SUSE-CU-2026:7941-1: Security update of suse/mariadb
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Aug 4 17:50:33 UTC 2026
SUSE Container Update Advisory: suse/mariadb
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7941-1
Container Tags : suse/mariadb:11.8 , suse/mariadb:11.8.8 , suse/mariadb:11.8.8-79.4 , suse/mariadb:latest
Container Release : 79.4
Severity : important
Type : security
References : 1271017 1271018 1271399 1271458 1271459 1271629 CVE-2026-14380
CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082
-----------------------------------------------------------------
The container suse/mariadb was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3415-1
Released: Thu Jul 30 08:54:36 2026
Summary: Security update for perl-DBI
Type: security
Severity: important
References: 1271017,1271018,1271399,1271458,1271459,1271629,CVE-2026-14380,CVE-2026-14740,CVE-2026-15043,CVE-2026-15392,CVE-2026-60081,CVE-2026-60082
This update for perl-DBI fixes the following issues
- CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code
execution (bsc#1271018).
- CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash
(bsc#1271017).
- CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters
(bsc#1271399).
- CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File`
allows for arbitrary file reads and writes (bsc#1271629).
- CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file
memory-amplification DoS (bsc#1271458).
- CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row
can lead to a process crash (bsc#1271459).
The following package changes have been done:
- perl-DBI-1.647.0-150600.12.18.1 updated
- container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated
More information about the sle-container-updates
mailing list