SUSE-CU-2026:8045-1: Security update of suse/sle15

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Aug 5 12:24:09 UTC 2026


SUSE Container Update Advisory: suse/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8045-1
Container Tags        : bci/bci-base:15.7 , bci/bci-base:15.7-5.20.53 , bci/bci-base:latest , suse/sle15:15.7 , suse/sle15:15.7-5.20.53 , suse/sle15:latest
Container Release     : 5.20.53
Severity              : important
Type                  : security
References            : 1261400 1261982 1261983 1262305 1267644 1267647 1269279 1269622
                        CVE-2026-40226 CVE-2026-41991 CVE-2026-57062 
-----------------------------------------------------------------

The container suse/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3243-1
Released:    Fri Jul 24 15:09:32 2026
Summary:     Security update for gpg2
Type:        security
Severity:    low
References:  1269279,CVE-2026-57062
This update for gpg2 fixes the following issue:

- CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released:    Fri Jul 24 15:11:25 2026
Summary:     Security update for systemd
Type:        security
Severity:    moderate
References:  1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues

Security issues fixed:

- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).

Other updates and bugfixes:

- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3269-1
Released:    Mon Jul 27 13:00:16 2026
Summary:     Security update for gzip
Type:        security
Severity:    important
References:  1269622,CVE-2026-41991
This update for gzip fixes the following issue:

- CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the
  user's PATH (bsc#1269622).


The following package changes have been done:

- gpg2-2.4.4-150600.3.18.1 updated
- gzip-1.10-150200.13.1 updated
- libudev1-254.27-150600.4.71.2 updated


More information about the sle-container-updates mailing list