: hv: Correct a comment (git-fixes). - PCI: hv: Fix ring buffer size calculation (git-fixes). - PCI: hv: remove unnecessary module_init/exit functions (git-fixes). - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - pkspec-dtb: Fix dtb-al rename. - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Validate rx_hash_key_len (git-fixes). - RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135). - RDMA/mana_ib: add additional port counters (bsc#1251135). - RDMA/mana_ib: Add CQ interrupt support for RAW QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device-memory support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add EQ creation for rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add port statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: add support of multiple ports (bsc#1251135). - RDMA/mana_ib: Adding and deleting GIDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allocate PAGE aligned doorbell index (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: check cqe length for kernel CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Configure mac address in RNIC (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create and destroy RNIC cqs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy UD/GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create EQs for RNIC CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create kernel-level CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create/destroy AH (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Enable RoCE on port 1 (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Ensure variable err is initialized (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend mana QP table (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Extend modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend query device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix DSCP value in modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix error code in probe() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135). - RDMA/mana_ib: Fix missing ret value (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690). - RDMA/mana_ib: helpers to allocate kernel queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement DMABUF MR support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement get_dma_mr (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement port parameters (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement req_notify_cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement uapi for creation of rnic cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement uapi to create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: indicate CM support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - RDMA/mana_ib: introduce a helper to remove cq callbacks (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce helpers to create and destroy mana queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mdev_to_gc helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Modify QP state (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: polling of CQs for GSI/UD (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Process QP error events in mana_ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: query device capabilities (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Query feature_flags bitmask from FW (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: register RDMA device with GDMA (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: remove useless return values from dbg prints (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - RDMA/mana_ib: request error CQEs when supported (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Set correct device into ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: set node_guid (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Support memory windows (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: support of the zero based MRs (bsc#1251135). - RDMA/mana_ib: Take CQ type from the device type (bsc#1257541). - RDMA/mana_ib: UD/GSI QP creation for kernel (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: UD/GSI work requests (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: unify mana_ib functions to support any gdma device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (bsc#1271011 jsc#PED-16573). - RDMA/mana_ib: Use num_comp_vectors of ib_device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use safer allocation function() (bsc#1251135). - RDMA/mana_ib: Use struct mana_ib_queue for CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for WQs (bsc#1240552 jsc#PED-12576). - sched/topology: Introduce for_each_numa_hop_mask() (bsc#1239015). - sched/topology: Introduce sched_numa_hop_mask() (bsc#1239015). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - scsi: storvsc: Remove redundant ternary operators (git-fixes). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - sctp: validate embedded address parameter length (git-fixes). - tcp: gso: really support BIG TCP (bsc#1246203). - time: Switch to hrtimer_setup() (bsc#1271912). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-4.14.3-150400.59.19.1 updated - kernel-default-5.14.21-150500.55.182.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:10:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:10:01 +0200 (CEST) Subject: SUSE-IU-2026:6269-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260813071001.DCE65FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6269-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.589 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.589 Severity : important Type : security References : 1185845 1226591 1237888 1239015 1240054 1240552 1240727 1243603 1244229 1245457 1245728 1245729 1245730 1245731 1246203 1246212 1251135 1251971 1252266 1253049 1254767 1255616 1256690 1257466 1257472 1257541 1258718 1259580 1260347 1261648 1262573 1263010 1263718 1263788 1264013 1264053 1264076 1264089 1264387 1264558 1264779 1265308 1265928 1266238 1266402 1266414 1266758 1266765 1266850 1266913 1267375 1267384 1267435 1267494 1267584 1267596 1267656 1267715 1268029 1268237 1268750 1268989 1269172 1269174 1269181 1269188 1269289 1269512 1269513 1269577 1269584 1269623 1269731 1269773 1269798 1269986 1269988 1269993 1269997 1270257 1271011 1271526 1271825 1271866 1271899 1271904 1271908 1271912 1271964 1272176 1272180 1272207 1272242 1272263 1272268 1272554 1272573 1272607 1272665 1272678 1272693 1272694 1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273097 1273231 1274072 CVE-2022-4994 CVE-2023-2058 CVE-2023-53995 CVE-2024-38542 CVE-2025-21710 CVE-2025-21953 CVE-2025-54518 CVE-2026-31431 CVE-2026-31542 CVE-2026-31598 CVE-2026-31628 CVE-2026-31759 CVE-2026-41992 CVE-2026-43033 CVE-2026-43056 CVE-2026-43211 CVE-2026-43276 CVE-2026-43440 CVE-2026-44605 CVE-2026-46052 CVE-2026-46056 CVE-2026-46080 CVE-2026-46084 CVE-2026-46109 CVE-2026-46117 CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46174 CVE-2026-46193 CVE-2026-46243 CVE-2026-46323 CVE-2026-46333 CVE-2026-52933 CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050 CVE-2026-53131 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256 CVE-2026-53260 CVE-2026-53267 CVE-2026-53297 CVE-2026-53324 CVE-2026-53357 CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806 CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63946 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3595-1 Released: Wed Aug 12 13:33:11 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1226591,1237888,1239015,1240552,1240727,1243603,1244229,1245457,1245728,1245729,1245730,1245731,1246203,1246212,1251135,1251971,1252266,1253049,1254767,1255616,1256690,1257466,1257472,1257541,1258718,1259580,1260347,1261648,1262573,1263010,1263718,1263788,1264013,1264053,1264076,1264089,1264387,1264558,1264779,1265308,1265928,1266238,1266402,1266414,1266758,1266765,1266850,1266913,1267375,1267384,1267435,1267494,1267584,1267596,1267656,1267715,1268029,1268237,1268750,1268989,1269172,1269174,1269181,1269188,1269289,1269512,1269513,1269577,1269731,1269773,1269798,1269986,1269988,1269993,1269997,1270257,1271011,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272573,1272607,1272665,1272678,1272693,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2024-38542,CVE-2025-21710,CVE-2025-21953,CVE-2025-54518,CVE-2026-31431,CVE -2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43056,CVE-2026-43211,CVE-2026-43276,CVE-2026-43440,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52933,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-6 4600 The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097). - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2024-38542: RDMA/mana_ib: boundary check before installing cq callbacks (bsc#1226591). - CVE-2025-21953: net: mana: cleanup mana struct after debugfs_remove() (bsc#1240727). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435). - CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573). - CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855). - CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - block: fix use-after-free of q->q_usage_counter (bsc#1268750). - cpumask: add cpumask_weight_andnot() (bsc#1239015). - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes). - Drivers: hv: remove stale comment (git-fixes). - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes). - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes). - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - Drivers: hv: vmbus: Remove duplication and cleanup code in create_gpadl_header() (git-fixes). - Drivers: hv: vmbus: Update indentation in create_gpadl_header() (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - ethtool: Implement ethtool_puts() (git-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203). - hv_sock: fix ARM64 support (git-fixes). - hv_utils: Allow implicit ICTIMESYNCFLAG_SYNC (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - IPv6/GRO: generic helper to remove temporary HBH/jumbo header in (bsc#1246203). - ipv6/gso: remove temporary HBH/jumbo header (bsc#1246203). - ipv6: add struct hop_jumbo_hdr definition (bsc#1246203). - jiffies: Cast to unsigned long in secs_to_jiffies() conversion (bsc#1257466). - jiffies: Define secs_to_jiffies() (bsc#1257466). - lib/bitmap: add bitmap_weight_and() (bsc#1239015). - mkspec-dtb: Skip missing DTBs. - net/mana: fix warning in the writer of client oob (git-fixes). - net/mana: Null service_wq on setup error to prevent double destroy (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net: mana: add a function to spread IRQs per CPUs (bsc#1239015). - net: mana: Add debug logs in MANA network driver (bsc#1246212). - net: mana: Add handler for hardware servicing events (bsc#1245730 bsc#1251971). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - net: mana: Add metadata support for xdp mode (git-fixes). - net: mana: add msix index sharing between EQs (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - net: mana: Add standard counter rx_missed_errors (git-fixes). - net: mana: Add support for auxiliary device servicing events (bsc#1251971). - net: mana: Add support for Multi Vports on Bare metal (bsc#1244229). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457). - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203). - net: mana: Assigning IRQ affinity on HT cores (bsc#1239015). - net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes). - net: mana: explain irq_setup() algorithm (bsc#1245457). - net: mana: Expose additional hardware counters for drop and TC via ethtool (bsc#1245729). - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (git-fixes). - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes). - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: Fix memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes). - net: mana: Fix spelling mistake 'enforecement' -> 'enforcement' (git-fixes). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - net: mana: fix use-after-free in add_adev() error path (git-fixes). - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes). - net: mana: Fix use-after-free in reset service rescan path (git-fixes). - net: mana: Fix warnings for missing export.h header inclusion (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (bsc#1269798). - net: mana: Handle hardware recovery events when probing the device (bsc#1257466). - net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971). - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes). - net: mana: Handle unsupported HWC commands (git-fixes). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1269798). - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes). - net: mana: Probe rdma device in mana driver (git-fixes). - net: mana: Record doorbell physical address in PF mode (bsc#1244229). - net: mana: Reduce waiting time if HWC not responding (bsc#1252266). - net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - net: mana: Set tx_packets to post gso processing packet count (bsc#1245731). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes). - net: mana: Support HW link state events (bsc#1253049). - net: mana: Switch to page pool for jumbo frames (git-fixes). - net: mana: Trigger VF reset/recovery on health check failure due to HWC timeout (bsc#1259580). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: use ethtool string helpers (git-fixes). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Validate the packet length reported by the NIC (git-fixes). - PCI: hv: Correct a comment (git-fixes). - PCI: hv: Fix ring buffer size calculation (git-fixes). - PCI: hv: remove unnecessary module_init/exit functions (git-fixes). - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - pkspec-dtb: Fix dtb-al rename. - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Validate rx_hash_key_len (git-fixes). - RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135). - RDMA/mana_ib: add additional port counters (bsc#1251135). - RDMA/mana_ib: Add CQ interrupt support for RAW QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device-memory support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add EQ creation for rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add port statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: add support of multiple ports (bsc#1251135). - RDMA/mana_ib: Adding and deleting GIDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allocate PAGE aligned doorbell index (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: check cqe length for kernel CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Configure mac address in RNIC (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create and destroy RNIC cqs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy UD/GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create EQs for RNIC CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create kernel-level CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create/destroy AH (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Enable RoCE on port 1 (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Ensure variable err is initialized (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend mana QP table (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Extend modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend query device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix DSCP value in modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix error code in probe() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135). - RDMA/mana_ib: Fix missing ret value (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690). - RDMA/mana_ib: helpers to allocate kernel queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement DMABUF MR support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement get_dma_mr (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement port parameters (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement req_notify_cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement uapi for creation of rnic cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement uapi to create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: indicate CM support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - RDMA/mana_ib: introduce a helper to remove cq callbacks (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce helpers to create and destroy mana queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mdev_to_gc helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Modify QP state (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: polling of CQs for GSI/UD (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Process QP error events in mana_ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: query device capabilities (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Query feature_flags bitmask from FW (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: register RDMA device with GDMA (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: remove useless return values from dbg prints (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - RDMA/mana_ib: request error CQEs when supported (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Set correct device into ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: set node_guid (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Support memory windows (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: support of the zero based MRs (bsc#1251135). - RDMA/mana_ib: Take CQ type from the device type (bsc#1257541). - RDMA/mana_ib: UD/GSI QP creation for kernel (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: UD/GSI work requests (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: unify mana_ib functions to support any gdma device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (bsc#1271011 jsc#PED-16573). - RDMA/mana_ib: Use num_comp_vectors of ib_device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use safer allocation function() (bsc#1251135). - RDMA/mana_ib: Use struct mana_ib_queue for CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for WQs (bsc#1240552 jsc#PED-12576). - sched/topology: Introduce for_each_numa_hop_mask() (bsc#1239015). - sched/topology: Introduce sched_numa_hop_mask() (bsc#1239015). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - scsi: storvsc: Remove redundant ternary operators (git-fixes). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - sctp: validate embedded address parameter length (git-fixes). - tcp: gso: really support BIG TCP (bsc#1246203). - time: Switch to hrtimer_setup() (bsc#1271912). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-4.14.3-150400.59.19.1 updated - kernel-default-base-5.14.21-150500.55.182.1.150500.6.85.2 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.306 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:13:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:13:39 +0200 (CEST) Subject: SUSE-IU-2026:6271-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260813071339.C65F3FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6271-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.688 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.688 Severity : important Type : security References : 1240054 1269584 1269623 1272554 CVE-2026-41992 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-4.14.3-150400.59.19.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.86 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:16:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:16:33 +0200 (CEST) Subject: SUSE-IU-2026:6272-1: Recommended update of suse/sle-micro/5.5 Message-ID: <20260813071633.16BBFFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6272-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.84 , suse/sle-micro/5.5:latest Image Release : 5.8.84 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:16:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:16:34 +0200 (CEST) Subject: SUSE-IU-2026:6273-1: Security update of suse/sle-micro/5.5 Message-ID: <20260813071634.45AF5FDC9@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6273-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.86 , suse/sle-micro/5.5:latest Image Release : 5.8.86 Severity : important Type : security References : 1240054 1269584 1269623 1272554 CVE-2026-41992 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-4.14.3-150400.59.19.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.306 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:23:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:23:49 +0200 (CEST) Subject: SUSE-CU-2026:8635-1: Security update of private-registry/1.2/harbor-portal Message-ID: <20260813072349.5838CFD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8635-1 Container Tags : private-registry/1.2/harbor-portal:1.2.1 , private-registry/1.2/harbor-portal:1.2.1-1.79 , private-registry/1.2/harbor-portal:latest Container Release : 1.79 Severity : important Type : security References : 1266304 1268349 1271372 1273101 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 CVE-2026-9672 ----------------------------------------------------------------- The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3553-1 Released: Mon Aug 10 18:47:09 2026 Summary: Security update for gd Type: security Severity: important References: 1273101,CVE-2026-9672 This update for gd fixes the following issue: - CVE-2026-9672: security issues in `libgd` (bsc#1273101). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - libgd3-2.2.5-150200.11.8.1 updated - system-user-harbor-2.15.1-150700.1.28 updated - harbor-portal-2.15.1-150700.1.28 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:29:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:29:33 +0200 (CEST) Subject: SUSE-CU-2026:8646-1: Security update of private-registry/harbor-portal Message-ID: <20260813072933.E6F0DFD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8646-1 Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.99 , private-registry/harbor-portal:latest Container Release : 2.99 Severity : important Type : security References : 1266304 1268349 1271372 1273101 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 CVE-2026-9672 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3553-1 Released: Mon Aug 10 18:47:09 2026 Summary: Security update for gd Type: security Severity: important References: 1273101,CVE-2026-9672 This update for gd fixes the following issue: - CVE-2026-9672: security issues in `libgd` (bsc#1273101). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - libgd3-2.2.5-150200.11.8.1 updated - system-user-harbor-2.14.4-150700.1.31 updated - harbor-portal-2.14.4-150700.1.31 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:33:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:33:33 +0200 (CEST) Subject: SUSE-CU-2026:8656-1: Security update of private-registry/harbor-portal Message-ID: <20260813073333.C4777FD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-portal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8656-1 Container Tags : private-registry/harbor-portal:2.13 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5 , private-registry/harbor-portal:2.13.5-1.41 , private-registry/harbor-portal:2.13.5-1.41 , private-registry/harbor-portal:latest Container Release : 1.41 Severity : important Type : security References : 1266304 1268349 1271372 1273101 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 CVE-2026-9672 ----------------------------------------------------------------- The container private-registry/harbor-portal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3553-1 Released: Mon Aug 10 18:47:09 2026 Summary: Security update for gd Type: security Severity: important References: 1273101,CVE-2026-9672 This update for gd fixes the following issue: - CVE-2026-9672: security issues in `libgd` (bsc#1273101). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - libgd3-2.2.5-150200.11.8.1 updated - system-user-harbor-2.13.5-150700.1.19 updated - harbor213-portal-2.13.5-150700.1.19 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:42:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:42:03 +0200 (CEST) Subject: SUSE-CU-2026:8666-1: Recommended update of suse/sle-micro/5.3/toolbox Message-ID: <20260813074203.AC7C4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8666-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.263 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.263 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:42:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:42:04 +0200 (CEST) Subject: SUSE-CU-2026:8667-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260813074204.ADD89FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8667-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.264 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.264 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - python3-rpm-4.14.3-150400.59.19.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:46:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:46:20 +0200 (CEST) Subject: SUSE-CU-2026:8668-1: Recommended update of suse/sle-micro-rancher/5.4 Message-ID: <20260813074620.E9D16FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8668-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.166 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.166 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:46:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:46:22 +0200 (CEST) Subject: SUSE-CU-2026:8669-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260813074622.41F24FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8669-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.167 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.167 Severity : important Type : security References : 1185845 1237888 1240054 1243603 1254767 1255616 1258718 1262573 1263718 1263788 1264013 1264076 1264089 1265308 1266238 1266850 1267384 1267435 1267494 1267596 1267656 1267715 1268029 1269172 1269174 1269181 1269188 1269289 1269577 1269584 1269623 1269731 1269773 1269986 1269988 1269993 1269997 1270230 1270257 1271526 1271825 1271899 1271904 1271908 1271912 1271964 1272176 1272180 1272207 1272242 1272263 1272268 1272554 1272607 1272678 1272694 1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273097 1273231 1274072 1274432 CVE-2022-4994 CVE-2023-2058 CVE-2023-53995 CVE-2025-21710 CVE-2025-54518 CVE-2026-15816 CVE-2026-31431 CVE-2026-31598 CVE-2026-31628 CVE-2026-31759 CVE-2026-41992 CVE-2026-43033 CVE-2026-44605 CVE-2026-46052 CVE-2026-46056 CVE-2026-46080 CVE-2026-46109 CVE-2026-46145 CVE-2026-46174 CVE-2026-46193 CVE-2026-46243 CVE-2026-46323 CVE-2026-46333 CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050 CVE-2026-53131 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256 CVE-2026-53260 CVE-2026-53267 CVE-2026-53354 CVE-2026-53357 CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806 CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63893 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3593-1 Released: Wed Aug 12 13:29:35 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1237888,1243603,1254767,1255616,1258718,1262573,1263718,1263788,1264013,1264076,1264089,1265308,1266238,1266850,1267384,1267435,1267494,1267596,1267656,1267715,1268029,1269172,1269174,1269181,1269188,1269289,1269577,1269731,1269773,1269986,1269988,1269993,1269997,1270230,1270257,1271526,1271825,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272607,1272678,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2025-21710,CVE-2025-54518,CVE-2026-31431,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46109,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53 354,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600 The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097). - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435). - CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - mkspec-dtb: Skip missing DTBs. - pkspec-dtb: Fix dtb-al rename. - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - sctp: validate embedded address parameter length (git-fixes). - time: Switch to hrtimer_setup() (bsc#1271912). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3599-1 Released: Wed Aug 12 13:53:05 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 055+suse.367.g85633e8. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1 updated - dracut-055+suse.367.g85633e8-150400.3.52.1 updated - gzip-1.10-150200.16.1 updated - kernel-default-5.14.21-150400.24.235.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:49:18 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:49:18 +0200 (CEST) Subject: SUSE-CU-2026:8670-1: Recommended update of suse/sle-micro/5.4/toolbox Message-ID: <20260813074918.5C0AAFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8670-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.264 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.264 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:49:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:49:19 +0200 (CEST) Subject: SUSE-CU-2026:8671-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260813074919.85096FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8671-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.265 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.265 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - python3-rpm-4.14.3-150400.59.19.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:51:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:51:34 +0200 (CEST) Subject: SUSE-CU-2026:8672-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260813075134.450A4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8672-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.175 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.175 Severity : important Type : security References : 1240054 1269584 1269623 1272554 CVE-2026-41992 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - python3-rpm-4.14.3-150400.59.19.1 updated - rpm-4.14.3-150400.59.19.1 updated - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:53:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:53:45 +0200 (CEST) Subject: SUSE-IU-2026:6274-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260813075345.C3EBFFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6274-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.223 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.223 Severity : critical Type : security References : 1272922 1272923 1272924 1272925 1272926 1272927 1272928 1272930 CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 CVE-2026-16530 CVE-2026-16531 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 842 Released: Tue Aug 11 13:11:14 2026 Summary: Security update for pcp Type: security Severity: critical References: 1272922,1272923,1272924,1272925,1272926,1272927,1272928,1272930,CVE-2026-16524,CVE-2026-16526,CVE-2026-16527,CVE-2026-16529,CVE-2026-16530,CVE-2026-16531 This update for pcp fixes the following issues: - CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). - CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). - CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). - CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). - CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). - CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). - command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). - command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). The following package changes have been done: - SL-Micro-release-6.0-25.120 updated - pcp-conf-6.2.0-2.1 updated - libpcp3-6.2.0-2.1 updated - libpcp_import1-6.2.0-2.1 updated - container:SL-Micro-base-container-2.1.3-7.186 updated From sle-container-updates at lists.suse.com Thu Aug 13 07:56:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 09:56:05 +0200 (CEST) Subject: SUSE-IU-2026:6275-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260813075605.4F2B5FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6275-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.186 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.186 Severity : important Type : security References : CVE-2025-28162 CVE-2025-64505 CVE-2025-64506 CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 CVE-2026-22695 CVE-2026-22801 CVE-2026-25646 CVE-2026-33416 CVE-2026-33636 CVE-2026-34757 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 841 Released: Tue Aug 11 12:52:28 2026 Summary: Security update for libpng16 Type: security Severity: important References: CVE-2025-28162,CVE-2025-64505,CVE-2025-64506,CVE-2025-64720,CVE-2025-65018,CVE-2025-66293,CVE-2026-22695,CVE-2026-22801,CVE-2026-25646,CVE-2026-33416,CVE-2026-33636,CVE-2026-34757 This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). The following package changes have been done: - libpng16-16-1.6.58-1.1 updated - SL-Micro-release-6.0-25.120 updated - container:suse-toolbox-image-1.0.0-9.147 updated From sle-container-updates at lists.suse.com Thu Aug 13 08:12:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 10:12:35 +0200 (CEST) Subject: SUSE-IU-2026:6278-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260813081235.518E8FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6278-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.148 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.148 Severity : critical Type : security References : 1260007 1272922 1272923 1272924 1272925 1272926 1272927 1272928 1272930 CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 CVE-2026-16530 CVE-2026-16531 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 664 Released: Tue Aug 11 13:26:04 2026 Summary: Security update for pcp Type: security Severity: critical References: 1260007,1272922,1272923,1272924,1272925,1272926,1272927,1272928,1272930,CVE-2026-16524,CVE-2026-16526,CVE-2026-16527,CVE-2026-16529,CVE-2026-16530,CVE-2026-16531 This update for pcp fixes the following issues: - CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). - CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). - CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). - CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). - CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). - CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). - command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). - command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). The following package changes have been done: - pcp-conf-6.2.0-slfo.1.1_6.1 updated - libpcp3-6.2.0-slfo.1.1_6.1 updated - libpcp_import1-6.2.0-slfo.1.1_6.1 updated From sle-container-updates at lists.suse.com Thu Aug 13 08:29:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 13 Aug 2026 10:29:32 +0200 (CEST) Subject: SUSE-IU-2026:6281-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260813082932.47C2AFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6281-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.95 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.95 Severity : important Type : recommended References : 1259132 1271980 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1451 Released: Tue Aug 11 12:13:14 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1259132,1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) - Add python-base BR - Fix broken bash completion on arm64 images when the bash-completion package is not installed (bsc#1259132) The following package changes have been done: - grub2-common-2.12-160000.7.1 updated - grub2-i386-pc-2.12-160000.7.1 updated - grub2-2.12-160000.7.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-001dbf64dc1a489968383c6e7f4ec3699fdd202bcfe6f579e6b9c2d6b6ae9139-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:07:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:07:32 +0200 (CEST) Subject: SUSE-IU-2026:6290-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260814070732.EE8B1FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6290-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.307 , suse/sle-micro/base-5.5:latest Image Release : 5.8.307 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3611-1 Released: Thu Aug 13 19:58:27 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 055+suse.404.gc96044c. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-055+suse.404.gc96044c-150500.3.44.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:13:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:13:34 +0200 (CEST) Subject: SUSE-IU-2026:6292-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260814071334.3C299FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6292-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.691 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.691 Severity : important Type : security References : 1185845 1226591 1237888 1239015 1240552 1240727 1243603 1244229 1245457 1245728 1245729 1245730 1245731 1246203 1246212 1251135 1251971 1252266 1253049 1254767 1255616 1256690 1257466 1257472 1257541 1258718 1259580 1260347 1261648 1262573 1263010 1263718 1263788 1264013 1264053 1264076 1264089 1264387 1264558 1264779 1265308 1265928 1266238 1266402 1266414 1266758 1266765 1266850 1266913 1267375 1267384 1267435 1267494 1267584 1267596 1267656 1267715 1268029 1268237 1268750 1268989 1269172 1269174 1269181 1269188 1269289 1269512 1269513 1269577 1269731 1269773 1269798 1269986 1269988 1269993 1269997 1270257 1271011 1271526 1271825 1271866 1271899 1271904 1271908 1271912 1271964 1272176 1272180 1272207 1272242 1272263 1272268 1272573 1272607 1272665 1272678 1272693 1272694 1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273097 1273231 1274072 CVE-2022-4994 CVE-2023-2058 CVE-2023-53995 CVE-2024-38542 CVE-2025-21710 CVE-2025-21953 CVE-2025-54518 CVE-2026-31431 CVE-2026-31542 CVE-2026-31598 CVE-2026-31628 CVE-2026-31759 CVE-2026-43033 CVE-2026-43056 CVE-2026-43211 CVE-2026-43276 CVE-2026-43440 CVE-2026-46052 CVE-2026-46056 CVE-2026-46080 CVE-2026-46084 CVE-2026-46109 CVE-2026-46117 CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46174 CVE-2026-46193 CVE-2026-46243 CVE-2026-46323 CVE-2026-46333 CVE-2026-52933 CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050 CVE-2026-53131 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256 CVE-2026-53260 CVE-2026-53267 CVE-2026-53297 CVE-2026-53324 CVE-2026-53357 CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806 CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63946 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3617-1 Released: Thu Aug 13 20:04:34 2026 Summary: Security update for the Linux Kernel Type: security Severity: important References: 1185845,1226591,1237888,1239015,1240552,1240727,1243603,1244229,1245457,1245728,1245729,1245730,1245731,1246203,1246212,1251135,1251971,1252266,1253049,1254767,1255616,1256690,1257466,1257472,1257541,1258718,1259580,1260347,1261648,1262573,1263010,1263718,1263788,1264013,1264053,1264076,1264089,1264387,1264558,1264779,1265308,1265928,1266238,1266402,1266414,1266758,1266765,1266850,1266913,1267375,1267384,1267435,1267494,1267584,1267596,1267656,1267715,1268029,1268237,1268750,1268989,1269172,1269174,1269181,1269188,1269289,1269512,1269513,1269577,1269731,1269773,1269798,1269986,1269988,1269993,1269997,1270257,1271011,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272573,1272607,1272665,1272678,1272693,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2024-38542,CVE-2025-21710,CVE-2025-21953,CVE-2025-54518,CVE-2026-31431,CVE -2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43056,CVE-2026-43211,CVE-2026-43276,CVE-2026-43440,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52933,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-6 4600 The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues: The following security issues were fixed: - CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097). - CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). - CVE-2024-38542: RDMA/mana_ib: boundary check before installing cq callbacks (bsc#1226591). - CVE-2025-21953: net: mana: cleanup mana struct after debugfs_remove() (bsc#1240727). - CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494). - CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435). - CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715). - CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656). - CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989). - CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172). - CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174). - CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181). - CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289). - CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188). - CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773). - CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986). - CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997). - CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988). - CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993). - CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731). - CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577). - CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257). - CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899). - CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825). - CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904). - CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908). - CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964). - CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268). - CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263). - CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180). - CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176). - CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573). - CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904). - CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918). - CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855). - CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678). - CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694). - CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035). - CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207). - CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004). - CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231). - CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072). - CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526). The following non security issues were fixed: - block: fix use-after-free of q->q_usage_counter (bsc#1268750). - cpumask: add cpumask_weight_andnot() (bsc#1239015). - Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes). - Drivers: hv: remove stale comment (git-fixes). - Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes). - Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes). - Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes). - Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes). - Drivers: hv: vmbus: Remove duplication and cleanup code in create_gpadl_header() (git-fixes). - Drivers: hv: vmbus: Update indentation in create_gpadl_header() (git-fixes). - drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). - drm/hyperv: validate VMBus packet size in receive callback (git-fixes). - ethtool: Implement ethtool_puts() (git-fixes). - hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912). - hv: utils: handle and propagate errors in kvp_register (git-fixes). - hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). - hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203). - hv_sock: fix ARM64 support (git-fixes). - hv_utils: Allow implicit ICTIMESYNCFLAG_SYNC (git-fixes). - hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). - IPv6/GRO: generic helper to remove temporary HBH/jumbo header in (bsc#1246203). - ipv6/gso: remove temporary HBH/jumbo header (bsc#1246203). - ipv6: add struct hop_jumbo_hdr definition (bsc#1246203). - jiffies: Cast to unsigned long in secs_to_jiffies() conversion (bsc#1257466). - jiffies: Define secs_to_jiffies() (bsc#1257466). - lib/bitmap: add bitmap_weight_and() (bsc#1239015). - mkspec-dtb: Skip missing DTBs. - net/mana: fix warning in the writer of client oob (git-fixes). - net/mana: Null service_wq on setup error to prevent double destroy (git-fixes). - net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866). - net: mana: add a function to spread IRQs per CPUs (bsc#1239015). - net: mana: Add debug logs in MANA network driver (bsc#1246212). - net: mana: Add handler for hardware servicing events (bsc#1245730 bsc#1251971). - net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes). - net: mana: Add metadata support for xdp mode (git-fixes). - net: mana: add msix index sharing between EQs (git-fixes). - net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). - net: mana: Add standard counter rx_missed_errors (git-fixes). - net: mana: Add support for auxiliary device servicing events (bsc#1251971). - net: mana: Add support for Multi Vports on Bare metal (bsc#1244229). - net: mana: Add support for PF device 0x00C1 (bsc#1268237). - net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457). - net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203). - net: mana: Assigning IRQ affinity on HT cores (bsc#1239015). - net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes). - net: mana: Create separate EQs for each vPort (git-fixes). - net: mana: Don't overwrite port probe error with add_adev result (git-fixes). - net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes). - net: mana: explain irq_setup() algorithm (bsc#1245457). - net: mana: Expose additional hardware counters for drop and TC via ethtool (bsc#1245729). - net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). - net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes). - net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (git-fixes). - net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes). - net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes). - net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: Fix memory leak in mana_gd_setup_irqs (bsc#1239015). - net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes). - net: mana: Fix spelling mistake 'enforecement' -> 'enforcement' (git-fixes). - net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). - net: mana: fix use-after-free in add_adev() error path (git-fixes). - net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes). - net: mana: Fix use-after-free in reset service rescan path (git-fixes). - net: mana: Fix warnings for missing export.h header inclusion (git-fixes). - net: mana: Guard mana_remove against double invocation (git-fixes). - net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (bsc#1269798). - net: mana: Handle hardware recovery events when probing the device (bsc#1257466). - net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971). - net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes). - net: mana: Handle unsupported HWC commands (git-fixes). - net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). - net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes). - net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes). - net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472). - net: mana: Init gf_stats_work before potential error paths in probe (git-fixes). - net: mana: Init link_change_work before potential error paths in probe (git-fixes). - net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1269798). - net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes). - net: mana: Probe rdma device in mana driver (git-fixes). - net: mana: Record doorbell physical address in PF mode (bsc#1244229). - net: mana: Reduce waiting time if HWC not responding (bsc#1252266). - net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes). - net: mana: Return error code from mana_create_rxq() (git-fixes). - net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes). - net: mana: Set default number of queues to 16 (bsc#1261648). - net: mana: Set tx_packets to post gso processing packet count (bsc#1245731). - net: mana: Skip redundant detach on already-detached port (git-fixes). - net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes). - net: mana: Support HW link state events (bsc#1253049). - net: mana: Switch to page pool for jumbo frames (git-fixes). - net: mana: Trigger VF reset/recovery on health check failure due to HWC timeout (bsc#1259580). - net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes). - net: mana: use ethtool string helpers (git-fixes). - net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). - net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes). - net: mana: Use pci_name() for debugfs directory naming (git-fixes). - net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). - net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). - net: mana: Validate the packet length reported by the NIC (git-fixes). - PCI: hv: Correct a comment (git-fixes). - PCI: hv: Fix ring buffer size calculation (git-fixes). - PCI: hv: remove unnecessary module_init/exit functions (git-fixes). - PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes). - PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648). - pkspec-dtb: Fix dtb-al rename. - posix-cpu-timers: Cleanup the firing logic (bsc#1271912). - posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912). - posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912). - posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912). - posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912). - posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912). - posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912). - posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912). - posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912). - posix-timers: Add proper state tracking (bsc#1271912). - posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912). - posix-timers: Clarify posix_timer_fn() comments (bsc#1271912). - posix-timers: Clear overrun in common_timer_set() (bsc#1271912). - posix-timers: Consolidate signal queueing (bsc#1271912). - posix-timers: Consolidate timer setup (bsc#1271912). - posix-timers: Cure si_sys_private race (bsc#1271912). - posix-timers: Document common_clock_get() correctly (bsc#1271912). - posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912). - posix-timers: Polish coding style in a few places (bsc#1271912). - posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912). - RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes). - RDMA/mana: Validate rx_hash_key_len (git-fixes). - RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135). - RDMA/mana_ib: add additional port counters (bsc#1251135). - RDMA/mana_ib: Add CQ interrupt support for RAW QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add device-memory support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add EQ creation for rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add port statistics support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: add support of multiple ports (bsc#1251135). - RDMA/mana_ib: Adding and deleting GIDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allocate PAGE aligned doorbell index (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: check cqe length for kernel CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Configure mac address in RNIC (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy rnic adapter (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create and destroy RNIC cqs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Create and destroy UD/GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create EQs for RNIC CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create kernel-level CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: create/destroy AH (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Disable RX steering on RSS QP destroy (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Enable RoCE on port 1 (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Ensure variable err is initialized (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend mana QP table (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Extend modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: extend query device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix DSCP value in modify QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix error code in probe() (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135). - RDMA/mana_ib: Fix missing ret value (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690). - RDMA/mana_ib: helpers to allocate kernel queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement DMABUF MR support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement get_dma_mr (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement port parameters (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement req_notify_cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: implement uapi for creation of rnic cq (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Implement uapi to create and destroy RC QP (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: indicate CM support (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: initialize err for empty send WR lists (git-fixes). - RDMA/mana_ib: introduce a helper to remove cq callbacks (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce helpers to create and destroy mana queues (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Introduce mdev_to_gc helper function (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Modify QP state (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: polling of CQs for GSI/UD (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Process QP error events in mana_ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: query device capabilities (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Query feature_flags bitmask from FW (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: register RDMA device with GDMA (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: remove useless return values from dbg prints (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). - RDMA/mana_ib: request error CQEs when supported (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Set correct device into ib (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: set node_guid (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Support memory windows (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: support of the zero based MRs (bsc#1251135). - RDMA/mana_ib: Take CQ type from the device type (bsc#1257541). - RDMA/mana_ib: UD/GSI QP creation for kernel (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: UD/GSI work requests (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: unify mana_ib functions to support any gdma device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (bsc#1271011 jsc#PED-16573). - RDMA/mana_ib: Use num_comp_vectors of ib_device (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use safer allocation function() (bsc#1251135). - RDMA/mana_ib: Use struct mana_ib_queue for CQs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (bsc#1240552 jsc#PED-12576). - RDMA/mana_ib: Use struct mana_ib_queue for WQs (bsc#1240552 jsc#PED-12576). - sched/topology: Introduce for_each_numa_hop_mask() (bsc#1239015). - sched/topology: Introduce sched_numa_hop_mask() (bsc#1239015). - scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes). - scsi: storvsc: Remove redundant ternary operators (git-fixes). - scsi: storvsc: Replace symbolic permissions with octal (git-fixes). - sctp: validate embedded address parameter length (git-fixes). - tcp: gso: really support BIG TCP (bsc#1246203). - time: Switch to hrtimer_setup() (bsc#1271912). The following package changes have been done: - kernel-rt-5.14.21-150500.13.156.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.88 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:16:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:16:16 +0200 (CEST) Subject: SUSE-IU-2026:6293-1: Security update of suse/sle-micro/5.5 Message-ID: <20260814071616.0C400FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6293-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.88 , suse/sle-micro/5.5:latest Image Release : 5.8.88 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3611-1 Released: Thu Aug 13 19:58:27 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 055+suse.404.gc96044c. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-055+suse.404.gc96044c-150500.3.44.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.307 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:25:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:25:48 +0200 (CEST) Subject: SUSE-IU-2026:6295-1: Recommended update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260814072548.04AC3FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6295-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.226 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.226 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 844 Released: Thu Aug 13 17:23:12 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - SL-Micro-release-6.0-25.121 updated - timezone-2026c-1.1 updated - container:SL-Micro-base-container-2.1.3-7.189 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:28:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:28:02 +0200 (CEST) Subject: SUSE-IU-2026:6296-1: Recommended update of suse/sl-micro/6.0/base-os-container Message-ID: <20260814072802.A04DEFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6296-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.187 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.187 Severity : important Type : recommended References : 1271980 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 843 Released: Thu Aug 13 14:19:44 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) The following package changes have been done: - grub2-2.12~rc1-9.1 updated - grub2-i386-pc-2.12~rc1-9.1 updated - grub2-x86_64-efi-2.12~rc1-9.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:41:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:41:40 +0200 (CEST) Subject: SUSE-CU-2026:8699-1: Recommended update of suse/sl-micro/6.0/toolbox Message-ID: <20260814074140.AF01CFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8699-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.149 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.149 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 844 Released: Thu Aug 13 17:23:12 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - SL-Micro-release-6.0-25.121 updated - skelcd-EULA-SL-Micro-2024.01.19-8.120 updated - timezone-2026c-1.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 07:45:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 09:45:40 +0200 (CEST) Subject: SUSE-IU-2026:6303-1: Recommended update of suse/sl-micro/6.1/base-os-container Message-ID: <20260814074540.961AFFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6303-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.165 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.165 Severity : important Type : recommended References : 1260251 1271980 CVE-2026-33186 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 668 Released: Thu Aug 13 08:31:01 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1260251,1271980,CVE-2026-33186 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) The following package changes have been done: - grub2-2.12-slfo.1.1_7.1 updated - grub2-i386-pc-2.12-slfo.1.1_7.1 updated - grub2-x86_64-efi-2.12-slfo.1.1_7.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:06:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:06:46 +0200 (CEST) Subject: SUSE-IU-2026:6306-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260814080646.5803DFD94@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6306-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.84 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.84 Severity : important Type : recommended References : 1259132 1271980 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1451 Released: Tue Aug 11 12:13:14 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1259132,1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) - Add python-base BR - Fix broken bash completion on arm64 images when the bash-completion package is not installed (bsc#1259132) The following package changes have been done: - grub2-common-2.12-160000.7.1 updated - grub2-i386-pc-2.12-160000.7.1 updated - grub2-2.12-160000.7.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-001dbf64dc1a489968383c6e7f4ec3699fdd202bcfe6f579e6b9c2d6b6ae9139-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:14:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:14:40 +0200 (CEST) Subject: SUSE-IU-2026:6313-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260814081440.0683EFD94@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6313-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.109 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.109 Severity : important Type : recommended References : 1259132 1271980 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1451 Released: Tue Aug 11 12:13:14 2026 Summary: Recommended update for grub2 Type: recommended Severity: important References: 1259132,1271980 This update for grub2 fixes the following issues: - Fix crash in booting kernel on some AMD systems (bsc#1271980) - Add python-base BR - Fix broken bash completion on arm64 images when the bash-completion package is not installed (bsc#1259132) The following package changes have been done: - grub2-common-2.12-160000.7.1 updated - grub2-i386-pc-2.12-160000.7.1 updated - grub2-2.12-160000.7.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-64e0bb9557317a0de0533fafd62359fec40072f53fd2c4ee0ad1c760c5f3c351-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:23:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:23:31 +0200 (CEST) Subject: SUSE-CU-2026:8706-1: Recommended update of suse/ltss/sle15.4/sle15 Message-ID: <20260814082331.8ED31FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8706-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.41 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.41 , suse/ltss/sle15.4/sle15:latest Container Release : 6.41 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:23:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:23:32 +0200 (CEST) Subject: SUSE-CU-2026:8707-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260814082332.B603AFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8707-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.42 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.42 , suse/ltss/sle15.4/sle15:latest Container Release : 6.42 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:27:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:27:49 +0200 (CEST) Subject: SUSE-CU-2026:8708-1: Recommended update of suse/ltss/sle15.5/sle15 Message-ID: <20260814082749.C3884FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8708-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.63 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.63 , suse/ltss/sle15.5/sle15:latest Container Release : 8.63 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:27:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:27:50 +0200 (CEST) Subject: SUSE-CU-2026:8709-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260814082750.EC999FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8709-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.64 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.64 , suse/ltss/sle15.5/sle15:latest Container Release : 8.64 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:31:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:31:04 +0200 (CEST) Subject: SUSE-CU-2026:8711-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260814083104.E7196FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8711-1 Container Tags : bci/dotnet-aspnet:10.0 , bci/dotnet-aspnet:10.0-sles15 , bci/dotnet-aspnet:10.0.10 , bci/dotnet-aspnet:10.0.10-27.6 , bci/dotnet-aspnet:latest Container Release : 27.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:32:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:32:25 +0200 (CEST) Subject: SUSE-CU-2026:8713-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260814083225.7CC22FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8713-1 Container Tags : bci/dotnet-aspnet:8.0 , bci/dotnet-aspnet:8.0-sles15 , bci/dotnet-aspnet:8.0.29 , bci/dotnet-aspnet:8.0.29-97.6 Container Release : 97.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:33:37 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:33:37 +0200 (CEST) Subject: SUSE-CU-2026:8715-1: Recommended update of bci/dotnet-aspnet Message-ID: <20260814083337.74567FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-aspnet ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8715-1 Container Tags : bci/dotnet-aspnet:9.0 , bci/dotnet-aspnet:9.0-sles15 , bci/dotnet-aspnet:9.0.18 , bci/dotnet-aspnet:9.0.18-56.6 Container Release : 56.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-aspnet was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:35:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:35:36 +0200 (CEST) Subject: SUSE-CU-2026:8718-1: Recommended update of bci/dotnet-sdk Message-ID: <20260814083536.462FDFD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8718-1 Container Tags : bci/dotnet-sdk:10.0 , bci/dotnet-sdk:10.0-sles15 , bci/dotnet-sdk:10.0.10 , bci/dotnet-sdk:10.0.10-27.6 , bci/dotnet-sdk:latest Container Release : 27.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:36:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:36:51 +0200 (CEST) Subject: SUSE-CU-2026:8720-1: Recommended update of bci/dotnet-sdk Message-ID: <20260814083651.929CEFD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8720-1 Container Tags : bci/dotnet-sdk:8.0 , bci/dotnet-sdk:8.0-sles15 , bci/dotnet-sdk:8.0.29 , bci/dotnet-sdk:8.0.29-97.6 Container Release : 97.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 08:38:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 10:38:13 +0200 (CEST) Subject: SUSE-CU-2026:8722-1: Recommended update of bci/dotnet-sdk Message-ID: <20260814083813.97B71FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8722-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.18 , bci/dotnet-sdk:9.0.18-57.6 Container Release : 57.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:27:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:27:23 +0200 (CEST) Subject: SUSE-CU-2026:8722-1: Recommended update of bci/dotnet-sdk Message-ID: <20260814092723.1B946FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-sdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8722-1 Container Tags : bci/dotnet-sdk:9.0 , bci/dotnet-sdk:9.0-sles15 , bci/dotnet-sdk:9.0.18 , bci/dotnet-sdk:9.0.18-57.6 Container Release : 57.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-sdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:28:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:28:13 +0200 (CEST) Subject: SUSE-CU-2026:8724-1: Recommended update of bci/dotnet-runtime Message-ID: <20260814092813.34A54FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8724-1 Container Tags : bci/dotnet-runtime:10.0 , bci/dotnet-runtime:10.0-sles15 , bci/dotnet-runtime:10.0.10 , bci/dotnet-runtime:10.0.10-27.6 , bci/dotnet-runtime:latest Container Release : 27.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:29:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:29:19 +0200 (CEST) Subject: SUSE-CU-2026:8726-1: Recommended update of bci/dotnet-runtime Message-ID: <20260814092919.05517FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8726-1 Container Tags : bci/dotnet-runtime:8.0 , bci/dotnet-runtime:8.0-sles15 , bci/dotnet-runtime:8.0.29 , bci/dotnet-runtime:8.0.29-97.6 Container Release : 97.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:30:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:30:22 +0200 (CEST) Subject: SUSE-CU-2026:8728-1: Recommended update of bci/dotnet-runtime Message-ID: <20260814093022.55A5CFD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8728-1 Container Tags : bci/dotnet-runtime:9.0 , bci/dotnet-runtime:9.0-sles15 , bci/dotnet-runtime:9.0.18 , bci/dotnet-runtime:9.0.18-56.6 Container Release : 56.6 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:35:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:35:44 +0200 (CEST) Subject: SUSE-CU-2026:8734-1: Security update of bci/bci-init Message-ID: <20260814093544.E1140FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8734-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.29 , bci/bci-init:latest Container Release : 53.29 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - gzip-1.10-150200.16.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:35:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:35:46 +0200 (CEST) Subject: SUSE-CU-2026:8735-1: Security update of bci/bci-init Message-ID: <20260814093546.9CB1CFDC9@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8735-1 Container Tags : bci/bci-init:15.7 , bci/bci-init:15.7-53.30 , bci/bci-init:latest Container Release : 53.30 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:36:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:36:52 +0200 (CEST) Subject: SUSE-CU-2026:8736-1: Security update of suse/kea Message-ID: <20260814093652.0521AFD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8736-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.7 Container Release : 79.7 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:38:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:38:22 +0200 (CEST) Subject: SUSE-CU-2026:8737-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260814093822.70E95FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8737-1 Container Tags : suse/kiosk/firefox-esr:140.13 , suse/kiosk/firefox-esr:140.13-75.9 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.9 Severity : important Type : security References : 1266304 1268349 1268595 1269490 1271351 1271352 1271354 1271372 1272752 1272754 1272758 1272765 1272768 CVE-2026-12087 CVE-2026-12706 CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-57432 CVE-2026-64830 CVE-2026-64832 CVE-2026-64835 CVE-2026-66038 CVE-2026-66039 CVE-2026-8376 CVE-2026-8461 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3455-1 Released: Mon Aug 3 13:46:45 2026 Summary: Security update for gawk Type: security Severity: moderate References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553 This update for gawk fixes the following issues: - CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). - CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). - CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3542-1 Released: Mon Aug 10 14:50:21 2026 Summary: Security update for ffmpeg-4 Type: security Severity: important References: 1268595,1269490,1272752,1272754,1272758,1272765,1272768,CVE-2026-12706,CVE-2026-64830,CVE-2026-64832,CVE-2026-64835,CVE-2026-66038,CVE-2026-66039,CVE-2026-8461 This update for ffmpeg-4 fixes the following issues: Update to release 4.4.8. - CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution (bsc#1269490). - CVE-2026-12706: heap use-after-free read in the RASC video decoder can lead to denial of service (bsc#1268595). - CVE-2026-64830: heap buffer overflow in the VobSub subtitle demuxer can lead to arbitrary code execution (bsc#1272752). - CVE-2026-64832: double-free in the NVIDIA NVDEC hardware decoder can lead to can lead to memory corruption (bsc#1272754). - CVE-2026-64835: out-of-bounds memory access in the ADX audio decoder can lead to information disclosure and memory corruption (bsc#1272758). - CVE-2026-66038: exposure of uninitialized heap memory by the LCL/ZLIB video decoder can lead to sensitive information disclosure (bsc#1272768). - CVE-2026-66039: signed integer overflow in the MACE6 audio decoder can lead to heap corruption and arbitrary code execution (bsc#1272765). Other updates and bugfixes: - Release 4.4.8 * Various bug fixes to codecs * avcodec/magicyuv: Fix 1 line MEDIAN slices * avcodec/magicyuv: Expand the s->interlaced slice-height sanity check * avcodec/magicyuv: reject slice_height misaligned with chroma vshift ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - perl-5.26.1-150300.17.23.1 updated - gawk-4.2.1-150000.3.6.1 updated - libavutil56_70-4.4.8-150600.13.52.1 updated - libswresample3_9-4.4.8-150600.13.52.1 updated - libavcodec58_134-4.4.8-150600.13.52.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:38:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:38:55 +0200 (CEST) Subject: SUSE-CU-2026:8738-1: Security update of bci/bci-minimal Message-ID: <20260814093855.40096FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8738-1 Container Tags : bci/bci-minimal:15.7 , bci/bci-minimal:15.7-26.34 , bci/bci-minimal:latest Container Release : 26.34 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:38:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:38:59 +0200 (CEST) Subject: SUSE-CU-2026:8739-1: Recommended update of bci/bci-nano Message-ID: <20260814093859.E4B32FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-nano ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8739-1 Container Tags : bci/bci-nano:15.7 , bci/bci-nano:15.7-11.15 Container Release : 11.15 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/bci-nano was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:40:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:40:05 +0200 (CEST) Subject: SUSE-CU-2026:8740-1: Recommended update of bci/nodejs Message-ID: <20260814094005.33611FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8740-1 Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.30 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.30 Container Release : 24.30 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:41:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:41:21 +0200 (CEST) Subject: SUSE-CU-2026:8741-1: Security update of bci/openjdk-devel Message-ID: <20260814094121.AE727FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8741-1 Container Tags : bci/openjdk-devel:17 , bci/openjdk-devel:17-sles15 , bci/openjdk-devel:17.0.20.0 , bci/openjdk-devel:17.0.20.0-21.36 Container Release : 21.36 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:bci-openjdk-17-15.7.17-20.31 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:43:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:43:44 +0200 (CEST) Subject: SUSE-CU-2026:8743-1: Security update of bci/openjdk-devel Message-ID: <20260814094344.AB565FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8743-1 Container Tags : bci/openjdk-devel:21 , bci/openjdk-devel:21-sles15 , bci/openjdk-devel:21.0.12.0 , bci/openjdk-devel:21.0.12.0-25.36 Container Release : 25.36 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:bci-openjdk-21-15.7.21-24.30 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:45:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:45:46 +0200 (CEST) Subject: SUSE-CU-2026:8745-1: Security update of bci/openjdk-devel Message-ID: <20260814094546.AD459FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/openjdk-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8745-1 Container Tags : bci/openjdk-devel:25 , bci/openjdk-devel:25-sles15 , bci/openjdk-devel:25.0.4.0 , bci/openjdk-devel:25.0.4.0-9.37 , bci/openjdk-devel:latest Container Release : 9.37 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/openjdk-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - container:bci-openjdk-25-15.7.25-9.30 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:47:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:47:43 +0200 (CEST) Subject: SUSE-CU-2026:8747-1: Recommended update of bci/php-apache Message-ID: <20260814094743.DA3B0FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8747-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-25.8 , bci/php-apache:latest Container Release : 25.8 Severity : moderate Type : recommended References : 1271729 ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3568-1 Released: Tue Aug 11 08:33:00 2026 Summary: Recommended update for php-composer2 Type: recommended Severity: moderate References: 1271729 This update for php-composer2 fixes the following issues: - Fix: php-composer2 2.8.9 /usr/bin/composer2 phar has byte-swapped signature on s390x 'broken or unsupported signature', composer2 unusable (bsc#1271729): * fix a regression on s390x due to the last change The following package changes have been done: - php-composer2-2.6.4-150600.3.15.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:47:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:47:45 +0200 (CEST) Subject: SUSE-CU-2026:8748-1: Recommended update of bci/php-apache Message-ID: <20260814094745.15042FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/php-apache ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8748-1 Container Tags : bci/php-apache:8 , bci/php-apache:8-sles15 , bci/php-apache:8.3.33 , bci/php-apache:8.3.33-25.9 , bci/php-apache:latest Container Release : 25.9 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/php-apache was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:48:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:48:47 +0200 (CEST) Subject: SUSE-CU-2026:8749-1: Recommended update of bci/php-fpm Message-ID: <20260814094847.1C26EFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8749-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.33 , bci/php-fpm:8.3.33-25.8 , bci/php-fpm:latest Container Release : 25.8 Severity : moderate Type : recommended References : 1271729 ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3568-1 Released: Tue Aug 11 08:33:00 2026 Summary: Recommended update for php-composer2 Type: recommended Severity: moderate References: 1271729 This update for php-composer2 fixes the following issues: - Fix: php-composer2 2.8.9 /usr/bin/composer2 phar has byte-swapped signature on s390x 'broken or unsupported signature', composer2 unusable (bsc#1271729): * fix a regression on s390x due to the last change The following package changes have been done: - php-composer2-2.6.4-150600.3.15.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:48:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:48:48 +0200 (CEST) Subject: SUSE-CU-2026:8750-1: Recommended update of bci/php-fpm Message-ID: <20260814094848.28E2DFD94@maintenance.suse.de> SUSE Container Update Advisory: bci/php-fpm ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8750-1 Container Tags : bci/php-fpm:8 , bci/php-fpm:8-sles15 , bci/php-fpm:8.3.33 , bci/php-fpm:8.3.33-25.9 , bci/php-fpm:latest Container Release : 25.9 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/php-fpm was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:49:45 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:49:45 +0200 (CEST) Subject: SUSE-CU-2026:8751-1: Recommended update of bci/php Message-ID: <20260814094945.EABC7FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8751-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.33 , bci/php:8.3.33-25.8 , bci/php:latest Container Release : 25.8 Severity : moderate Type : recommended References : 1271729 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3568-1 Released: Tue Aug 11 08:33:00 2026 Summary: Recommended update for php-composer2 Type: recommended Severity: moderate References: 1271729 This update for php-composer2 fixes the following issues: - Fix: php-composer2 2.8.9 /usr/bin/composer2 phar has byte-swapped signature on s390x 'broken or unsupported signature', composer2 unusable (bsc#1271729): * fix a regression on s390x due to the last change The following package changes have been done: - php-composer2-2.6.4-150600.3.15.1 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:49:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:49:47 +0200 (CEST) Subject: SUSE-CU-2026:8752-1: Recommended update of bci/php Message-ID: <20260814094947.0C6FCFD94@maintenance.suse.de> SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8752-1 Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.33 , bci/php:8.3.33-25.9 , bci/php:latest Container Release : 25.9 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - container:bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Fri Aug 14 09:50:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 14 Aug 2026 11:50:38 +0200 (CEST) Subject: SUSE-CU-2026:8753-1: Security update of suse/postgres Message-ID: <20260814095038.6833DFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8753-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.8 Container Release : 93.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:08:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:08:49 +0200 (CEST) Subject: SUSE-IU-2026:6320-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260815070849.7CECAFD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6320-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.96 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.96 Severity : important Type : security References : 1268352 1268353 CVE-2026-44943 CVE-2026-44944 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1458 Released: Fri Aug 14 08:41:35 2026 Summary: Security update for open-iscsi Type: security Severity: important References: 1268352,1268353,CVE-2026-44943,CVE-2026-44944 This update for open-iscsi fixes the following issues: Update to version 2.1.12.suse+0.8f77cf16: - CVE-2026-44943: improper limitation of pathname to a restricted directory allows remote MITM attackers to create root-owned files outside the database and inject lines into records (bsc#1268353). - CVE-2026-44944: incorrect authorization allows unpriviledged local users to use the `isscsiuio` control socket (bsc#1268352). Changes for open-iscsi: - Version 2.1.12.suse+0.8f77cf16: * Fix security issues recently discovered by Keith at Linneman Labs. * iscsi-init.service: use `iscsi-gen-initiatorname`. * iscsi-gen-initiatorname: use `@IQN_PREFIX@` as default. * Avoid possible double free of found in `idbm_rec_update_param`. * iscsi: validate interface IP against target address family. The following package changes have been done: - libopeniscsiusr0-0.2.0-160000.4.1 updated - open-iscsi-2.1.12-160000.4.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:32:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:32:08 +0200 (CEST) Subject: SUSE-CU-2026:8753-1: Security update of suse/postgres Message-ID: <20260815073208.05870FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8753-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.8 Container Release : 93.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:32:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:32:09 +0200 (CEST) Subject: SUSE-CU-2026:8754-1: Security update of suse/postgres Message-ID: <20260815073209.89B94FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8754-1 Container Tags : suse/postgres:16-contrib , suse/postgres:16.14 , suse/postgres:16.14-contrib , suse/postgres:16.14-contrib-93.9 Container Release : 93.9 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - gzip-1.10-150200.16.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:32:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:32:34 +0200 (CEST) Subject: SUSE-CU-2026:8755-1: Security update of suse/postgres Message-ID: <20260815073234.F165CFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8755-1 Container Tags : suse/postgres:16 , suse/postgres:16.14 , suse/postgres:16.14 , suse/postgres:16.14-93.9 Container Release : 93.9 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - gzip-1.10-150200.16.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:33:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:33:24 +0200 (CEST) Subject: SUSE-CU-2026:8756-1: Security update of suse/postgres Message-ID: <20260815073324.56BA6FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8756-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.8 Container Release : 83.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:33:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:33:26 +0200 (CEST) Subject: SUSE-CU-2026:8757-1: Security update of suse/postgres Message-ID: <20260815073326.053B1FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8757-1 Container Tags : suse/postgres:17-contrib , suse/postgres:17.10 , suse/postgres:17.10-contrib , suse/postgres:17.10-contrib-83.9 Container Release : 83.9 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - gzip-1.10-150200.16.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:33:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:33:49 +0200 (CEST) Subject: SUSE-CU-2026:8758-1: Security update of suse/postgres Message-ID: <20260815073349.56159FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8758-1 Container Tags : suse/postgres:17 , suse/postgres:17.10 , suse/postgres:17.10 , suse/postgres:17.10-83.9 Container Release : 83.9 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - gzip-1.10-150200.16.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:34:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:34:24 +0200 (CEST) Subject: SUSE-CU-2026:8759-1: Security update of suse/postgres Message-ID: <20260815073424.4BDC4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8759-1 Container Tags : suse/postgres:18-contrib , suse/postgres:18.4 , suse/postgres:18.4-contrib , suse/postgres:18.4-contrib-73.9 , suse/postgres:latest Container Release : 73.9 Severity : important Type : security References : 1266304 1268349 1269623 1271372 1271712 1272554 CVE-2026-12087 CVE-2026-41992 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated - gzip-1.10-150200.16.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:34:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:34:42 +0200 (CEST) Subject: SUSE-CU-2026:8760-1: Security update of suse/postgres Message-ID: <20260815073442.D0966FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/postgres ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8760-1 Container Tags : suse/postgres:18 , suse/postgres:18.4 , suse/postgres:18.4 , suse/postgres:18.4-73.9 , suse/postgres:latest Container Release : 73.9 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container suse/postgres was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - gzip-1.10-150200.16.1 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:35:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:35:43 +0200 (CEST) Subject: SUSE-CU-2026:8761-1: Security update of suse/kiosk/pulseaudio Message-ID: <20260815073543.72653FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/pulseaudio ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8761-1 Container Tags : suse/kiosk/pulseaudio:17 , suse/kiosk/pulseaudio:17.0 , suse/kiosk/pulseaudio:17.0-73.11 , suse/kiosk/pulseaudio:latest Container Release : 73.11 Severity : important Type : security References : 1240054 1266304 1268349 1269584 1269623 1271372 1271712 1272554 CVE-2026-12087 CVE-2026-41992 CVE-2026-44605 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/kiosk/pulseaudio was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3493-1 Released: Tue Aug 4 14:11:00 2026 Summary: Security update for libpng16 Type: security Severity: important References: This update for libpng16 fixes the following issues: Changes for libpng16: - version update to 1.6.58 (jsc#PED-16190). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libpng16-16-1.6.58-150600.3.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - gzip-1.10-150200.16.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated - container:suse-sle15-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:36:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:36:48 +0200 (CEST) Subject: SUSE-CU-2026:8762-1: Security update of bci/python Message-ID: <20260815073648.3D9A3FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8762-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.31 Container Release : 85.31 Severity : important Type : security References : 1264962 1265268 1267581 1267821 1268375 1268977 1269066 1269788 1269959 1271192 1273090 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-13346 CVE-2026-15308 CVE-2026-3276 CVE-2026-4360 CVE-2026-7210 CVE-2026-7774 CVE-2026-8328 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3560-1 Released: Mon Aug 10 20:09:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issue fixed: - [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3589-1 Released: Tue Aug 11 16:57:03 2026 Summary: Security update for python-pip Type: security Severity: moderate References: 1273090,CVE-2026-13346 This update for python-pip fixes the following issue: - CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed to arbitrary locations on disk (bsc#1273090). The following package changes have been done: - libpython3_11-1_0-3.11.15-150600.3.62.2 updated - python311-base-3.11.15-150600.3.62.2 updated - python311-pip-22.3.1-150400.17.29.1 updated - python311-3.11.15-150600.3.62.2 updated - python311-devel-3.11.15-150600.3.62.2 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:39:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:39:02 +0200 (CEST) Subject: SUSE-CU-2026:8765-1: Security update of bci/python Message-ID: <20260815073902.40D3EFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8765-1 Container Tags : bci/python:3 , bci/python:3.6 , bci/python:3.6.15 , bci/python:3.6.15-84.27 Container Release : 84.27 Severity : moderate Type : security References : 1271712 1273090 CVE-2026-13346 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3588-1 Released: Tue Aug 11 16:56:34 2026 Summary: Security update for python3-pip Type: security Severity: moderate References: 1273090,CVE-2026-13346 This update for python3-pip fixes the following issue: - CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed to arbitrary locations on disk (bsc#1273090). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated - python3-pip-20.0.2-150400.26.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:39:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:39:43 +0200 (CEST) Subject: SUSE-CU-2026:8767-1: Security update of suse/mariadb Message-ID: <20260815073943.9093BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/mariadb ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8767-1 Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.10 , suse/mariadb:latest Container Release : 79.10 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/mariadb was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:40:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:40:39 +0200 (CEST) Subject: SUSE-CU-2026:8768-1: Security update of suse/rmt-server Message-ID: <20260815074039.E4A6EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/rmt-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8768-1 Container Tags : suse/rmt-server:2 , suse/rmt-server:2.28 , suse/rmt-server:2.28-88.7 , suse/rmt-server:latest Container Release : 88.7 Severity : important Type : security References : 1262441 1271712 CVE-2026-41316 ----------------------------------------------------------------- The container suse/rmt-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3556-1 Released: Mon Aug 10 19:56:42 2026 Summary: Security update for ruby2.5 Type: security Severity: important References: 1262441,CVE-2026-41316 This update for ruby2.5 fixes the following issue - CVE-2026-41316: erb: @_init deserialization guard bypass via def_module / def_method / def_class (bsc#1262441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated - libruby2_5-2_5-2.5.9-150700.24.11.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - ruby2.5-stdlib-2.5.9-150700.24.11.1 updated - ruby2.5-2.5.9-150700.24.11.1 updated - container:suse-sle15-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:41:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:41:42 +0200 (CEST) Subject: SUSE-CU-2026:8769-1: Security update of bci/ruby Message-ID: <20260815074142.779B3FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8769-1 Container Tags : bci/ruby:2 , bci/ruby:2.5 , bci/ruby:2.5-26.30 , bci/ruby:2.5-sles15 Container Release : 26.30 Severity : important Type : security References : 1262441 1271712 CVE-2026-41316 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3556-1 Released: Mon Aug 10 19:56:42 2026 Summary: Security update for ruby2.5 Type: security Severity: important References: 1262441,CVE-2026-41316 This update for ruby2.5 fixes the following issue - CVE-2026-41316: erb: @_init deserialization guard bypass via def_module / def_method / def_class (bsc#1262441). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated - libruby2_5-2_5-2.5.9-150700.24.11.1 updated - timezone-2026c-150600.91.12.1 updated - ruby2.5-stdlib-2.5.9-150700.24.11.1 updated - ruby2.5-2.5.9-150700.24.11.1 updated - ruby2.5-devel-2.5.9-150700.24.11.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:42:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:42:50 +0200 (CEST) Subject: SUSE-CU-2026:8771-1: Recommended update of bci/ruby Message-ID: <20260815074250.9F585FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8771-1 Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.29 , bci/ruby:3.4-sles15 , bci/ruby:latest Container Release : 25.29 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150600.91.12.1 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:43:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:43:36 +0200 (CEST) Subject: SUSE-CU-2026:8773-1: Security update of bci/rust Message-ID: <20260815074336.F15F1FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8773-1 Container Tags : bci/rust:1.96 , bci/rust:1.96-sles15 , bci/rust:1.96.1 , bci/rust:1.96.1-2.2.7 , bci/rust:oldstable Container Release : 2.7 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:44:43 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:44:43 +0200 (CEST) Subject: SUSE-CU-2026:8775-1: Security update of bci/rust Message-ID: <20260815074443.316EFFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/rust ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8775-1 Container Tags : bci/rust:1.97 , bci/rust:1.97-sles15 , bci/rust:1.97.1 , bci/rust:1.97.1-1.2.7 , bci/rust:latest , bci/rust:stable Container Release : 2.7 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container bci/rust was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:45:47 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:45:47 +0200 (CEST) Subject: SUSE-CU-2026:8777-1: Security update of suse/samba-client Message-ID: <20260815074547.026B2FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8777-1 Container Tags : suse/samba-client:4.21 , suse/samba-client:4.21 , suse/samba-client:4.21-75.8 , suse/samba-client:latest Container Release : 75.8 Severity : moderate Type : security References : 1271712 ----------------------------------------------------------------- The container suse/samba-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:46:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:46:51 +0200 (CEST) Subject: SUSE-CU-2026:8778-1: Security update of suse/samba-server Message-ID: <20260815074651.55873FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-server ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8778-1 Container Tags : suse/samba-server:4.21 , suse/samba-server:4.21 , suse/samba-server:4.21-76.8 , suse/samba-server:latest Container Release : 76.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/samba-server was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated From sle-container-updates at lists.suse.com Sat Aug 15 07:47:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 15 Aug 2026 09:47:42 +0200 (CEST) Subject: SUSE-CU-2026:8779-1: Security update of suse/samba-toolbox Message-ID: <20260815074742.D3AB8FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8779-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.8 , suse/samba-toolbox:latest Container Release : 76.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:34:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:34:35 +0200 (CEST) Subject: SUSE-CU-2026:8779-1: Security update of suse/samba-toolbox Message-ID: <20260816073435.D4047FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/samba-toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8779-1 Container Tags : suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21 , suse/samba-toolbox:4.21-76.8 , suse/samba-toolbox:latest Container Release : 76.8 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/samba-toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - container:suse-sle15-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:36:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:36:34 +0200 (CEST) Subject: SUSE-CU-2026:8780-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260816073634.18392FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8780-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.40 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.40 Severity : important Type : security References : 1240054 1269584 1271712 CVE-2026-44605 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated - rpm-build-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:36:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:36:36 +0200 (CEST) Subject: SUSE-CU-2026:8781-1: Security update of bci/bci-sle15-kernel-module-devel Message-ID: <20260816073636.2E0E7FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8781-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.7 , bci/bci-sle15-kernel-module-devel:15.7-60.41 , bci/bci-sle15-kernel-module-devel:latest Container Release : 60.41 Severity : important Type : security References : 1266304 1268349 1269623 1271372 1272554 CVE-2026-12087 CVE-2026-41992 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - gzip-1.10-150200.16.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:38:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:38:03 +0200 (CEST) Subject: SUSE-CU-2026:8782-1: Security update of suse/sle15 Message-ID: <20260816073803.8A0C7FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8782-1 Container Tags : bci/bci-base:15.7 , bci/bci-base:15.7-5.23.9 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.23.9 , suse/sle15:latest Container Release : 5.23.9 Severity : important Type : security References : 1240054 1266304 1268349 1269584 1269623 1271372 1272554 CVE-2026-12087 CVE-2026-41992 CVE-2026-44605 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - perl-base-5.26.1-150300.17.23.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated - timezone-2026c-150600.91.12.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:40:39 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:40:39 +0200 (CEST) Subject: SUSE-CU-2026:8783-1: Security update of bci/spack Message-ID: <20260816074039.F3BB7FD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8783-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.34 , bci/spack:latest Container Release : 25.34 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:40:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:40:42 +0200 (CEST) Subject: SUSE-CU-2026:8784-1: Security update of bci/spack Message-ID: <20260816074042.02BB8FD94@maintenance.suse.de> SUSE Container Update Advisory: bci/spack ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8784-1 Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.36 , bci/spack:latest Container Release : 25.36 Severity : moderate Type : security References : 1269623 1272554 CVE-2026-41992 ----------------------------------------------------------------- The container bci/spack was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - gzip-1.10-150200.16.1 updated - container:registry.suse.com-bci-bci-base-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:40:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:40:50 +0200 (CEST) Subject: SUSE-CU-2026:8785-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260816074050.8E6ACFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8785-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.10 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.10 Severity : important Type : security References : 1266304 1268349 1271372 1271712 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3578-1 Released: Tue Aug 11 15:58:41 2026 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1271712 This update for openssl-1_1 fixes the following issues: - HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations (bsc#1271712). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - libopenssl1_1-1.1.1w-150700.11.25.2 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:40:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:40:52 +0200 (CEST) Subject: SUSE-CU-2026:8786-1: Security update of suse/kiosk/tigervnc-x11vnc Message-ID: <20260816074052.39094FD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/tigervnc-x11vnc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8786-1 Container Tags : suse/kiosk/tigervnc-x11vnc:1 , suse/kiosk/tigervnc-x11vnc:1.14 , suse/kiosk/tigervnc-x11vnc:1.14-63.12 , suse/kiosk/tigervnc-x11vnc:latest Container Release : 63.12 Severity : important Type : security References : 1240054 1269584 1269623 1272554 CVE-2026-41992 CVE-2026-44605 ----------------------------------------------------------------- The container suse/kiosk/tigervnc-x11vnc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:42:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:42:11 +0200 (CEST) Subject: SUSE-CU-2026:8787-1: Security update of suse/kiosk/xorg-client Message-ID: <20260816074211.16F8DFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg-client ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8787-1 Container Tags : suse/kiosk/xorg-client:21 , suse/kiosk/xorg-client:21-79.8 , suse/kiosk/xorg-client:latest Container Release : 79.8 Severity : important Type : security References : 1266304 1268349 1268595 1269490 1271372 1272752 1272754 1272758 1272765 1272768 CVE-2026-12087 CVE-2026-12706 CVE-2026-57432 CVE-2026-64830 CVE-2026-64832 CVE-2026-64835 CVE-2026-66038 CVE-2026-66039 CVE-2026-8376 CVE-2026-8461 ----------------------------------------------------------------- The container suse/kiosk/xorg-client was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3542-1 Released: Mon Aug 10 14:50:21 2026 Summary: Security update for ffmpeg-4 Type: security Severity: important References: 1268595,1269490,1272752,1272754,1272758,1272765,1272768,CVE-2026-12706,CVE-2026-64830,CVE-2026-64832,CVE-2026-64835,CVE-2026-66038,CVE-2026-66039,CVE-2026-8461 This update for ffmpeg-4 fixes the following issues: Update to release 4.4.8. - CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution (bsc#1269490). - CVE-2026-12706: heap use-after-free read in the RASC video decoder can lead to denial of service (bsc#1268595). - CVE-2026-64830: heap buffer overflow in the VobSub subtitle demuxer can lead to arbitrary code execution (bsc#1272752). - CVE-2026-64832: double-free in the NVIDIA NVDEC hardware decoder can lead to can lead to memory corruption (bsc#1272754). - CVE-2026-64835: out-of-bounds memory access in the ADX audio decoder can lead to information disclosure and memory corruption (bsc#1272758). - CVE-2026-66038: exposure of uninitialized heap memory by the LCL/ZLIB video decoder can lead to sensitive information disclosure (bsc#1272768). - CVE-2026-66039: signed integer overflow in the MACE6 audio decoder can lead to heap corruption and arbitrary code execution (bsc#1272765). Other updates and bugfixes: - Release 4.4.8 * Various bug fixes to codecs * avcodec/magicyuv: Fix 1 line MEDIAN slices * avcodec/magicyuv: Expand the s->interlaced slice-height sanity check * avcodec/magicyuv: reject slice_height misaligned with chroma vshift ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated - libavutil56_70-4.4.8-150600.13.52.1 updated - libswresample3_9-4.4.8-150600.13.52.1 updated - libavcodec58_134-4.4.8-150600.13.52.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:44:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:44:02 +0200 (CEST) Subject: SUSE-CU-2026:8788-1: Security update of suse/kiosk/xorg Message-ID: <20260816074402.BEE4DFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8788-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.8 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.8 Severity : important Type : security References : 1266304 1268349 1271372 CVE-2026-12087 CVE-2026-57432 CVE-2026-8376 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3558-1 Released: Mon Aug 10 20:01:21 2026 Summary: Security update for perl Type: security Severity: important References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376 This update for perl fixes the following issues: - CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds (bsc#1266304). - CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure (bsc#1268349). - CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack` (bsc#1271372). The following package changes have been done: - perl-base-5.26.1-150300.17.23.1 updated - perl-5.26.1-150300.17.23.1 updated From sle-container-updates at lists.suse.com Sun Aug 16 07:44:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 09:44:04 +0200 (CEST) Subject: SUSE-CU-2026:8789-1: Security update of suse/kiosk/xorg Message-ID: <20260816074404.8FEBEFD94@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/xorg ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8789-1 Container Tags : suse/kiosk/xorg:21 , suse/kiosk/xorg:21.1 , suse/kiosk/xorg:21.1-83.11 , suse/kiosk/xorg:latest , suse/kiosk/xorg:notaskbar Container Release : 83.11 Severity : important Type : security References : 1240054 1269584 1269623 1272554 CVE-2026-41992 CVE-2026-44605 ----------------------------------------------------------------- The container suse/kiosk/xorg was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3592-1 Released: Wed Aug 12 11:15:00 2026 Summary: Security update for gzip Type: security Severity: moderate References: 1269623,1272554,CVE-2026-41992 This update for gzip fixes the following issues: - CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623). - Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - gzip-1.10-150200.16.1 updated - rpm-ndb-4.14.3-150400.59.19.1 updated - container:suse-sle15-15.7-cf4c66d3369e1cf8626eac5ede03500dbc2d4b9d48db2ffa77a09d3d4ca82254-0 updated From sle-container-updates at lists.suse.com Sun Aug 16 08:02:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 10:02:02 +0200 (CEST) Subject: SUSE-CU-2026:8846-1: Security update of suse/manager/4.3/proxy-httpd Message-ID: <20260816080202.B0238FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8846-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.19 , suse/manager/4.3/proxy-httpd:4.3.19.9.82.21 , suse/manager/4.3/proxy-httpd:latest Container Release : 9.82.21 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - python3-rpm-4.14.3-150400.59.19.1 updated - container:sles15-ltss-image-15.4.0-6.41 updated From sle-container-updates at lists.suse.com Sun Aug 16 08:04:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sun, 16 Aug 2026 10:04:11 +0200 (CEST) Subject: SUSE-CU-2026:8848-1: Recommended update of suse/manager/4.3/proxy-salt-broker Message-ID: <20260816080411.57053FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8848-1 Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.25 , suse/manager/4.3/proxy-salt-broker:latest Container Release : 9.72.25 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3583-1 Released: Tue Aug 11 16:36:37 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. The following package changes have been done: - timezone-2026c-150000.75.40.1 updated - container:sles15-ltss-image-15.4.0-6.41 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:07:17 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:07:17 +0200 (CEST) Subject: SUSE-IU-2026:6326-1: Security update of suse/sle-micro/base-5.5 Message-ID: <20260818070717.7798DFD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/base-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6326-1 Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.308 , suse/sle-micro/base-5.5:latest Image Release : 5.8.308 Severity : important Type : security References : 1264514 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 CVE-2026-41035 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 ----------------------------------------------------------------- The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3634-1 Released: Mon Aug 17 21:03:13 2026 Summary: Security update for rsync Type: security Severity: important References: 1264514,1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-41035,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). The following package changes have been done: - rsync-3.2.3-150400.3.34.1 updated - openslp-2.0.0-150000.6.17.1 removed From sle-container-updates at lists.suse.com Tue Aug 18 07:10:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:10:00 +0200 (CEST) Subject: SUSE-IU-2026:6327-1: Security update of suse/sle-micro/kvm-5.5 Message-ID: <20260818071000.BC186FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/kvm-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6327-1 Image Tags : suse/sle-micro/kvm-5.5:2.0.4 , suse/sle-micro/kvm-5.5:2.0.4-3.5.593 , suse/sle-micro/kvm-5.5:latest Image Release : 3.5.593 Severity : important Type : security References : 1264514 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 CVE-2026-41035 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 ----------------------------------------------------------------- The container suse/sle-micro/kvm-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3634-1 Released: Mon Aug 17 21:03:13 2026 Summary: Security update for rsync Type: security Severity: important References: 1264514,1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-41035,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). The following package changes have been done: - rsync-3.2.3-150400.3.34.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.308 updated - openslp-2.0.0-150000.6.17.1 removed From sle-container-updates at lists.suse.com Tue Aug 18 07:17:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:17:51 +0200 (CEST) Subject: SUSE-IU-2026:6329-1: Security update of suse/sle-micro/5.5 Message-ID: <20260818071751.D94AAFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6329-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.90 , suse/sle-micro/5.5:latest Image Release : 5.8.90 Severity : important Type : security References : 1264514 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 CVE-2026-41035 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3634-1 Released: Mon Aug 17 21:03:13 2026 Summary: Security update for rsync Type: security Severity: important References: 1264514,1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-41035,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). The following package changes have been done: - rsync-3.2.3-150400.3.34.1 updated - container:suse-sle-micro-base-5.5-latest-2.0.4-5.8.308 updated - openslp-2.0.0-150000.6.17.1 removed From sle-container-updates at lists.suse.com Tue Aug 18 07:14:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:14:19 +0200 (CEST) Subject: SUSE-IU-2026:6328-1: Security update of suse/sle-micro/rt-5.5 Message-ID: <20260818071419.69AA3FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/rt-5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6328-1 Image Tags : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.694 , suse/sle-micro/rt-5.5:latest Image Release : 4.5.694 Severity : important Type : security References : 1264514 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 CVE-2026-41035 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 ----------------------------------------------------------------- The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3634-1 Released: Mon Aug 17 21:03:13 2026 Summary: Security update for rsync Type: security Severity: important References: 1264514,1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-41035,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). The following package changes have been done: - rsync-3.2.3-150400.3.34.1 updated - container:suse-sle-micro-5.5-latest-2.0.4-5.8.90 updated - openslp-2.0.0-150000.6.17.1 removed From sle-container-updates at lists.suse.com Tue Aug 18 07:36:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:36:03 +0200 (CEST) Subject: SUSE-CU-2026:8859-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260818073603.BB056FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8859-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.171 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.171 Severity : important Type : security References : 1264514 1269039 1269040 1269041 1269042 1269043 1269044 1269045 1269046 1269047 1269048 1269049 1269050 1269051 1269052 1269053 1269054 1269055 1269056 1269057 1269058 1269060 1273429 1273430 1273431 1273432 1273433 1273434 1273435 1273436 1273437 1273438 1273439 1273440 1273441 CVE-2026-41035 CVE-2026-53783 CVE-2026-53784 CVE-2026-53785 CVE-2026-53786 CVE-2026-53788 CVE-2026-53789 CVE-2026-53790 CVE-2026-53791 CVE-2026-53792 CVE-2026-53793 CVE-2026-53794 CVE-2026-53795 CVE-2026-53796 CVE-2026-53797 CVE-2026-53798 CVE-2026-53799 CVE-2026-53800 CVE-2026-53801 CVE-2026-53802 CVE-2026-53803 CVE-2026-70452 CVE-2026-70453 CVE-2026-70454 CVE-2026-70455 CVE-2026-70456 CVE-2026-70457 CVE-2026-70458 CVE-2026-70459 CVE-2026-70460 CVE-2026-70461 CVE-2026-70462 CVE-2026-70463 CVE-2026-70464 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3634-1 Released: Mon Aug 17 21:03:13 2026 Summary: Security update for rsync Type: security Severity: important References: 1264514,1269039,1269040,1269041,1269042,1269043,1269044,1269045,1269046,1269047,1269048,1269049,1269050,1269051,1269052,1269053,1269054,1269055,1269056,1269057,1269058,1269060,1273429,1273430,1273431,1273432,1273433,1273434,1273435,1273436,1273437,1273438,1273439,1273440,1273441,CVE-2026-41035,CVE-2026-53783,CVE-2026-53784,CVE-2026-53785,CVE-2026-53786,CVE-2026-53788,CVE-2026-53789,CVE-2026-53790,CVE-2026-53791,CVE-2026-53792,CVE-2026-53793,CVE-2026-53794,CVE-2026-53795,CVE-2026-53796,CVE-2026-53797,CVE-2026-53798,CVE-2026-53799,CVE-2026-53800,CVE-2026-53801,CVE-2026-53802,CVE-2026-53803,CVE-2026-70452,CVE-2026-70453,CVE-2026-70454,CVE-2026-70455,CVE-2026-70456,CVE-2026-70457,CVE-2026-70458,CVE-2026-70459,CVE-2026-70460,CVE-2026-70461,CVE-2026-70462,CVE-2026-70463,CVE-2026-70464 This update for rsync fixes the following issues: - CVE-2026-53783: rrsync restricted-directory escape (validation-vs-exec race + unsafe option allowlist) (bsc#1269041). - CVE-2026-53784: Daemon module-root chdir escape under 'use chroot = no' (bsc#1269042). - CVE-2026-53785: --relative implied-parent creation escapes the destination tree (bsc#1269043). - CVE-2026-53786: Daemon --filter merge file bypasses the module filter list (bsc#1269044). - CVE-2026-53788: Daemon name-converter accepts newline-bearing names into its line protocol (bsc#1269046). - CVE-2026-53789: Malicious sender expands --delete scope by reclassifying an implied parent (bsc#1269047). - CVE-2026-53790: Command / argument injection via unquoted peer- or host-controlled values (bsc#1269048). - CVE-2026-53791: PROXY-protocol mode lets a direct client spoof the daemon's source address (bsc#1269049). - CVE-2026-53792: Receiver-supplied zero checksum block length drives sender matching negative (bsc#1269050). - CVE-2026-53793: Chroot '/./' inner-module escape via a parent-component symlink (bsc#1269051). - CVE-2026-53794: Remote peer disables the per-allocation sanity cap via --max-alloc=0 (bsc#1269052). - CVE-2026-53795: Receiver write escape via an absolute --temp-dir / --link-dest disabling rename/link confinement (bsc#1269053). - CVE-2026-53796: Non-daemon receiver destination-chdir symlink race (TOCTOU) (bsc#1269054). - CVE-2026-53797: Sender source-tree parent-component symlink race -> out-of-tree disclosure (bsc#1269055). - CVE-2026-53798: Daemon name-converter empty response maps an unknown name to uid/gid 0 (bsc#1269045). - CVE-2026-53799: Receiver ACL/xattr application follows a symlink-race -> arbitrary ACL set (local privilege escalation) (bsc#1269056). - CVE-2026-53800: Sender --remove-source-files unlink follows a parent-component symlink race -> arbitrary file deletion outside the source tree (bsc#1269057). - CVE-2026-53801: Sender/daemon directory-scan enumeration escapes the transfer root / module -> out-of-tree disclosure (bsc#1269058). - CVE-2026-53802: Arbitrary file read / transfer-shaping via symlinked operator-supplied input files (bsc#1269039). - CVE-2026-53803: Arbitrary file write / privilege escalation via symlinked operator-supplied output paths (bsc#1269040). - CVE-2026-70452: `hosts deny` fails OPEN when a configured hostname cannot be resolved, admitting the host it was meant to block (bsc#1273441). - CVE-2026-70453: Quadratic CPU exhaustion in hash_search() from a crafted equal-weak-checksum chain (bsc#1273440). - CVE-2026-70454: rsync-ssl establishes an unauthenticated TLS connection (bsc#1273439). - CVE-2026-70455: Peer-controlled Zstandard worker exhaustion on an rsync daemon (bsc#1273438). - CVE-2026-70456: Remote out-of-bounds heap write in read_args() when the argument count lands exactly on maxargs (bsc#1273437). - CVE-2026-70457: Attacker-chosen-offset write in parse_size_arg() error formatting (bsc#1273436). - CVE-2026-70458: Out-of-bounds write from a FLAG_HLINKED file entry accepted without -H (bsc#1273435). - CVE-2026-70459: Per-connection daemon child crash from a crafted first incremental file list with a non-directory transfer root (bsc#1273434). - CVE-2026-70460: Daemon module-root escape through a peer-supplied --partial-dir / --backup-dir resolving via an in- module symlink (bsc#1273433). - CVE-2026-70461: Peer-driven one-byte heap out-of-bounds write in add_implied_include() (bsc#1273432). - CVE-2026-70462: Peer-supplied MSG_IO_TIMEOUT defeats the client's own I/O timeout (bsc#1273431). - CVE-2026-70463: 'auth users' ignores documented comma-only parsing, silently skipping a deny/read-only rule (bsc#1273430). - CVE-2026-70464: Unauthenticated pre-transfer handshake DoS locks out an rsync daemon module (bsc#1273429). The following package changes have been done: - rsync-3.2.3-150400.3.34.1 updated - openslp-2.0.0-150000.6.17.1 removed From sle-container-updates at lists.suse.com Tue Aug 18 07:38:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:38:58 +0200 (CEST) Subject: SUSE-IU-2026:6330-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260818073858.CBBFBFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6330-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.227 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.227 Severity : important Type : security References : 1268579 1269471 1269584 CVE-2026-44605 CVE-2026-55686 CVE-2026-57231 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 845 Released: Mon Aug 17 21:48:21 2026 Summary: Security update for rpm Type: security Severity: important References: 1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). ----------------------------------------------------------------- Advisory ID: 846 Released: Mon Aug 17 21:56:54 2026 Summary: Security update for podman Type: security Severity: important References: 1268579,1269471,CVE-2026-55686,CVE-2026-57231 This update for podman fixes the following issues: - CVE-2026-55686: Podman: WORKDIR symlink traversal vulnerability (bsc#1268579). - CVE-2026-57231: specially crafted image can trick podman run into leaking host environment variables into the container (bsc#1269471). The following package changes have been done: - rpm-4.18.0-8.1 updated - SL-Micro-release-6.0-25.122 updated - podman-4.9.5-13.1 updated - container:SL-Micro-base-container-2.1.3-7.190 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:41:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:41:36 +0200 (CEST) Subject: SUSE-IU-2026:6331-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260818074136.A8216FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6331-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.190 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.190 Severity : important Type : security References : 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 845 Released: Mon Aug 17 21:48:21 2026 Summary: Security update for rpm Type: security Severity: important References: 1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - rpm-4.18.0-8.1 updated - SL-Micro-release-6.0-25.122 updated - container:suse-toolbox-image-1.0.0-9.150 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:44:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:44:13 +0200 (CEST) Subject: SUSE-IU-2026:6332-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260818074413.3C85FFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6332-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.200 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.200 Severity : important Type : security References : 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 845 Released: Mon Aug 17 21:48:21 2026 Summary: Security update for rpm Type: security Severity: important References: 1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - rpm-4.18.0-8.1 updated - SL-Micro-release-6.0-25.122 updated - container:SL-Micro-base-container-2.1.3-7.190 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:46:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:46:58 +0200 (CEST) Subject: SUSE-IU-2026:6333-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260818074658.0E1F3FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6333-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.220 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.220 Severity : important Type : security References : 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 845 Released: Mon Aug 17 21:48:21 2026 Summary: Security update for rpm Type: security Severity: important References: 1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - rpm-4.18.0-8.1 updated - SL-Micro-release-6.0-25.122 updated - container:SL-Micro-container-2.1.3-6.227 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:55:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:55:50 +0200 (CEST) Subject: SUSE-CU-2026:8864-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260818075550.8A65AFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8864-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.150 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.150 Severity : important Type : security References : 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 845 Released: Mon Aug 17 21:48:21 2026 Summary: Security update for rpm Type: security Severity: important References: 1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - SL-Micro-release-6.0-25.122 updated - rpm-4.18.0-8.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.121 updated From sle-container-updates at lists.suse.com Tue Aug 18 07:57:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 09:57:55 +0200 (CEST) Subject: SUSE-IU-2026:6334-1: Recommended update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260818075755.416EAFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6334-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.150 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.150 Severity : important Type : recommended References : 1229975 1257836 1258641 1268874 CVE-2026-25547 CVE-2026-26996 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 670 Released: Mon Aug 17 09:10:21 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1257836,1258641,1268874,CVE-2026-25547,CVE-2026-26996 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-slfo.1.1_2.1 updated - cryptsetup-2.6.1-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.166 updated From sle-container-updates at lists.suse.com Tue Aug 18 08:00:03 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 10:00:03 +0200 (CEST) Subject: SUSE-IU-2026:6335-1: Recommended update of suse/sl-micro/6.1/base-os-container Message-ID: <20260818080003.B4185FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6335-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.166 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.166 Severity : important Type : recommended References : 1229975 1257836 1258641 1268874 CVE-2026-25547 CVE-2026-26996 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 670 Released: Mon Aug 17 09:10:21 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1257836,1258641,1268874,CVE-2026-25547,CVE-2026-26996 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-slfo.1.1_2.1 updated From sle-container-updates at lists.suse.com Tue Aug 18 08:02:22 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 10:02:22 +0200 (CEST) Subject: SUSE-IU-2026:6336-1: Recommended update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260818080222.5F1B9FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6336-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.168 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.168 Severity : important Type : recommended References : 1229975 1257836 1258641 1268874 CVE-2026-25547 CVE-2026-26996 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 670 Released: Mon Aug 17 09:10:21 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1257836,1258641,1268874,CVE-2026-25547,CVE-2026-26996 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-slfo.1.1_2.1 updated - container:SL-Micro-base-container-2.2.1-5.166 updated From sle-container-updates at lists.suse.com Tue Aug 18 08:04:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 10:04:58 +0200 (CEST) Subject: SUSE-IU-2026:6337-1: Recommended update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260818080458.1AFB0FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6337-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.164 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.164 Severity : important Type : recommended References : 1229975 1257836 1258641 1268874 CVE-2026-25547 CVE-2026-26996 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 670 Released: Mon Aug 17 09:10:21 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1257836,1258641,1268874,CVE-2026-25547,CVE-2026-26996 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-slfo.1.1_2.1 updated - container:SL-Micro-container-2.2.1-7.150 updated From sle-container-updates at lists.suse.com Tue Aug 18 08:33:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Tue, 18 Aug 2026 10:33:42 +0200 (CEST) Subject: SUSE-CU-2026:8870-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260818083342.06EB3FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8870-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.83 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.83 , suse/ltss/sle15.6/sle15:latest Container Release : 5.83 Severity : important Type : security References : 1240054 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3582-1 Released: Tue Aug 11 16:35:48 2026 Summary: Recommended update for timezone Type: recommended Severity: moderate References: This update for timezone fixes the following issues: - Update to 2026c: * Alberta moved to permanent -06 on 2026-06-18. * Morocco moves to permanent +00 on 2026-09-20. * More integer overflow bugs have been fixed in zic. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3600-1 Released: Wed Aug 12 13:59:10 2026 Summary: Security update for rpm Type: security Severity: important References: 1240054,1269584,CVE-2026-44605 This update for rpm fixes the following issues: Security issues fixed: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). Other updates and bugfixes: - Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054). The following package changes have been done: - rpm-ndb-4.14.3-150400.59.19.1 updated - timezone-2026c-150600.91.12.1 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:24:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:24:12 +0200 (CEST) Subject: SUSE-IU-2026:6349-1: Recommended update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260819072412.83D1BFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6349-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.228 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.228 Severity : important Type : recommended References : 1229975 1268874 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 847 Released: Tue Aug 18 10:07:24 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1268874 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-5.1 updated - cryptsetup-2.6.1-5.1 updated - container:SL-Micro-base-container-2.1.3-7.191 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:27:09 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:27:09 +0200 (CEST) Subject: SUSE-IU-2026:6352-1: Recommended update of suse/sl-micro/6.0/base-os-container Message-ID: <20260819072709.3036BFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6352-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.191 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.191 Severity : important Type : recommended References : 1229975 1268874 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 847 Released: Tue Aug 18 10:07:24 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1268874 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-5.1 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:30:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:30:08 +0200 (CEST) Subject: SUSE-IU-2026:6355-1: Recommended update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260819073008.8DA8CFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6355-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.201 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.201 Severity : important Type : recommended References : 1229975 1268874 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 847 Released: Tue Aug 18 10:07:24 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1268874 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-5.1 updated - container:SL-Micro-base-container-2.1.3-7.191 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:33:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:33:19 +0200 (CEST) Subject: SUSE-IU-2026:6358-1: Recommended update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260819073319.6B122FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6358-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.221 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.221 Severity : important Type : recommended References : 1229975 1268874 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 847 Released: Tue Aug 18 10:07:24 2026 Summary: Recommended update for cryptsetup Type: recommended Severity: important References: 1229975,1268874 This update for cryptsetup fixes the following issues: - Extend the password for PBKDF2 benchmarking to be more than 20 chars to meet FIPS 140-3 requirements (bsc#1229975, bsc#1268874) The following package changes have been done: - libcryptsetup12-2.6.1-5.1 updated - container:SL-Micro-container-2.1.3-6.228 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:42:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:42:56 +0200 (CEST) Subject: SUSE-CU-2026:8904-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260819074256.F1A1BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8904-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.151 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.151 Severity : important Type : security References : 1258364 1261969 1262098 1262319 1262654 1263083 1264962 1265268 1267581 1267821 1268375 1268977 1269066 1269788 1269959 1271192 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-1502 CVE-2026-15308 CVE-2026-3276 CVE-2026-4360 CVE-2026-4786 CVE-2026-6019 CVE-2026-6100 CVE-2026-7210 CVE-2026-7774 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 853 Released: Tue Aug 18 13:57:55 2026 Summary: Security update for python311 Type: security Severity: important References: 1258364,1261969,1262098,1262319,1262654,1263083,1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319). - CVE-2026-6019: BaseCookie.js_output() does not neutralize embedded characters (bsc#1262654). - CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules (bsc#1262098). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issues fixed: - Regression in `http.cookies` (bsc#1263083). - udplite was removed -> python fails in tests (bsc#1268375). - Conflicts between different versions of Python (bsc#1258364). The following package changes have been done: - SL-Micro-release-6.0-25.123 updated - libpython3_11-1_0-3.11.15-5.1 updated - python311-base-3.11.15-5.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.122 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:45:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:45:04 +0200 (CEST) Subject: SUSE-IU-2026:6361-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260819074504.49A9CFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6361-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.151 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.151 Severity : important Type : security References : 1222465 1234736 1258364 1261809 1261969 1262098 1262319 1262654 1263083 1264962 1265268 1267581 1267821 1268375 1268977 1269066 1269788 1269959 1271192 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-1502 CVE-2026-15308 CVE-2026-3276 CVE-2026-4360 CVE-2026-4786 CVE-2026-4878 CVE-2026-6019 CVE-2026-6100 CVE-2026-7210 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 CVE-2026-7774 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 675 Released: Tue Aug 18 12:45:35 2026 Summary: Security update for vim Type: security Severity: important References: 1261809,1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-4878,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: Updated to version 9.2.0957. - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Version 9.2.0957: * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). ----------------------------------------------------------------- Advisory ID: 676 Released: Tue Aug 18 13:41:50 2026 Summary: Security update for python311 Type: security Severity: important References: 1222465,1234736,1258364,1261969,1262098,1262319,1262654,1263083,1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-1502,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python311 fixes the following issues: Security issues fixed: - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319). - CVE-2026-6019: BaseCookie.js_output() does not neutralize embedded characters (bsc#1262654). - CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules (bsc#1262098). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issues fixed: - Regression in `http.cookies` (bsc#1263083). - udplite was removed -> python fails in tests (bsc#1268375). - Conflicts between different versions of Python (bsc#1258364). The following package changes have been done: - SL-Micro-release-6.1-slfo.1.12.63 updated - vim-data-common-9.2.0957-slfo.1.1_1.1 updated - python311-base-3.11.15-slfo.1.1_5.1 updated - libpython3_11-1_0-3.11.15-slfo.1.1_5.1 updated - vim-small-9.2.0957-slfo.1.1_1.1 updated - python311-3.11.15-slfo.1.1_5.1 updated - container:SL-Micro-base-container-2.2.1-5.167 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:45:05 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:45:05 +0200 (CEST) Subject: SUSE-IU-2026:6362-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260819074505.6AEA1FD94@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6362-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.153 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.153 Severity : important Type : security References : 1250110 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 677 Released: Tue Aug 18 19:41:59 2026 Summary: Security update for rpm Type: security Severity: important References: 1250110,1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - rpm-4.18.0-slfo.1.1_3.1 updated - SL-Micro-release-6.1-slfo.1.12.64 updated - container:SL-Micro-base-container-2.2.1-5.169 updated From sle-container-updates at lists.suse.com Wed Aug 19 07:50:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 09:50:23 +0200 (CEST) Subject: SUSE-IU-2026:6366-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260819075023.15F88FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6366-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.173 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.173 Severity : important Type : security References : 1250110 1269584 CVE-2026-44605 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 677 Released: Tue Aug 18 19:41:59 2026 Summary: Security update for rpm Type: security Severity: important References: 1250110,1269584,CVE-2026-44605 This update for rpm fixes the following issue: - CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot table (bsc#1269584). The following package changes have been done: - rpm-4.18.0-slfo.1.1_3.1 updated - SL-Micro-release-6.1-slfo.1.12.64 updated - kernel-default-base-6.4.0-51.1.21.33 updated - container:SL-Micro-base-container-2.2.1-5.169 updated From sle-container-updates at lists.suse.com Wed Aug 19 08:33:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 10:33:41 +0200 (CEST) Subject: SUSE-CU-2026:8924-1: Security update of bci/golang Message-ID: <20260819083341.84374FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8924-1 Container Tags : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.13 , bci/golang:1.25.13-2.76.30 , bci/golang:oldstable Container Release : 76.30 Severity : important Type : security References : 1244485 1266609 1275024 1275025 1275026 1275028 1275029 1275032 1275033 1275034 CVE-2026-33818 CVE-2026-39821 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3640-1 Released: Tue Aug 18 11:04:48 2026 Summary: Security update for go1.25 Type: security Severity: important References: 1244485,1266609,1275024,1275025,1275026,1275028,1275029,1275032,1275033,1275034,CVE-2026-33818,CVE-2026-39821,CVE-2026-56853,CVE-2026-56858,CVE-2026-56859,CVE-2026-56860,CVE-2026-56862,CVE-2026-56864,CVE-2026-56865 This update for go1.25 fixes the following issues: Security issues fixed: - CVE-2026-33818: encoding/asn1: enforce maximum recursion depth (bsc#1275034). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). - CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted HTTP/2 check (bsc#1275028). - CVE-2026-56858: html/template: fix Javascript regexp context tracking (bsc#1275033). - CVE-2026-56859: encoding/xml: add recursion depth guard during decode (bsc#1275026). - CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath (bsc#1275029). - CVE-2026-56862: crypto/tls: limit handshake messages we are willing to accept post-handshake (bsc#1275032). - CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025). - CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024). Non security issue fixed: - go1.25 release tracking (bsc#1244485). Changes for go1.25: - update to go1.25.13 * go#79875 cmd/compile: prove misscompilation in slicemask folding leaves garbage in upper bits * go#80098 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr * go#80364 os: Root's MkdirAll can't create paths ending in forward slashes * go#80366 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880 * go#80368 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880 * go#80393 runtime: arm64 found pointer to free object with safe code * go#80440 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer * go#80477 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field * go#80500 runtime: js/wasm: 'found bad pointer in Go heap' -- link-layout-constant value recorded as a pointer in the write-barrier buffer * go#80578 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills * go#80605 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement * go#80614 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic * go#80616 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames * go#80618 cmd/compile: prove bug causes invalid indirect call * go#80737 runtime: fpTracebackPartialExpand SIGSEGV under high panic load The following package changes have been done: - go1.25-doc-1.25.13-150000.1.50.1 updated - go1.25-1.25.13-150000.1.50.1 updated - go1.25-race-1.25.13-150000.1.50.1 updated - container:registry.suse.com-bci-bci-base-15.7-7046acf29602306de3a201afea54d7e9adfb8a01cab70f1066a1c463e03989c2-0 updated From sle-container-updates at lists.suse.com Wed Aug 19 08:36:26 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Wed, 19 Aug 2026 10:36:26 +0200 (CEST) Subject: SUSE-CU-2026:8926-1: Security update of bci/golang Message-ID: <20260819083626.25052FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8926-1 Container Tags : bci/golang:1.26 , bci/golang:1.26-sles15 , bci/golang:1.26.6 , bci/golang:1.26.6-1.75.30 , bci/golang:latest , bci/golang:stable Container Release : 75.30 Severity : important Type : security References : 1255111 1266609 1275024 1275025 1275026 1275028 1275029 1275032 1275033 1275034 CVE-2026-33818 CVE-2026-39821 CVE-2026-56853 CVE-2026-56858 CVE-2026-56859 CVE-2026-56860 CVE-2026-56862 CVE-2026-56864 CVE-2026-56865 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3641-1 Released: Tue Aug 18 11:06:06 2026 Summary: Security update for go1.26 Type: security Severity: important References: 1255111,1266609,1275024,1275025,1275026,1275028,1275029,1275032,1275033,1275034,CVE-2026-33818,CVE-2026-39821,CVE-2026-56853,CVE-2026-56858,CVE-2026-56859,CVE-2026-56860,CVE-2026-56862,CVE-2026-56864,CVE-2026-56865 This update for go1.26 fixes the following issues: Security issues fixed: - CVE-2026-33818: encoding/asn1: enforce maximum recursion depth (bsc#1275034). - CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). - CVE-2026-56853: net/http: apply ReadHeaderTimeout when doing unencrypted HTTP/2 check (bsc#1275028). - CVE-2026-56858: html/template: fix Javascript regexp context tracking (bsc#1275033). - CVE-2026-56859: encoding/xml: add recursion depth guard during decode (bsc#1275026). - CVE-2026-56860: net/url: avoid quadratic complexity in resolvePath (bsc#1275029). - CVE-2026-56862: crypto/tls: limit handshake messages we are willing to accept post-handshake (bsc#1275032). - CVE-2026-56864: x/mod/sumdb: ignore unrelated, unauthenticated hashes in Lookup (bsc#1275025). - CVE-2026-56865: x/mod/sumdb/tlog: fix transparency log tile verification bypass (bsc#1275024). Non security issue fixed: - go1.26 release tracking (bsc#1255111). Changes for go1.26: - update to go1.26.6 * go#79876 cmd/compile: prove misscompilation in slicemask folding leaves garbage in the upper bits * go#80099 cmd/compile: internal compiler error invalid heap allocated var without Heapaddr * go#80131 cmd/link: peCreateExportFile generates invalid .def file when output name has trailing dot (c-shared on Windows) * go#80365 os: Root's MkdirAll can't create paths ending in forward slashes * go#80367 os: TestRootMultiReadFile fails on netbsd/arm64 after CL 797880 * go#80369 os: TestRootConsistencyRemoveAll fails on Plan 9 after CL 797880 * go#80394 runtime: arm64 found pointer to free object with safe code * go#80441 runtime: uninitialized register due to wrong ABI in mach_vm_region_trampoline leads to libc following garbage stack data as a pointer * go#80478 cmd/compile: riscv64 miscompiles struct copy, corrupting a []byte slice field * go#80499 runtime: js/wasm: 'found bad pointer in Go heap' -- link-layout-constant value recorded as a pointer in the write-barrier buffer * go#80579 cmd/compile: regalloc uses unreliable type data (like v.Type.IsSigned()) to choose the restore of spills * go#80606 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement * go#80609 net, x/net/dns/dnsmessage: panic when parsing invalid SVCB record * go#80615 cmd/compile: mips64le misscompile OffPtr by a const which doesn't fit 32bits resulting in panic * go#80617 cmd/compile: mips/mips64, multiply/divide results spilled from HI/LO corrupted w/ big stack frames * go#80619 cmd/compile: prove bug causes invalid indirect call * go#80715 runtime: fpTracebackPartialExpand SIGSEGV under high panic load The following package changes have been done: - go1.26-doc-1.26.6-150000.1.24.1 updated - go1.26-1.26.6-150000.1.24.1 updated - go1.26-race-1.26.6-150000.1.24.1 updated - container:registry.suse.com-bci-bci-base-15.7-7046acf29602306de3a201afea54d7e9adfb8a01cab70f1066a1c463e03989c2-0 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:09:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:09:25 +0200 (CEST) Subject: SUSE-IU-2026:6370-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260820070925.74BF1FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6370-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.231 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.231 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 856 Released: Wed Aug 19 12:54:57 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.611.g7d90691. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.611.g7d90691-1.1 updated - container:SL-Micro-base-container-2.1.3-7.194 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:11:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:11:28 +0200 (CEST) Subject: SUSE-IU-2026:6371-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260820071128.E4E5BFD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6371-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.194 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.194 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 856 Released: Wed Aug 19 12:54:57 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.611.g7d90691. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.611.g7d90691-1.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:13:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:13:31 +0200 (CEST) Subject: SUSE-IU-2026:6372-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260820071331.76E03FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6372-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.205 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.205 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 856 Released: Wed Aug 19 12:54:57 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.611.g7d90691. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.611.g7d90691-1.1 updated - container:SL-Micro-base-container-2.1.3-7.194 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:15:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:15:42 +0200 (CEST) Subject: SUSE-IU-2026:6373-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260820071542.54616FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6373-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.224 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.224 Severity : important Type : security References : 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 856 Released: Wed Aug 19 12:54:57 2026 Summary: Security update for dracut Type: security Severity: important References: 1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.611.g7d90691. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.611.g7d90691-1.1 updated - container:SL-Micro-container-2.1.3-6.231 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:23:24 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:23:24 +0200 (CEST) Subject: SUSE-IU-2026:6374-1: Security update of suse/sl-micro/6.1/baremetal-os-container Message-ID: <20260820072324.B8ADEFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6374-1 Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.154 , suse/sl-micro/6.1/baremetal-os-container:latest Image Release : 7.154 Severity : important Type : security References : 1257490 1257625 1257667 1257825 1261155 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 679 Released: Wed Aug 19 13:15:07 2026 Summary: Security update for dracut Type: security Severity: important References: 1257490,1257625,1257667,1257825,1261155,1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.645.g79fd74d. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.645.g79fd74d-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.170 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:25:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:25:08 +0200 (CEST) Subject: SUSE-IU-2026:6375-1: Security update of suse/sl-micro/6.1/base-os-container Message-ID: <20260820072508.1FAAEFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6375-1 Image Tags : suse/sl-micro/6.1/base-os-container:2.2.1 , suse/sl-micro/6.1/base-os-container:2.2.1-5.170 , suse/sl-micro/6.1/base-os-container:latest Image Release : 5.170 Severity : important Type : security References : 1257490 1257625 1257667 1257825 1261155 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.1/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 679 Released: Wed Aug 19 13:15:07 2026 Summary: Security update for dracut Type: security Severity: important References: 1257490,1257625,1257667,1257825,1261155,1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.645.g79fd74d. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.645.g79fd74d-slfo.1.1_1.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:27:04 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:27:04 +0200 (CEST) Subject: SUSE-IU-2026:6376-1: Security update of suse/sl-micro/6.1/kvm-os-container Message-ID: <20260820072704.39C88FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6376-1 Image Tags : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.174 , suse/sl-micro/6.1/kvm-os-container:latest Image Release : 5.174 Severity : important Type : security References : 1257490 1257625 1257667 1257825 1261155 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 679 Released: Wed Aug 19 13:15:07 2026 Summary: Security update for dracut Type: security Severity: important References: 1257490,1257625,1257667,1257825,1261155,1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.645.g79fd74d. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.645.g79fd74d-slfo.1.1_1.1 updated - container:SL-Micro-base-container-2.2.1-5.170 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:29:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:29:19 +0200 (CEST) Subject: SUSE-IU-2026:6377-1: Security update of suse/sl-micro/6.1/rt-os-container Message-ID: <20260820072919.63B3EFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6377-1 Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.168 , suse/sl-micro/6.1/rt-os-container:latest Image Release : 5.168 Severity : important Type : security References : 1257490 1257625 1257667 1257825 1261155 1274432 CVE-2026-15816 ----------------------------------------------------------------- The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 679 Released: Wed Aug 19 13:15:07 2026 Summary: Security update for dracut Type: security Severity: important References: 1257490,1257625,1257667,1257825,1261155,1274432,CVE-2026-15816 This update for dracut fixes the following issue: Update to version 059+suse.645.g79fd74d. Securitys issue fixed: - CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()` (bsc#1274432). Other updates and bugfixes: - Fix(base): sanitize message written by `die()` to the emergency hook. - Feat(base): add escape function implementing `printf %q`. The following package changes have been done: - dracut-059+suse.645.g79fd74d-slfo.1.1_1.1 updated - container:SL-Micro-container-2.2.1-7.154 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:38:23 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:38:23 +0200 (CEST) Subject: SUSE-IU-2026:6378-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20260820073823.C6BFFFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6378-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.97 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.97 Severity : important Type : security References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1465 Released: Wed Aug 19 14:39:32 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). The following package changes have been done: - python313-3.13.14-160000.2.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:44:32 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:44:32 +0200 (CEST) Subject: SUSE-IU-2026:6384-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20260820074432.2B6C8FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6384-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.53 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.53 Severity : important Type : security References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1465 Released: Wed Aug 19 14:39:32 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). The following package changes have been done: - python313-base-3.13.14-160000.2.1 updated - libpython3_13-1_0-3.13.14-160000.2.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:50:41 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:50:41 +0200 (CEST) Subject: SUSE-IU-2026:6388-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20260820075041.3A1ACFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6388-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.86 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.86 Severity : important Type : security References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1465 Released: Wed Aug 19 14:39:32 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). The following package changes have been done: - python313-base-3.13.14-160000.2.1 updated - libpython3_13-1_0-3.13.14-160000.2.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-98095c1ad760d62124f6513040615362e4ced8db3d3bd1df9158f45666d637b7-0 updated From sle-container-updates at lists.suse.com Thu Aug 20 07:57:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 09:57:10 +0200 (CEST) Subject: SUSE-IU-2026:6395-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20260820075710.E4086FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6395-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.113 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.113 Severity : important Type : security References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1465 Released: Wed Aug 19 14:39:32 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). The following package changes have been done: - python313-base-3.13.14-160000.2.1 updated - libpython3_13-1_0-3.13.14-160000.2.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-9f2a29b07af0c8a5d7fe1114c7c154124633505966180bec3487927d58f09fd2-0 updated From sle-container-updates at lists.suse.com Thu Aug 20 08:08:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 10:08:12 +0200 (CEST) Subject: SUSE-CU-2026:8979-1: Security update of bci/python Message-ID: <20260820080812.967DFFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8979-1 Container Tags : bci/python:3 , bci/python:3.11 , bci/python:3.11.15 , bci/python:3.11.15-85.34 Container Release : 85.34 Severity : important Type : security References : 1263083 CVE-2026-3276 CVE-2026-6019 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3648-1 Released: Wed Aug 19 11:54:08 2026 Summary: Security update for python311 Type: security Severity: important References: 1263083,CVE-2026-3276,CVE-2026-6019 This update for python311 fixes the following issues: - Regression in `http.cookies` (bsc#1263083). The following package changes have been done: - libpython3_11-1_0-3.11.15-150600.3.65.1 updated - python311-base-3.11.15-150600.3.65.1 updated - python311-3.11.15-150600.3.65.1 updated - python311-devel-3.11.15-150600.3.65.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 08:09:08 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 10:09:08 +0200 (CEST) Subject: SUSE-CU-2026:8980-1: Security update of bci/python Message-ID: <20260820080908.79E5FFD2D@maintenance.suse.de> SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8980-1 Container Tags : bci/python:3 , bci/python:3.13 , bci/python:3.13-sles15 , bci/python:3.13.14 , bci/python:3.13.14-88.30 , bci/python:latest Container Release : 88.30 Severity : important Type : security References : 1257041 1257044 1262429 1263083 1264962 1265268 1267581 1267821 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-3219 CVE-2026-3276 CVE-2026-4360 CVE-2026-45186 CVE-2026-7210 CVE-2026-7774 CVE-2026-8328 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3649-1 Released: Wed Aug 19 11:54:44 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1262429,1263083,1264962,1265268,1267581,1267821,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3219,CVE-2026-3276,CVE-2026-4360,CVE-2026-45186,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-3219: python-pip: pip doesn't reject concatenated ZIP (bsc#1262429). - CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-6100: Arbitrary code execution or information disclosure via use-after-free in decompression modules (bsc#1262098). - CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). - CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). - Regression in `http.cookies` (bsc#1263083). Changes for python313: - Update to 3.13.14: - Security - gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. - gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. - gh-87451: The ftplib module's undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328) - gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink's directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter (bsc#1267821, CVE-2026-7774). - gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs (bsc#1267581, CVE-2026-3276). - gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (CVE-2026-7210, bsc#1264962). - gh-149017: Update bundled libexpat to version 2.8.0. - gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) - gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) - gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). - gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing '..' in the name (like 'foo..bar') are no longer skipped. - gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) - gh-149144: Fixes an issue introduced by CVE-2026-6019 patch. atob() in JavaScript processes bytes as 'latin-1', switches the encoding algorithm from base64 to percent encoding and uses the decodeURIComponent() JavaScript API (bsc#1263083). - Core and Builtins - gh-151112: Fix a crash in the compiler that could occur when running out of memory. - gh-151126: Fix a crash, when there's no memory left on a device, which happened in: - code compilation - _winapi.CreateProcess() - Now these places raise proper MemoryError errors. - gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. - gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. - gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. - gh-148450: Fix abc.register() so it invalidates type version tags for registered classes. - gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper MemoryError is now raised instead. - gh-150107: asyncio: sendfile() and sock_sendfile() event loop methods now call file.seek(offset) if file has a seek() method, even if offset is 0 (default value). - gh-150146: Fix a crash on a complex type variable substitution. - from typing import TypeVar; memoryview[TypeVar('')][*typing.Mapping[..., ...]] used to fail due to missing NULL check on _unpack_args C function call. - gh-149590: Fix crash when faulthandler is imported more than once. - gh-149738: sqlite3: Disallow removing row_factory and text_factory attributes of a connection to prevent a crash on a query. - gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by -X perf_jit (Linux perf profiler integration). - gh-148820: Fix a race in _PyRawMutex on the free-threaded build where a Py_PARK_INTR return from _PySemaphore_Wait could let the waiter destroy its semaphore before the unlocking thread's _PySemaphore_Wakeup completed, causing a fatal ReleaseSemaphore error. - gh-148653: Forbid marshalling recursive code objects which cannot be correctly unmarshalled. - gh-148390: Fix an undefined behavior in memoryview when using the native boolean format (?) in cast(). Previously, on some common platforms, calling memoryview(b).cast('?').tolist() incorrectly returned [False] instead of [True] for any even byte b. Patch by B??n??dikt Tran. - gh-148418: Fix a possible reference leak in a corrupted TYPE_CODE marshal stream. - gh-148222: Fix vectorcall support in types.GenericAlias when the underlying type does not support the vectorcall protocol. Fix possible leaks in types.GenericAlias and types.UnionType in case of memory error. - gh-145376: Fix reference leaks in various unusual error scenarios. - C API - gh-150907: Fix dynamic_annotations.h header file when built with C++ and Valgrind: add extern 'C++' scope for the C++ template. Patch by Victor Stinner. - Build - gh-149351: Avoid possible broken macOS framework install names when DESTDIR is specified during builds. - gh-146475: Block Apple Clang from being used to build the JIT as it ships without required LLVM tools. - gh-148535: No longer use the gcc -fprofile-update=atomic flag on i686. The flag has been added to fix a random GCC internal error on PGO build (gh-145801) caused by corruption of profile data (.gcda files). The problem is that it makes the PGO build way slower (up to 47x slower) on i686. Since the GCC internal error was not seen on i686 so far, don't use -fprofile-update=atomic on i686 anymore. Patch by Victor Stinner. - Library - gh-150913: Fix sqlite3.Blob slice assignment to raise TypeError and IndexError for type and size mismatches respectively, even when the target slice is empty. - gh-143008: Fix race conditions when re-initializing a io.TextIOWrapper object. - gh-150685: Update bundled pip to 26.1.2 - gh-150406: Fix a possible crash occurring during socket module initialization when the system is out of memory on platforms without a reentrant gethostbyname. - gh-150372: readline: Fix a potential crash during tab completion caused by an out-of-memory error during module initialization. - gh-150175: Fix race condition in unittest.mock.ThreadingMock where concurrent calls could lose increments to call_count and other attributes due to a missing lock in _increment_mock_call. - gh-84353: Preserve non-UTF-8 encoded filenames when appending to a zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8. - gh-149995: Update various docstrings in typing. - gh-88726: The email package now uses standard MIME charset names 'gb2312' and 'big5' instead of non-standard names 'eucgb2312_cn' and 'big5_tw'. - gh-149571: Fix the C implementation of xml.etree.ElementTree.Element.itertext(): it no longer emits text for comments and processing instructions. - gh-149921: Fix reference leaks in error paths of the _interpchannels and _interpqueues extension modules. - gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs. - gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled - gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects. - gh-149388: Make asyncio.windows_utils.PipeHandle closing idempotent. - gh-149489: Fix ElementTree serialization to HTML. The content of elements 'xmp', 'iframe', 'noembed', 'noframes', and 'plaintext' is no longer escaped. The 'plaintext' element no longer have the closing tag. - gh-149377: Update bundled pip to 26.1.1 - gh-149231: In tomllib, the number of parts in TOML keys is now limited. - gh-149117: Fix runpy.run_module() and runpy.run_path() to set the name attribute on the ImportError they raise. - gh-149148: ensurepip: Upgrade bundled pip to 26.1. This version fixes the CVE 2026-3219 vulnerability. Patch by Victor Stinner. - gh-148093: Fix an out-of-bounds read of one byte in binascii.a2b_uu(). Raise binascii.Error, instead of reading past the buffer end. - gh-148914: Fix memoization of in-band PickleBuffer in the Python implementation of pickle. Previously, identical PickleBuffers did not preserve identity, and empty writable PickleBuffer memoized an empty bytearray object in place of b'', so the following references to b'' were unpickled as an empty bytearray object. - gh-138907: Support RFC 9309 in urllib.robotparser. - gh-148954: Fix XML injection vulnerability in xmlrpc.client.dumps() where the methodname was not being escaped before interpolation into the XML body. - gh-148801: xml.etree.ElementTree: Fix a crash in Element.__deepcopy__ on deeply nested trees. - gh-148735: xml.etree.ElementTree: Fix a use-after-free in Element.findtext when the element tree is mutated concurrently during the search. - gh-146553: Fix infinite loop in typing.get_type_hints() when __wrapped__ forms a cycle. Patch by Shamil Abdulaev. - gh-148508: An intermittent timing error when running SSL tests on iOS has been resolved. - gh-148518: If an email containing an address header that ended in an open double quote was parsed with a non-compat32 policy, accessing the username attribute of the mailbox accessed through that header object would result in an IndexError. It now correctly returns an empty string as the result. - gh-148370: configparser: prevent quadratic behavior when a ParsingError is raised after a parser fails to parse multiple lines. Patch by B??n??dikt Tran. - gh-148254: Use singular 'sec' instead of 'secs' in timeit verbose output for consistency with other time units. - gh-148192: email.generator.Generator._make_boundary could fail to detect a duplicate boundary string if linesep was not n. It now correctly detects boundary strings when linesep is rn as well. - gh-146313: Fix a deadlock in multiprocessing's resource tracker where the parent process could hang indefinitely in os.waitpid() during interpreter shutdown if a child created via os.fork() still held the resource tracker's pipe open. - gh-145831: Fix email.quoprimime.decode() leaving a stray \r when eol='\r\n' by stripping the full eol string instead of one character. - gh-145105: Fix crash in csv reader when iterating with a re-entrant iterator that calls next() on the same reader from within __next__. - gh-130750: Restore quoting of choices in argparse error messages for improved clarity and consistency with documentation. - gh-105936: Attempting to mutate non-field attributes of dataclasses with both frozen and slots being True now raises FrozenInstanceError instead of TypeError. Their non-dataclass subclasses can now freely mutate non-field attributes, and the original non-slotted class can be garbage collected. The fix also handles the case of an empty __class__ cell on a function found within the class (gh-148947). - gh-142516: ssl: fix reference leaks in ssl.SSLContext objects. Patch by B??n??dikt Tran. - gh-142831: Fix a crash in the json module where a use-after-free could occur if the object being encoded is modified during serialization. - gh-140287: The asyncio REPL now handles exceptions when executing PYTHONSTARTUP scripts. Patch by Bartosz S??awecki. - gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by B??n??dikt Tran. - gh-132631: Fix 'I/O operation on closed file' when parsing JSON Lines file with JSON CLI. - gh-128110: Fix bug in the parsing of email address headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject). - gh-107398: Fix tarfile stream mode exception when process the file with the gzip extra field. - gh-123853: Update the table of Windows language code identifiers (LCIDs) used by locale.getdefaultlocale() on Windows to protocol version 16.0 (2024-04-23). - gh-70039: Fixed bug where smtplib.SMTP.starttls() could fail if smtplib.SMTP.connect() is called explicitly rather than implicitly. - gh-83281: email: improve handling trailing garbage in address lists to avoid throwing AttributeError in certain edge cases - gh-91099: imaplib.IMAP4.login() now raises exceptions with str instead of bytes. Patch by Florian Best. - IDLE - bpo-6699: Warn the user if a file will be overwritten when saving. - Documentation - gh-150319: Generic builtin and standard library types now document the meaning of their type parameters. - gh-148663: Document that calendar.IllegalMonthError is a subclass of both ValueError and IndexError since Python 3.12. - gh-146646: Document that glob.glob(), glob.iglob(), pathlib.Path.glob(), and pathlib.Path.rglob() silently suppress OSError exceptions raised from scanning the filesystem. - gh-109503: Fix documentation for shutil.move() on usage of os.rename() since nonatomic move might be used even if the files are on the same filesystem. Patch by Fang Li - Tests - gh-151130: Add more tests for PyWeakref_* C API. - gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it's not supported. Patch by Victor Stinner. The following package changes have been done: - libpython3_13-1_0-3.13.14-150700.4.53.1 updated - python313-base-3.13.14-150700.4.53.1 updated - python313-3.13.14-150700.4.53.1 updated - python313-devel-3.13.14-150700.4.53.1 updated From sle-container-updates at lists.suse.com Thu Aug 20 08:14:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 20 Aug 2026 10:14:38 +0200 (CEST) Subject: SUSE-CU-2026:8981-1: Security update of suse/sles/16.0/toolbox Message-ID: <20260820081438.211E3FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8981-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.108 , suse/sles/16.0/toolbox:latest Container Release : 1.108 Severity : important Type : security References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192 CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972 CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1465 Released: Wed Aug 19 14:39:32 2026 Summary: Security update for python313 Type: security Severity: important References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328 This update for python313 fixes the following issues: - CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044). - CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041). - CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). - CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). - CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268). - CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). - CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). - CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). The following package changes have been done: - container-suseconnect-2.5.6-160000.2.5 updated - libpython3_13-1_0-3.13.14-160000.2.1 updated - python313-base-3.13.14-160000.2.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:08:57 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:08:57 +0200 (CEST) Subject: SUSE-CU-2026:8982-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260821070857.26AC8FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8982-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.269 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.269 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:11:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:11:25 +0200 (CEST) Subject: SUSE-CU-2026:8983-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260821071125.BD056FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8983-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.270 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.270 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:13:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:13:29 +0200 (CEST) Subject: SUSE-CU-2026:8984-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260821071329.3E2BBFD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8984-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.180 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.180 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:28:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:28:20 +0200 (CEST) Subject: SUSE-CU-2026:8986-1: Security update of suse/ltss/sle15.4/sle15 Message-ID: <20260821072820.5E180FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.4/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8986-1 Container Tags : suse/ltss/sle15.4/bci-base:15.4 , suse/ltss/sle15.4/bci-base:15.4-6.43 , suse/ltss/sle15.4/sle15:15.4 , suse/ltss/sle15.4/sle15:15.4-6.43 , suse/ltss/sle15.4/sle15:latest Container Release : 6.43 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/ltss/sle15.4/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:32:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:32:28 +0200 (CEST) Subject: SUSE-CU-2026:8987-1: Security update of suse/ltss/sle15.5/sle15 Message-ID: <20260821073228.F3F6BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.5/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8987-1 Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.65 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.65 , suse/ltss/sle15.5/sle15:latest Container Release : 8.65 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:35:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:35:31 +0200 (CEST) Subject: SUSE-CU-2026:8989-1: Security update of suse/ltss/sle15.6/sle15 Message-ID: <20260821073531.59C33FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8989-1 Container Tags : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.84 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.84 , suse/ltss/sle15.6/sle15:latest Container Release : 5.84 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3654-1 Released: Thu Aug 20 10:33:05 2026 Summary: Security update for container-suseconnect Type: security Severity: important References: This update for container-suseconnect rebuilds it against the current go security release. The following package changes have been done: - container-suseconnect-2.5.6-150000.4.92.1 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:36:55 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:36:55 +0200 (CEST) Subject: SUSE-CU-2026:8990-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260821073655.42D90FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8990-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.12 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.12 Severity : important Type : security References : 1274867 CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74937 CVE-2026-74938 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74947 CVE-2026-74948 CVE-2026-74949 CVE-2026-74950 CVE-2026-74951 CVE-2026-74952 CVE-2026-74953 CVE-2026-74954 CVE-2026-74955 CVE-2026-74956 CVE-2026-74957 CVE-2026-74958 CVE-2026-74959 CVE-2026-74960 CVE-2026-74961 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74966 CVE-2026-74967 CVE-2026-74968 CVE-2026-74969 CVE-2026-74970 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74975 CVE-2026-74976 CVE-2026-74977 CVE-2026-74978 CVE-2026-74979 CVE-2026-74980 CVE-2026-74981 CVE-2026-74982 CVE-2026-74983 CVE-2026-74984 CVE-2026-74985 CVE-2026-74986 CVE-2026-74987 CVE-2026-74988 CVE-2026-74989 CVE-2026-74990 CVE-2026-75874 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3658-1 Released: Thu Aug 20 19:15:33 2026 Summary: Security update for MozillaFirefox Type: security Severity: important References: 1274867,CVE-2026-74934,CVE-2026-74935,CVE-2026-74936,CVE-2026-74937,CVE-2026-74938,CVE-2026-74939,CVE-2026-74940,CVE-2026-74941,CVE-2026-74942,CVE-2026-74943,CVE-2026-74944,CVE-2026-74945,CVE-2026-74946,CVE-2026-74947,CVE-2026-74948,CVE-2026-74949,CVE-2026-74950,CVE-2026-74951,CVE-2026-74952,CVE-2026-74953,CVE-2026-74954,CVE-2026-74955,CVE-2026-74956,CVE-2026-74957,CVE-2026-74958,CVE-2026-74959,CVE-2026-74960,CVE-2026-74961,CVE-2026-74962,CVE-2026-74963,CVE-2026-74964,CVE-2026-74965,CVE-2026-74966,CVE-2026-74967,CVE-2026-74968,CVE-2026-74969,CVE-2026-74970,CVE-2026-74971,CVE-2026-74972,CVE-2026-74973,CVE-2026-74974,CVE-2026-74975,CVE-2026-74976,CVE-2026-74977,CVE-2026-74978,CVE-2026-74979,CVE-2026-74980,CVE-2026-74981,CVE-2026-74982,CVE-2026-74983,CVE-2026-74984,CVE-2026-74985,CVE-2026-74986,CVE-2026-74987,CVE-2026-74988,CVE-2026-74989,CVE-2026-74990,CVE-2026-75874 This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.14.0 ESR. - MFSA 2026-74 (bsc#1274867) - CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component. - CVE-2026-74935: Privilege escalation in the DOM: Networking component. - CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component. - CVE-2026-74937: Use-after-free in the JavaScript: GC component. - CVE-2026-74938: Mitigation bypass in the JavaScript: GC component. - CVE-2026-74939: Privilege escalation in the DOM: Navigation component. - CVE-2026-74940: Use-after-free in the Graphics: Text component. - CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component. - CVE-2026-74942: Privilege escalation in the Remote Settings Client component. - CVE-2026-74943: Use-after-free in the Graphics: ImageLib component. - CVE-2026-74944: Use-after-free in the DOM: Core & HTML component. - CVE-2026-74945: Information disclosure in the Graphics: Text component. - CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. - CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component. - CVE-2026-74948: Information disclosure in the Graphics component. - CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component. - CVE-2026-74950: Privilege escalation in the Downloads API component. - CVE-2026-74951: Clickjacking issue in Firefox for Android. - CVE-2026-74952: Privilege escalation in the Application Update component. - CVE-2026-74953: Privilege escalation in the Networking: Cookies component. - CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component. - CVE-2026-74955: Privilege escalation in the Request Handling component. - CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component. - CVE-2026-74957: Mitigation bypass in the Safe Browsing component. - CVE-2026-74958: Information disclosure in the WebRTC component. - CVE-2026-74959: Mitigation bypass in the Storage: Cache API component. - CVE-2026-74960: Site isolation issue in the WebExtensions component. - CVE-2026-74961: Side-channel in the Web Audio component. - CVE-2026-74962: Site isolation issue in the Networking: Cookies component. - CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component. - CVE-2026-74964: Integer overflow in the Graphics component. - CVE-2026-74965: Privilege escalation in the Shell Integration component. - CVE-2026-74966: Information disclosure in the Form Autofill component. - CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component. - CVE-2026-74968: Site isolation issue in the Graphics: WebRender component. - CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component. - CVE-2026-74970: Site isolation issue in the Graphics component. - CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component. - CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component. - CVE-2026-74973: Race condition, use-after-free in the Graphics component. - CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component. - CVE-2026-74975: Spoofing issue in the Downloads component in Firefox for Android. - CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component. - CVE-2026-74977: Integer overflow in the Graphics component. - CVE-2026-74978: Clickjacking issue in the Widget component. - CVE-2026-74979: Mitigation bypass in the Add-ons Manager component. - CVE-2026-74980: Clickjacking issue in the Downloads component in Firefox for Android. - CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component. - CVE-2026-74982: Denial-of-service in the Widget component. - CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component. - CVE-2026-74984: Race condition in the JavaScript Engine component. - CVE-2026-74985: Privilege escalation in the Enterprise Policies component. - CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component. - CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. - CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154. - CVE-2026-74989: Internally found bugs fixed in Firefox 154. - CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154. - CVE-2026-75874: Sandbox escape in the Remote Settings Client component. The following package changes have been done: - MozillaFirefox-140.14.0-150200.152.251.1 updated - container:suse-sle15-15.7-7046acf29602306de3a201afea54d7e9adfb8a01cab70f1066a1c463e03989c2-0 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:37:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:37:25 +0200 (CEST) Subject: SUSE-CU-2026:8991-1: Security update of suse/kubectl Message-ID: <20260821073725.2FB73FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8991-1 Container Tags : suse/kubectl:1.33 , suse/kubectl:1.33.11 , suse/kubectl:1.33.11-2.70.7 , suse/kubectl:oldstable Container Release : 70.7 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3659-1 Released: Thu Aug 20 20:17:00 2026 Summary: Security update for kubernetes-old Type: security Severity: important References: This update for kubernetes-old rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3661-1 Released: Thu Aug 20 20:18:10 2026 Summary: Security update for helm Type: security Severity: important References: This update for helm rebuilds it against the current go security release. The following package changes have been done: - helm-3.21.3-150000.1.87.1 updated - kubernetes1.33-client-1.33.11-150600.13.36.1 updated - kubernetes1.33-client-common-1.33.11-150600.13.36.1 updated - container:suse-sle15-15.7-7046acf29602306de3a201afea54d7e9adfb8a01cab70f1066a1c463e03989c2-0 updated From sle-container-updates at lists.suse.com Fri Aug 21 07:37:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 21 Aug 2026 09:37:54 +0200 (CEST) Subject: SUSE-CU-2026:8992-1: Security update of suse/kubectl Message-ID: <20260821073754.E70D1FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/kubectl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:8992-1 Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-1.70.7 , suse/kubectl:latest , suse/kubectl:stable Container Release : 70.7 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/kubectl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3660-1 Released: Thu Aug 20 20:17:13 2026 Summary: Security update for kubernetes Type: security Severity: important References: This update for kubernetes rebuilds it against the current go security release. ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3661-1 Released: Thu Aug 20 20:18:10 2026 Summary: Security update for helm Type: security Severity: important References: This update for helm rebuilds it against the current go security release. The following package changes have been done: - helm-3.21.3-150000.1.87.1 updated - kubernetes1.35-client-1.35.4-150600.13.38.1 updated - kubernetes1.35-client-common-1.35.4-150600.13.38.1 updated - container:suse-sle15-15.7-7046acf29602306de3a201afea54d7e9adfb8a01cab70f1066a1c463e03989c2-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:11:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:11:11 +0200 (CEST) Subject: SUSE-IU-2026:6407-1: Security update of suse/sle-micro/5.5 Message-ID: <20260822071111.AC421FD2F@maintenance.suse.de> SUSE Image Update Advisory: suse/sle-micro/5.5 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6407-1 Image Tags : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.91 , suse/sle-micro/5.5:latest Image Release : 5.8.91 Severity : important Type : security References : ----------------------------------------------------------------- The container suse/sle-micro/5.5 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3671-1 Released: Fri Aug 21 09:16:34 2026 Summary: Security update for podman Type: security Severity: important References: This update for podman rebuilds it against the current go security release. The following package changes have been done: - podman-4.9.5-150500.3.80.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:18:19 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:18:19 +0200 (CEST) Subject: SUSE-CU-2026:9009-1: Security update of private-registry/1.2/harbor-registry Message-ID: <20260822071819.9D20CFD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9009-1 Container Tags : private-registry/1.2/harbor-registry:1.2.1 , private-registry/1.2/harbor-registry:1.2.1-1.78 , private-registry/1.2/harbor-registry:latest Container Release : 1.78 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.15.2-150700.1.4 updated - util-linux-2.40.4-150700.4.18.1 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:18:40 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:18:40 +0200 (CEST) Subject: SUSE-CU-2026:9011-1: Security update of private-registry/1.2/harbor-registryctl Message-ID: <20260822071840.8A08FFD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/1.2/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9011-1 Container Tags : private-registry/1.2/harbor-registryctl:1.2.1 , private-registry/1.2/harbor-registryctl:1.2.1-1.78 , private-registry/1.2/harbor-registryctl:latest Container Release : 1.78 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/1.2/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.15.2-150700.1.4 updated - util-linux-2.40.4-150700.4.18.1 updated - harbor-registryctl-2.15.2-150700.1.4 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:24:52 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:24:52 +0200 (CEST) Subject: SUSE-CU-2026:9023-1: Security update of private-registry/harbor-registry Message-ID: <20260822072452.A94C2FD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9023-1 Container Tags : private-registry/harbor-registry:1.1.3 , private-registry/harbor-registry:1.1.3-2.93 , private-registry/harbor-registry:latest Container Release : 2.93 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.14.4-150700.1.34 updated - util-linux-2.40.4-150700.4.18.1 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:26:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:26:06 +0200 (CEST) Subject: SUSE-CU-2026:9025-1: Security update of private-registry/harbor-registryctl Message-ID: <20260822072606.58024FD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9025-1 Container Tags : private-registry/harbor-registryctl:1.1.3 , private-registry/harbor-registryctl:1.1.3-2.94 , private-registry/harbor-registryctl:latest Container Release : 2.94 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.14.4-150700.1.34 updated - util-linux-2.40.4-150700.4.18.1 updated - harbor-registryctl-2.14.4-150700.1.34 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:28:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:28:33 +0200 (CEST) Subject: SUSE-CU-2026:9037-1: Security update of private-registry/harbor-registry Message-ID: <20260822072833.8038FFD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9037-1 Container Tags : private-registry/harbor-registry:2.8.3 , private-registry/harbor-registry:2.8.3-1.44 , private-registry/harbor-registry:latest Container Release : 1.44 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/harbor-registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.13.5-150700.1.24 updated - util-linux-2.40.4-150700.4.18.1 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:28:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:28:46 +0200 (CEST) Subject: SUSE-CU-2026:9039-1: Security update of private-registry/harbor-registryctl Message-ID: <20260822072846.63105FD2D@maintenance.suse.de> SUSE Container Update Advisory: private-registry/harbor-registryctl ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9039-1 Container Tags : private-registry/harbor-registryctl:2.13 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5 , private-registry/harbor-registryctl:2.13.5-1.43 , private-registry/harbor-registryctl:2.13.5-1.43 , private-registry/harbor-registryctl:latest Container Release : 1.43 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container private-registry/harbor-registryctl was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - system-user-harbor-2.13.5-150700.1.24 updated - util-linux-2.40.4-150700.4.18.1 updated - harbor213-registryctl-2.13.5-150700.1.24 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:37:02 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:37:02 +0200 (CEST) Subject: SUSE-CU-2026:9043-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20260822073702.9BAD4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9043-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.270 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.270 Severity : important Type : security References : 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3679-1 Released: Fri Aug 21 16:20:08 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). The following package changes have been done: - vim-data-common-9.2.0957-150000.5.102.1 updated - vim-9.2.0957-150000.5.102.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:41:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:41:31 +0200 (CEST) Subject: SUSE-CU-2026:9044-1: Security update of suse/sle-micro-rancher/5.4 Message-ID: <20260822074131.AE67BFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro-rancher/5.4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9044-1 Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.172 , suse/sle-micro-rancher/5.4:latest Container Release : 4.5.172 Severity : important Type : security References : 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 ----------------------------------------------------------------- The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3679-1 Released: Fri Aug 21 16:20:08 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). The following package changes have been done: - vim-data-common-9.2.0957-150000.5.102.1 updated - vim-small-9.2.0957-150000.5.102.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:43:59 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:43:59 +0200 (CEST) Subject: SUSE-CU-2026:9045-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20260822074359.5D7A4FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9045-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.271 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.271 Severity : important Type : security References : 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3679-1 Released: Fri Aug 21 16:20:08 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). The following package changes have been done: - vim-data-common-9.2.0957-150000.5.102.1 updated - vim-9.2.0957-150000.5.102.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:46:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:46:11 +0200 (CEST) Subject: SUSE-CU-2026:9046-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20260822074611.E2046FD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9046-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.181 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.181 Severity : important Type : security References : 1275011 1275012 1275013 1275014 1275015 1275016 1275017 1275018 CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075 CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3680-1 Released: Fri Aug 21 16:21:23 2026 Summary: Security update for vim Type: security Severity: important References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078 This update for vim fixes the following issues: - CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). - CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). - CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). - CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). - CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). - CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). - CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). - CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Changes for vim: - Updated to version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ':language messages' only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using '|' (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * 'zb' scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). The following package changes have been done: - vim-data-common-9.2.0957-150500.20.64.1 updated - vim-9.2.0957-150500.20.64.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:48:31 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:48:31 +0200 (CEST) Subject: SUSE-IU-2026:6408-1: Security update of suse/sl-micro/6.0/baremetal-os-container Message-ID: <20260822074831.72888FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6408-1 Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.232 , suse/sl-micro/6.0/baremetal-os-container:latest Image Release : 6.232 Severity : important Type : security References : 1239671 1241012 1241667 1259642 1261427 1261430 1261441 1261606 1264568 1268886 1269583 CVE-2025-32728 CVE-2026-13595 CVE-2026-27456 CVE-2026-3497 CVE-2026-35385 CVE-2026-35388 CVE-2026-35414 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 859 Released: Fri Aug 21 16:14:36 2026 Summary: Security update for openssh Type: security Severity: important References: 1239671,1241012,1241667,1259642,1261427,1261430,1261441,1264568,CVE-2025-32728,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414 This update for openssh fixes the following issues: - CVE-2025-32728: fix logic error in DisableForwarding option (bsc#1241012). - CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642). - CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427). Other issues fixed:: - ignores write permissions for Group and World Directory Permissions (bsc#1241667). - wall tool not longer printing any message to terminals (bsc#1239671) - potential issue in validating mac (bsc#1264568): * Improve %prep LDAP regex to preserve subdirectories (e.g., ope- nbsd-compat/) and handle optional [ab]/ prefixes. ----------------------------------------------------------------- Advisory ID: 858 Released: Fri Aug 21 16:17:45 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libuuid1-2.39.3-8.1 updated - libsmartcols1-2.39.3-8.1 updated - libblkid1-2.39.3-8.1 updated - libfdisk1-2.39.3-8.1 updated - libmount1-2.39.3-8.1 updated - util-linux-2.39.3-8.1 updated - SL-Micro-release-6.0-25.124 updated - util-linux-systemd-2.39.3-8.1 updated - openssh-common-9.6p1-6.1 updated - openssh-server-9.6p1-6.1 updated - openssh-clients-9.6p1-6.1 updated - openssh-9.6p1-6.1 updated - container:SL-Micro-base-container-2.1.3-7.195 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:50:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:50:54 +0200 (CEST) Subject: SUSE-IU-2026:6409-1: Security update of suse/sl-micro/6.0/base-os-container Message-ID: <20260822075054.4939CFD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6409-1 Image Tags : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.195 , suse/sl-micro/6.0/base-os-container:latest Image Release : 7.195 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 858 Released: Fri Aug 21 16:17:45 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libuuid1-2.39.3-8.1 updated - libsmartcols1-2.39.3-8.1 updated - libblkid1-2.39.3-8.1 updated - libfdisk1-2.39.3-8.1 updated - libmount1-2.39.3-8.1 updated - util-linux-2.39.3-8.1 updated - SL-Micro-release-6.0-25.124 updated - util-linux-systemd-2.39.3-8.1 updated - container:suse-toolbox-image-1.0.0-9.153 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:53:14 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:53:14 +0200 (CEST) Subject: SUSE-IU-2026:6410-1: Security update of suse/sl-micro/6.0/kvm-os-container Message-ID: <20260822075314.D80A6FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6410-1 Image Tags : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.206 , suse/sl-micro/6.0/kvm-os-container:latest Image Release : 6.206 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 858 Released: Fri Aug 21 16:17:45 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libuuid1-2.39.3-8.1 updated - libsmartcols1-2.39.3-8.1 updated - libblkid1-2.39.3-8.1 updated - libfdisk1-2.39.3-8.1 updated - libmount1-2.39.3-8.1 updated - util-linux-2.39.3-8.1 updated - SL-Micro-release-6.0-25.124 updated - util-linux-systemd-2.39.3-8.1 updated - container:SL-Micro-base-container-2.1.3-7.195 updated From sle-container-updates at lists.suse.com Sat Aug 22 07:56:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 09:56:11 +0200 (CEST) Subject: SUSE-IU-2026:6411-1: Security update of suse/sl-micro/6.0/rt-os-container Message-ID: <20260822075611.F3A80FD2D@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.0/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:6411-1 Image Tags : suse/sl-micro/6.0/rt-os-container:2.1.3 , suse/sl-micro/6.0/rt-os-container:2.1.3-7.225 , suse/sl-micro/6.0/rt-os-container:latest Image Release : 7.225 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/sl-micro/6.0/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 858 Released: Fri Aug 21 16:17:45 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libuuid1-2.39.3-8.1 updated - libsmartcols1-2.39.3-8.1 updated - libblkid1-2.39.3-8.1 updated - libfdisk1-2.39.3-8.1 updated - libmount1-2.39.3-8.1 updated - util-linux-2.39.3-8.1 updated - SL-Micro-release-6.0-25.124 updated - util-linux-systemd-2.39.3-8.1 updated - container:SL-Micro-container-2.1.3-6.232 updated From sle-container-updates at lists.suse.com Sat Aug 22 08:05:46 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 10:05:46 +0200 (CEST) Subject: SUSE-CU-2026:9051-1: Security update of suse/sl-micro/6.0/toolbox Message-ID: <20260822080546.25385FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/sl-micro/6.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9051-1 Container Tags : suse/sl-micro/6.0/toolbox:13.2 , suse/sl-micro/6.0/toolbox:13.2-9.153 , suse/sl-micro/6.0/toolbox:latest Container Release : 9.153 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/sl-micro/6.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 858 Released: Fri Aug 21 16:17:45 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - SL-Micro-release-6.0-25.124 updated - libblkid1-2.39.3-8.1 updated - libfdisk1-2.39.3-8.1 updated - libmount1-2.39.3-8.1 updated - libsmartcols1-2.39.3-8.1 updated - libuuid1-2.39.3-8.1 updated - skelcd-EULA-SL-Micro-2024.01.19-8.123 updated - util-linux-2.39.3-8.1 updated From sle-container-updates at lists.suse.com Sat Aug 22 08:23:33 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 10:23:33 +0200 (CEST) Subject: SUSE-CU-2026:9052-1: Security update of suse/ltss/sle15.6/bci-base-fips Message-ID: <20260822082333.42E6EFD2D@maintenance.suse.de> SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9052-1 Container Tags : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.93 , suse/ltss/sle15.6/bci-base-fips:latest Container Release : 35.93 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3685-1 Released: Fri Aug 21 20:23:55 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libuuid1-2.39.3-150600.4.26.1 updated - libsmartcols1-2.39.3-150600.4.26.1 updated - libblkid1-2.39.3-150600.4.26.1 updated - libfdisk1-2.39.3-150600.4.26.1 updated - libmount1-2.39.3-150600.4.26.1 updated - util-linux-2.39.3-150600.4.26.1 updated - container:sles15-ltss-image-15.6.0-5.85 updated From sle-container-updates at lists.suse.com Sat Aug 22 08:42:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 10:42:16 +0200 (CEST) Subject: SUSE-CU-2026:9064-1: Recommended update of bci/golang Message-ID: <20260822084216.6E623FD2F@maintenance.suse.de> SUSE Container Update Advisory: bci/golang ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9064-1 Container Tags : bci/golang:1.27 , bci/golang:1.27 , bci/golang:1.27-1.71.2 , bci/golang:1.27-sles15 , bci/golang:latest , bci/golang:stable Container Release : 71.2 Severity : moderate Type : recommended References : 1272545 ----------------------------------------------------------------- The container bci/golang was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2026:3627-1 Released: Mon Aug 17 13:35:18 2026 Summary: Recommended update for go1.27 Type: recommended Severity: moderate References: 1272545 This update fixes the following issue: go1.27rc2 is the prerelease for upcoming stable version of Go. The following package changes have been done: - go1.27-doc-1.27rc2-150000.1.3.1 added - go1.27-1.27rc2-150000.1.3.1 added - go1.27-race-1.27rc2-150000.1.3.1 added - container:registry.suse.com-bci-bci-base-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated - go1.26-1.26.6-150000.1.24.1 removed - go1.26-doc-1.26.6-150000.1.24.1 removed - go1.26-race-1.26.6-150000.1.24.1 removed From sle-container-updates at lists.suse.com Sat Aug 22 08:45:12 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 10:45:12 +0200 (CEST) Subject: SUSE-CU-2026:9066-1: Security update of suse/kea Message-ID: <20260822084512.0FB98FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/kea ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9066-1 Container Tags : suse/kea:2.6 , suse/kea:2.6-79.11 Container Release : 79.11 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/kea was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - util-linux-2.40.4-150700.4.18.1 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated From sle-container-updates at lists.suse.com Sat Aug 22 08:46:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Sat, 22 Aug 2026 10:46:56 +0200 (CEST) Subject: SUSE-CU-2026:9067-1: Security update of suse/kiosk/firefox-esr Message-ID: <20260822084656.62780FD2F@maintenance.suse.de> SUSE Container Update Advisory: suse/kiosk/firefox-esr ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:9067-1 Container Tags : suse/kiosk/firefox-esr:140.14 , suse/kiosk/firefox-esr:140.14-75.14 , suse/kiosk/firefox-esr:esr , suse/kiosk/firefox-esr:latest Container Release : 75.14 Severity : important Type : security References : 1261606 1268886 1269583 CVE-2026-13595 CVE-2026-27456 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 ----------------------------------------------------------------- The container suse/kiosk/firefox-esr was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:3684-1 Released: Fri Aug 21 20:23:10 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606). - Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886). The following package changes have been done: - libsmartcols1-2.40.4-150700.4.18.1 updated - libuuid1-2.40.4-150700.4.18.1 updated - libblkid1-2.40.4-150700.4.18.1 updated - libmount1-2.40.4-150700.4.18.1 updated - libfdisk1-2.40.4-150700.4.18.1 updated - util-linux-2.40.4-150700.4.18.1 updated - container:suse-sle15-15.7-1958b7b131c62ed3148de1748fdbfd479a5b7aa095db5e1d7ebc99a6b41c5f3d-0 updated