SUSE-CU-2026:8617-1: Security update of trento/trento-web

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Aug 11 08:45:17 UTC 2026


SUSE Container Update Advisory: trento/trento-web
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8617-1
Container Tags        : trento/trento-web:3.1.5 , trento/trento-web:3.1.5-build4.62.1 , trento/trento-web:latest
Container Release     : 4.62.1
Severity              : important
Type                  : security
References            : 1252306 1253043 1257463 1261400 1261982 1261983 1262305 1263656
                        1263658 1267644 1267647 1271712 CVE-2026-40226 CVE-2026-5435
                        CVE-2026-6238 
-----------------------------------------------------------------

The container trento/trento-web was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released:    Wed Jul 15 11:53:06 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released:    Fri Jul 24 15:11:25 2026
Summary:     Security update for systemd
Type:        security
Severity:    moderate
References:  1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues

Security issues fixed:

- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).

Other updates and bugfixes:

- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3515-1
Released:    Thu Aug  6 13:08:56 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    important
References:  1271712
This update for openssl-1_1 fixes the following issue

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3563-1
Released:    Tue Aug 11 05:44:13 2026
Summary:     Recommended update for trento-agent, trento-server-helm, trento-web
Type:        recommended
Severity:    moderate
References:  
This update for trento-agent, trento-server-helm, trento-web fixes the following issues:

trento-agent:

- Release 3.1.2
  * Bump github.com/prometheus-community/pro-bing from 0.8.0 to 0.9.0
  * Bump golang.org/x/sync from 0.20.0 to 0.21.0
  * Bump golang.org/x/mod from 0.36.0 to 0.37.0
  * Bump gopkg.in/ini.v1 from 1.67.2 to 1.67.3
  * Bump the common-workflows group across 1 directory with 2 updates
  * Bump github.com/hashicorp/go-plugin from 1.7.0 to 1.8.0
  * Bump isbang/compose-action from 2.5.0 to 2.6.0
  **Full Changelog**: https://github.com/trento-project/agent/compare/3.1.1...3.1.2

trento-server-helm:

- Release 3.1.4
  * Trigger release 3.1.4
  **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.3...3.1.4

- Release 3.1.3
  * Update trento-web to 3.1.5
  * Update kubectl to 1.35.4
  **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.2...3.1.3

- Release 3.1.2
  * Proper name of the check container image
  * Update busybox and kubectl images to BCI
  * Add liveness and readiness probes in Web and Wanda
  * After release fixes
  **Full Changelog**: https://github.com/trento-project/helm-charts/compare/3.1.1...3.1.2

trento-web:

- Release 3.1.5
  * Trigger release 3.1.5
  * Regenerate package lock
  **Full Changelog**: https://github.com/trento-project/web/compare/3.1.4...3.1.5

- Release 3.1.4
  * Create SIDs list properly using filtered array IDs
  * Update /assets npm lockfile to remediate transitive vulnerabilities
  **Full Changelog**: https://github.com/trento-project/web/compare/3.1.3...3.1.4

- Release 3.1.3
  * Bump `fast-uri` to 3.1.3
  * Bump redux-saga from 1.4.2 to 1.5.0 in /assets
  * Relax gcp image metadata requirement
  * Make only SAPSYSTEM and SAPLOCALHOST properties mandatory
  * Bump brace-expansion to 2.1.2 and 1.1.16
  **Full Changelog**: https://github.com/trento-project/web/compare/3.1.2...3.1.3


The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libopenssl1_1-1.1.1w-150600.5.35.2 updated
- libsystemd0-254.27-150600.4.71.2 updated
- trento-web-3.1.5-150300.1.28.2 updated
- container:registry.suse.com-bci-bci-base-15.7-5a26f31e499eb470f2ecdfa3d3b2d2ebcc83b2bc5b3b443e8d494e13a4b79b06-0 updated


More information about the sle-container-updates mailing list