SUSE-CU-2026:8038-1: Security update of suse/sle15

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 12:24:01 UTC 2026


SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8038-1
Container Tags        : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.39 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.39 , suse/sle15:latest
Container Release     : 5.20.39
Severity              : important
Type                  : security
References            : 1261900 1265450 1267189 CVE-2026-5704 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2714-1
Released:    Tue Jun 30 14:02:53 2026
Summary:     Security update for tar
Type:        security
Severity:    important
References:  1261900,1265450,1267189,CVE-2026-5704
This update for tar fixes the following issues

Security fixes:

- CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900).

Other fixes:

- Fix tar changing dir permissions temporarily even when using --no-overwrite-dir.
- Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450).
- Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2
 implementation (bsc#1267189).


The following package changes have been done:

- container-suseconnect-2.5.6-150700.4.90.4 updated
- tar-1.34-150000.3.42.1 updated


More information about the sle-container-updates mailing list