SUSE-IU-2026:6054-1: Security update of suse/sl-micro/6.1/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 07:19:37 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6054-1
Image Tags        : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.144 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release     : 7.144
Severity          : critical
Type              : security
References        : 1230797 1232063 1232227 1233588 1236321 1236390 1236392 1238484
                        1239461 1244917 1246501 1253260 1254094 1254323 1255285 1255451
                        1257007 1257153 1257244 1257476 1266304 1266361 1268144 1268145
                        1268275 1268349 1269892 1270008 1270009 1270010 1270016 1270018
                        1270021 1271372 1271386 CVE-2024-58251 CVE-2025-15649 CVE-2025-24912
                        CVE-2025-59529 CVE-2026-12087 CVE-2026-13221 CVE-2026-41579 CVE-2026-57432
                        CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014
                        CVE-2026-58016 CVE-2026-58374 CVE-2026-8376 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 642
Released:    Fri Jul 31 11:07:43 2026
Summary:     Security update for wpa_supplicant
Type:        security
Severity:    moderate
References:  1230797,1239461,1269892,CVE-2025-24912,CVE-2026-58374
This update for wpa_supplicant fixes the following issues:

Security issues fixed:

- CVE-2025-24912: RADIUS pending request dropping (bsc#1239461).
- CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an
  unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892).
- Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/.
- Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/.

Other updates and bugfixes:

- Revert 'Mark authorization completed on driver indication during 4-way HS offload' because of WPA2-PSK/WPA-SAE
  connection problems with brcmfmac wifi hardware (bsc#1230797).

-----------------------------------------------------------------
Advisory ID: 644
Released:    Fri Jul 31 11:51:56 2026
Summary:     Security update for perl
Type:        security
Severity:    important
References:  1266304,1266361,1268349,1271372,1271386,CVE-2025-15649,CVE-2026-12087,CVE-2026-13221,CVE-2026-57432,CVE-2026-8376
This update for perl fixes the following issues

- CVE-2025-15649: `IO:Uncompress:Unzip` propagates uncaught exception when parsing zip header with malformed DOS date
  (bsc#1266361).
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
  (bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
  (bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
  (bsc#1271372).
- CVE-2026-13221: regex trie branch-count overflow leads to silent false-positive/negative pattern matching
  (bsc#1271386).

-----------------------------------------------------------------
Advisory ID: 648
Released:    Mon Aug  3 09:33:31 2026
Summary:     Security update for net-tools
Type:        security
Severity:    moderate
References:  1254323,CVE-2024-58251
This update for net-tools fixes the following issues:

- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323).

-----------------------------------------------------------------
Advisory ID: 647
Released:    Mon Aug  3 09:43:21 2026
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues

- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
  (bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
  bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
  read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
  bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).

-----------------------------------------------------------------
Advisory ID: 652
Released:    Tue Aug  4 13:04:57 2026
Summary:     Security update for multipath-tools
Type:        security
Severity:    critical
References:  1232063,1232227,1233588,1236321,1236390,1236392,1238484,1244917,1246501,1253260,1254094,1255285,1257007,1257153,1257244,1257476,1268144,1268145
This update for multipath-tools fixes the following issues:

Update to version 0.10.7~1+211+suse.18f1559.

Security issues fixed:

- kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device
  or disk image(bsc#1268145).
- kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256
  consecutive format labels (bsc#1268144).

Other updates and bugfixes:

- Fix system with multipath failing to boot during first boot during the installation (bsc#1232063).
- Fix code that leads to `is_bit_set_in_bitfield: bitfield overflow: 1 >= 0` message showing up in syslog
  (bsc#1255285).
- Version 0.10.7~1+211+suse.18f1559:
  * Fix ALUA asymmetric access state descriptions in multipathd logs, so that
    the same terms are used as by the kernel ('lba-dependent', 'transitioning').
  * Don't set a hardware handler for bio-based multipath devices. The kernel
    rejects this anyway.
  * Fix WWID detection for legacy devices that use the older SCSI-2 VPD page
    0x83 format for their device identifier.
  * Fix duplicate 'checker timed out' log messages when `log_checker_err` is
    set to `once`. (bsc#1254094)
  * Avoid potential buffer overflows in the iet and datacore prioritizers.
  * iet prioritizer: avoid misleading error message with systemd 256 and
    newer, and properly use udev to derive path parameters.
    (gh#opensvc/multipath-tools#145)
- Version 0.10.6+201+suse.9f189e79:
  * libmultipath: reduce log level of 'map X has no targets' (bsc#1257476)
- Version 0.10.6+200+suse.547788f4 (bsc#1257007):
  * kpartx: fix segfault when operating on regular files (bsc#1257244, bsc#1257153)
  * multipathd: print path offline message even without a checker
    (bsc#1254094)
  * Fix command descriptions in the multipathd man page.
  * Fix ISO C23 compatibility issue causing errors with new compilers.
  * Fix memory leak caused by not joining the 'init unwinder' thread.
  * Fix memory leaks in kpartx.
  * Print the warning 'setting scsi timeouts is unsupported for protocol' only
    once per protocol.
  * Make sure multipath-tools is compiled with the compiler flag
    `-fno-strict-aliasing`. (gh#opensvc/multipath-tools#130, bsc#1255285)
- Version 0.10.5+213+suse.04c3a0ac:
  * Log offline path state if 'log_checker_err always' is set
  * mpathpersist: Fix REPORT CAPABILITIES output
- Version 0.10.5+190+suse.a9f87040:
  * CI: GitHub workflow updates. No code changes.
- _service: switched to tar_scm for git LFS.
- Version 0.10.5+125+suse.1ed79487:
  - Fixes from upstream 0.10.5 (see also NEWS.md) (bsc#1253260)
    * Improved the communication with **udev** and **systemd** by triggering
      uevents when path devices are added to or removed from multipath maps,
      or when `multipathd reconfigure` is executed after changing blacklist
      directives in `multipath.conf`.
    * Failed paths should be checked every `polling_interval`. In certain cases,
      this wouldn't happen, because the check interval wasn't reset by multipathd.
    * It could happen that multipathd would accidentally release a SCSI persistent
      reservation held by another node. Fix it.
    * After manually failing some paths and then reinstating them, sometimes
      the reinstated paths were immediately failed again by multipathd. Fix it.
    * Various minor fixes reported by coverity.
- Version 0.10.3+124+suse.ed5b4b11:
  * multipath-tools: add HPE MSA Gen7 (2070/2072) to hwtable (bsc#1246501)
- Version 0.10.2+123+suse.48d66ee8:
  * multipathd: cli_reinstate(): avoid reinstated paths being failed again
    (bsc#1244917)
- Version 0.10.2+122+suse.51e02cc:
  * multipathd: fix hang during shutdown with queuing maps
    (bsc#1238484).
  * This adds multipathd-queueing.service.
- Version 0.10.2+117+suse.33411aa:
  * multipathd: trigger uevents for blacklisted paths in reconfigure
    (bsc#1236321)
  * Make sure maps are reloaded in the path checker loop after detecting an
    inconsistent or wrong kernel state (bsc#1236392)
  * Make sure udev and systemd notice changes in multipath path state
    when devices are added to or removed from multipath maps (bsc#1236321)
  * Fix the problem that `group_by_tpg` might be disabled if one or more
    paths were offline during initial configuration (bsc#1236392)
  * Fix multipathd crash because of invalid path group index value, for example
    if an invalid path device was removed from a map.
    (gh#opensvc/multipath-tools#105, bsc#1236392)
  * Fixed a memory leak in the nvme foreign library.
  * Fixed a problem in the marginal path detection algorithm that could cause
    the io error check for a recently failed path to be delayed.
    (bsc#1236390)
  * Reduce log level of harmless 'map ... doesn't exist' message
- Version 0.10.1~2+112+suse.b66763a:
  * libmultipath: reduce log level of 'map X has multiple targets'
    (bsc#1233588)
- Version 0.10.1~1+113+suse.d6eca5e:
  * This is a pre-release of the upstream stable release 0.10.1.
  * libmultipath: dm_get_maps(): don't bail out for single-map failures
    (bsc#1233588, gh#opensvc/multipath-tools#102)
  * libmultipath: don't print error message if WATCHDOG_USEC is 0
    (bsc#1232227)
  * libmultipath: don't set dev_loss_tmo to 0 for NO_PATH_RETRY_FAIL
  * multipathd: fix deferred_failback_tick for reload removes
- Version 0.10.0+108+suse.2c2e597:
  * Update fix for bsc#1232063 to upstream-accepted solution
- Version 0.10.0+106+suse.ffbdb7a:
  * Fix reboot hang if uevent is processed for suspended device
    (bsc#1232063)

-----------------------------------------------------------------
Advisory ID: 650
Released:    Tue Aug  4 13:08:52 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1255451,CVE-2025-59529
This update for avahi fixes the following issue

- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).

-----------------------------------------------------------------
Advisory ID: 654
Released:    Tue Aug  4 17:21:01 2026
Summary:     Security update for runc
Type:        security
Severity:    low
References:  1268275,CVE-2026-41579
This update for runc fixes the following issues:

- CVE-2026-41579: runc allows a malicious image with a /dev symlink to trigger limited host filesystem integrity
  violations (bsc#1268275).

Changes for runc:

- update to 1.3.6:

 * Various integration test improvements. (#5222, #5237, #5226,
 #5229, #5239, #5249, #5269, #5287, #5295, #5304)
 * When masking directories with `maskPaths`, runc will now re-
 use a single `tmpfs` instance (which is not writeable) to
 reduce the number `tmpfs` superblocks that need to be reaped
 when containers die (in particular, Kubernetes applies masks
 to per-CPU sysfs directories which get expensive quickly).
  
- update to 1.3.5
 
 * Recursive atime-related mount flags (rrelatime et al.) are now applied
 properly. (#5115, #5098)
 * PR #4757 caused a regression that resulted in spurious
 cannot start a container that has stopped errors when
 running runc create and has thus been reverted. (#5158,
 #5153, #5151, #4645, #4757)
 * Updated builds to Go 1.25, libseccomp v2.6.0. (#5111, #5053)
 * Minor signing keyring updates. (#5146, #5139, #5144, #5148)


The following package changes have been done:

- perl-base-5.38.2-slfo.1.1_3.1 updated
- SL-Micro-release-6.1-slfo.1.12.60 updated
- libglib-2_0-0-2.78.6-slfo.1.1_7.1 updated
- libgobject-2_0-0-2.78.6-slfo.1.1_7.1 updated
- libgmodule-2_0-0-2.78.6-slfo.1.1_7.1 updated
- libgio-2_0-0-2.78.6-slfo.1.1_7.1 updated
- glib2-tools-2.78.6-slfo.1.1_7.1 updated
- wpa_supplicant-2.11-slfo.1.1_2.1 updated
- kpartx-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated
- libavahi-common3-0.8-slfo.1.1_8.1 updated
- runc-1.3.6-slfo.1.1_1.1 updated
- libavahi-core7-0.8-slfo.1.1_8.1 updated
- libavahi-client3-0.8-slfo.1.1_8.1 updated
- net-tools-2.10-slfo.1.1_3.1 updated
- avahi-0.8-slfo.1.1_8.1 updated
- perl-5.38.2-slfo.1.1_3.1 updated
- libmpath0-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated
- multipath-tools-0.10.7~1+211+suse.18f1559-slfo.1.1_1.1 updated
- container:SL-Micro-base-container-2.2.1-5.161 updated


More information about the sle-container-updates mailing list