SUSE-CU-2026:7985-1: Security update of bci/ruby
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Aug 5 09:17:12 UTC 2026
SUSE Container Update Advisory: bci/ruby
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7985-1
Container Tags : bci/ruby:3 , bci/ruby:3.4 , bci/ruby:3.4-25.21 , bci/ruby:3.4-sles15 , bci/ruby:latest
Container Release : 25.21
Severity : important
Type : security
References : 1252306 1253043 1257463 1262684 1268011 1268290 1268337 1268338
1268339 1270034 1270393 CVE-2025-61594 CVE-2026-41989 CVE-2026-42258
CVE-2026-47240 CVE-2026-47241 CVE-2026-47242 CVE-2026-54411
-----------------------------------------------------------------
The container bci/ruby was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3090-1
Released: Fri Jul 17 08:13:15 2026
Summary: Security update for ruby3.4
Type: security
Severity: moderate
References: 1268011,1268337,1268338,1268339,1270034,CVE-2025-61594,CVE-2026-42258,CVE-2026-47240,CVE-2026-47241,CVE-2026-47242
This update for ruby3.4 fixes the following issues
- CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011).
- CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in 'raw' argument (bsc#1268337).
- CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338).
- CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339).
- CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034).
Changes for ruby3.4:
- Update to 3.4.10:
- bundling net-imap 0.5.15.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released: Wed Jul 22 09:25:44 2026
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue
- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
(bsc#1262684).
The following package changes have been done:
- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- libatomic1-15.3.0+git11272-150000.1.12.1 updated
- libgomp1-15.3.0+git11272-150000.1.12.1 updated
- libitm1-15.3.0+git11272-150000.1.12.1 updated
- liblsan0-15.3.0+git11272-150000.1.12.1 updated
- libruby3_4-3_4-3.4.10-150700.3.4.1 updated
- ruby3.4-3.4.10-150700.3.4.1 updated
- ruby3.4-devel-3.4.10-150700.3.4.1 updated
- container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated
More information about the sle-container-updates
mailing list