SUSE-CU-2026:8056-1: Security update of bci/spack
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Aug 5 12:52:36 UTC 2026
SUSE Container Update Advisory: bci/spack
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8056-1
Container Tags : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.20 , bci/spack:latest
Container Release : 25.20
Severity : important
Type : security
References : 1269790 1270393 1271166 1271167 CVE-2026-11979 CVE-2026-56288
CVE-2026-56289
-----------------------------------------------------------------
The container bci/spack was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released: Fri Jul 17 13:39:27 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1269790,CVE-2026-11979
This update for libxml2 fixes the following issue
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3161-1
Released: Tue Jul 21 16:30:29 2026
Summary: Security update for patch
Type: security
Severity: low
References: 1271166,1271167,CVE-2026-56288,CVE-2026-56289
This update for patch fixes the following issues
- CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167).
- CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166).
The following package changes have been done:
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.12.10-150700.4.14.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- patch-2.7.6-150000.5.12.1 updated
- container:registry.suse.com-bci-bci-base-15.7-7c4ff84762720bbe1fc27d5076e2d45e00372024f997207f5f9cf7ede3ebfa4a-0 updated
More information about the sle-container-updates
mailing list