SUSE-IU-2026:6268-1: Security update of suse/sle-micro/base-5.5
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 13 07:07:31 UTC 2026
SUSE Image Update Advisory: suse/sle-micro/base-5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6268-1
Image Tags : suse/sle-micro/base-5.5:2.0.4 , suse/sle-micro/base-5.5:2.0.4-5.8.306 , suse/sle-micro/base-5.5:latest
Image Release : 5.8.306
Severity : important
Type : security
References : 1185845 1226591 1237888 1239015 1240054 1240552 1240727 1243603
1244229 1245457 1245728 1245729 1245730 1245731 1246203 1246212
1251135 1251971 1252266 1253049 1254767 1255616 1256690 1257466
1257472 1257541 1258718 1259580 1260347 1261648 1262573 1263010
1263718 1263788 1264013 1264053 1264076 1264089 1264387 1264558
1264779 1265308 1265928 1266238 1266402 1266414 1266758 1266765
1266850 1266913 1267375 1267384 1267435 1267494 1267584 1267596
1267656 1267715 1268029 1268237 1268750 1268989 1269172 1269174
1269181 1269188 1269289 1269512 1269513 1269577 1269584 1269623
1269731 1269773 1269798 1269986 1269988 1269993 1269997 1270257
1271011 1271526 1271825 1271866 1271899 1271904 1271908 1271912
1271964 1272176 1272180 1272207 1272242 1272263 1272268 1272554
1272573 1272607 1272665 1272678 1272693 1272694 1272855 1272865
1272904 1272907 1272918 1273004 1273035 1273097 1273231 1274072
CVE-2022-4994 CVE-2023-2058 CVE-2023-53995 CVE-2024-38542 CVE-2025-21710
CVE-2025-21953 CVE-2025-54518 CVE-2026-31431 CVE-2026-31542 CVE-2026-31598
CVE-2026-31628 CVE-2026-31759 CVE-2026-41992 CVE-2026-43033 CVE-2026-43056
CVE-2026-43211 CVE-2026-43276 CVE-2026-43440 CVE-2026-44605 CVE-2026-46052
CVE-2026-46056 CVE-2026-46080 CVE-2026-46084 CVE-2026-46109 CVE-2026-46117
CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46174 CVE-2026-46193
CVE-2026-46243 CVE-2026-46323 CVE-2026-46333 CVE-2026-52933 CVE-2026-52956
CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050 CVE-2026-53131
CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256 CVE-2026-53260
CVE-2026-53267 CVE-2026-53297 CVE-2026-53324 CVE-2026-53357 CVE-2026-53375
CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806
CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893
CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924
CVE-2026-63946 CVE-2026-63971 CVE-2026-63975 CVE-2026-63984 CVE-2026-63994
CVE-2026-64106 CVE-2026-64189 CVE-2026-64530 CVE-2026-64560 CVE-2026-64561
CVE-2026-64564 CVE-2026-64600
-----------------------------------------------------------------
The container suse/sle-micro/base-5.5 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3592-1
Released: Wed Aug 12 11:15:00 2026
Summary: Security update for gzip
Type: security
Severity: moderate
References: 1269623,1272554,CVE-2026-41992
This update for gzip fixes the following issues:
- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3595-1
Released: Wed Aug 12 13:33:11 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1185845,1226591,1237888,1239015,1240552,1240727,1243603,1244229,1245457,1245728,1245729,1245730,1245731,1246203,1246212,1251135,1251971,1252266,1253049,1254767,1255616,1256690,1257466,1257472,1257541,1258718,1259580,1260347,1261648,1262573,1263010,1263718,1263788,1264013,1264053,1264076,1264089,1264387,1264558,1264779,1265308,1265928,1266238,1266402,1266414,1266758,1266765,1266850,1266913,1267375,1267384,1267435,1267494,1267584,1267596,1267656,1267715,1268029,1268237,1268750,1268989,1269172,1269174,1269181,1269188,1269289,1269512,1269513,1269577,1269731,1269773,1269798,1269986,1269988,1269993,1269997,1270257,1271011,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272573,1272607,1272665,1272678,1272693,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2024-38542,CVE-2025-21710,CVE-2025-21953,CVE-2025-54518,CVE-2026-31431,CVE
-2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43056,CVE-2026-43211,CVE-2026-43276,CVE-2026-43440,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46084,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52933,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-6
4600
The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues:
The following security issues were fixed:
- CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097).
- CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616).
- CVE-2024-38542: RDMA/mana_ib: boundary check before installing cq callbacks (bsc#1226591).
- CVE-2025-21953: net: mana: cleanup mana struct after debugfs_remove() (bsc#1240727).
- CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).
- CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).
- CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715).
- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
- CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989).
- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
- CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181).
- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).
- CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).
- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
- CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731).
- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
- CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).
- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).
- CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908).
- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).
- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).
- CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263).
- CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180).
- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).
- CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573).
- CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607).
- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904).
- CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907).
- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918).
- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855).
- CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665).
- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678).
- CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694).
- CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865).
- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035).
- CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242).
- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207).
- CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004).
- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231).
- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).
The following non security issues were fixed:
- block: fix use-after-free of q->q_usage_counter (bsc#1268750).
- cpumask: add cpumask_weight_andnot() (bsc#1239015).
- Drivers: hv: fix missing kernel-doc description for 'size' in request_arr_init() (git-fixes).
- Drivers: hv: remove stale comment (git-fixes).
- Drivers: hv: vmbus: Clean up sscanf format specifier in target_cpu_store() (git-fixes).
- Drivers: hv: vmbus: Fix sysfs output format for ring buffer index (git-fixes).
- Drivers: hv: vmbus: Fix typos in vmbus_drv.c (git-fixes).
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes).
- Drivers: hv: vmbus: Remove duplication and cleanup code in create_gpadl_header() (git-fixes).
- Drivers: hv: vmbus: Update indentation in create_gpadl_header() (git-fixes).
- drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes).
- drm/hyperv: validate VMBus packet size in receive callback (git-fixes).
- ethtool: Implement ethtool_puts() (git-fixes).
- hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
- hv: utils: handle and propagate errors in kvp_register (git-fixes).
- hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).
- hv_netvsc: Use VF's tso_max_size value when data path is VF (bsc#1246203).
- hv_sock: fix ARM64 support (git-fixes).
- hv_utils: Allow implicit ICTIMESYNCFLAG_SYNC (git-fixes).
- hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).
- IPv6/GRO: generic helper to remove temporary HBH/jumbo header in (bsc#1246203).
- ipv6/gso: remove temporary HBH/jumbo header (bsc#1246203).
- ipv6: add struct hop_jumbo_hdr definition (bsc#1246203).
- jiffies: Cast to unsigned long in secs_to_jiffies() conversion (bsc#1257466).
- jiffies: Define secs_to_jiffies() (bsc#1257466).
- lib/bitmap: add bitmap_weight_and() (bsc#1239015).
- mkspec-dtb: Skip missing DTBs.
- net/mana: fix warning in the writer of client oob (git-fixes).
- net/mana: Null service_wq on setup error to prevent double destroy (git-fixes).
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866).
- net: mana: add a function to spread IRQs per CPUs (bsc#1239015).
- net: mana: Add debug logs in MANA network driver (bsc#1246212).
- net: mana: Add handler for hardware servicing events (bsc#1245730 bsc#1251971).
- net: mana: Add MAC address to vPort logs and clarify error messages (git-fixes).
- net: mana: Add metadata support for xdp mode (git-fixes).
- net: mana: add msix index sharing between EQs (git-fixes).
- net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes).
- net: mana: Add standard counter rx_missed_errors (git-fixes).
- net: mana: Add support for auxiliary device servicing events (bsc#1251971).
- net: mana: Add support for Multi Vports on Bare metal (bsc#1244229).
- net: mana: Add support for PF device 0x00C1 (bsc#1268237).
- net: mana: Allow irq_setup() to skip cpus for affinity (bsc#1245457).
- net: mana: Allow tso_max_size to go up-to GSO_MAX_SIZE (bsc#1246203).
- net: mana: Assigning IRQ affinity on HT cores (bsc#1239015).
- net: mana: check xdp_rxq registration before unreg in mana_destroy_rxq() (git-fixes).
- net: mana: Create separate EQs for each vPort (git-fixes).
- net: mana: Don't overwrite port probe error with add_adev result (git-fixes).
- net: mana: Drop TX skb on post_work_request failure and unmap resources (git-fixes).
- net: mana: explain irq_setup() algorithm (bsc#1245457).
- net: mana: Expose additional hardware counters for drop and TC via ethtool (bsc#1245729).
- net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414).
- net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes).
- net: mana: Fix crash from unvalidated SHM offset read from BAR0 during FLR (git-fixes).
- net: mana: Fix double destroy_workqueue on service rescan PCI path (git-fixes).
- net: mana: Fix EQ leak in mana_remove on NULL port (git-fixes).
- net: mana: Fix irq_contexts memory leak in mana_gd_setup_irqs (bsc#1239015).
- net: mana: Fix memory leak in mana_gd_setup_irqs (bsc#1239015).
- net: mana: fix spelling for mana_gd_deregiser_irq() (git-fixes).
- net: mana: Fix spelling mistake 'enforecement' -> 'enforcement' (git-fixes).
- net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928).
- net: mana: fix use-after-free in add_adev() error path (git-fixes).
- net: mana: fix use-after-free in mana_hwc_destroy_channel() by reordering teardown (git-fixes).
- net: mana: Fix use-after-free in reset service rescan path (git-fixes).
- net: mana: Fix warnings for missing export.h header inclusion (git-fixes).
- net: mana: Guard mana_remove against double invocation (git-fixes).
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (bsc#1269798).
- net: mana: Handle hardware recovery events when probing the device (bsc#1257466).
- net: mana: Handle Reset Request from MANA NIC (bsc#1245728 bsc#1251971).
- net: mana: Handle SKB if TX SGEs exceed hardware limit (git-fixes).
- net: mana: Handle unsupported HWC commands (git-fixes).
- net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes).
- net: mana: hardening: Validate adapter_mtu from MANA_QUERY_DEV_CONFIG (git-fixes).
- net: mana: hardening: Validate doorbell ID from GDMA_REGISTER_DEVICE response (git-fixes).
- net: mana: Implement ndo_tx_timeout and serialize queue resets per port (bsc#1257472).
- net: mana: Init gf_stats_work before potential error paths in probe (git-fixes).
- net: mana: Init link_change_work before potential error paths in probe (git-fixes).
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1269798).
- net: mana: Move hardware counter stats from per-port to per-VF context (git-fixes).
- net: mana: Probe rdma device in mana driver (git-fixes).
- net: mana: Record doorbell physical address in PF mode (bsc#1244229).
- net: mana: Reduce waiting time if HWC not responding (bsc#1252266).
- net: mana: remove double CQ cleanup in mana_create_rxq error path (git-fixes).
- net: mana: Return error code from mana_create_rxq() (git-fixes).
- net: mana: Ring doorbell at 4 CQ wraparounds (git-fixes).
- net: mana: Set default number of queues to 16 (bsc#1261648).
- net: mana: Set tx_packets to post gso processing packet count (bsc#1245731).
- net: mana: Skip redundant detach on already-detached port (git-fixes).
- net: mana: Skip WQ object destruction for uninitialized RXQ (git-fixes).
- net: mana: Support HW link state events (bsc#1253049).
- net: mana: Switch to page pool for jumbo frames (git-fixes).
- net: mana: Trigger VF reset/recovery on health check failure due to HWC timeout (bsc#1259580).
- net: mana: Use at least SZ_4K in doorbell ID range check (git-fixes).
- net: mana: use ethtool string helpers (git-fixes).
- net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765).
- net: mana: Use mana_cleanup_port_context() for rxq cleanup (git-fixes).
- net: mana: Use pci_name() for debugfs directory naming (git-fixes).
- net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765).
- net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402).
- net: mana: Validate the packet length reported by the NIC (git-fixes).
- PCI: hv: Correct a comment (git-fixes).
- PCI: hv: Fix ring buffer size calculation (git-fixes).
- PCI: hv: remove unnecessary module_init/exit functions (git-fixes).
- PCI: hv: Remove unused field pci_bus in struct hv_pcibus_device (git-fixes).
- PCI: hv: Set default NUMA node to 0 for devices without affinity info (bsc#1261648).
- pkspec-dtb: Fix dtb-al rename.
- posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
- posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912).
- posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
- posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912).
- posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
- posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
- posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
- posix-timers: Add proper state tracking (bsc#1271912).
- posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
- posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
- posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
- posix-timers: Consolidate signal queueing (bsc#1271912).
- posix-timers: Consolidate timer setup (bsc#1271912).
- posix-timers: Cure si_sys_private race (bsc#1271912).
- posix-timers: Document common_clock_get() correctly (bsc#1271912).
- posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912).
- posix-timers: Polish coding style in a few places (bsc#1271912).
- posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912).
- RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() (git-fixes).
- RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() (git-fixes).
- RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() (git-fixes).
- RDMA/mana: Validate rx_hash_key_len (git-fixes).
- RDMA/mana_ib: Access remote atomic for MRs (bsc#1251135).
- RDMA/mana_ib: add additional port counters (bsc#1251135).
- RDMA/mana_ib: Add CQ interrupt support for RAW QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add device statistics support (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add device-memory support (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add EQ creation for rnic adapter (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add port statistics support (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add support of 4M, 1G, and 2G pages (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Add support of mana_ib for RNIC and ETH nic (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: add support of multiple ports (bsc#1251135).
- RDMA/mana_ib: Adding and deleting GIDs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Allocate PAGE aligned doorbell index (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Allow registration of DMA-mapped memory in PDs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: check cqe length for kernel CQs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: cleanup the usage of mana_gd_send_request() (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Configure mac address in RNIC (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Create and destroy RC QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Create and destroy rnic adapter (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: create and destroy RNIC cqs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Create and destroy UD/GSI QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: create EQs for RNIC CQs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: create kernel-level CQs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: create/destroy AH (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Disable RX steering on RSS QP destroy (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Drain send wrs of GSI QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Enable RoCE on port 1 (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Ensure variable err is initialized (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: extend mana QP table (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Extend modify QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: extend query device (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Fix DSCP value in modify QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Fix error code in probe() (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Fix integer overflow during queue creation (bsc#1251135).
- RDMA/mana_ib: Fix missing ret value (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Handle net event for pointing to the current netdev (bsc#1256690).
- RDMA/mana_ib: helpers to allocate kernel queues (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Implement DMABUF MR support (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: implement get_dma_mr (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Implement port parameters (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: implement req_notify_cq (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: implement uapi for creation of rnic cq (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Implement uapi to create and destroy RC QP (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: indicate CM support (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: initialize err for empty send WR lists (git-fixes).
- RDMA/mana_ib: introduce a helper to remove cq callbacks (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Introduce helpers to create and destroy mana queues (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Introduce mana_ib_get_netdev helper function (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Introduce mana_ib_install_cq_cb helper function (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Introduce mdev_to_gc helper function (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Modify QP state (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: polling of CQs for GSI/UD (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Process QP error events in mana_ib (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: query device capabilities (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Query feature_flags bitmask from FW (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: register RDMA device with GDMA (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: remove useless return values from dbg prints (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes).
- RDMA/mana_ib: request error CQEs when supported (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Set correct device into ib (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: set node_guid (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Support memory windows (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: support of the zero based MRs (bsc#1251135).
- RDMA/mana_ib: Take CQ type from the device type (bsc#1257541).
- RDMA/mana_ib: UD/GSI QP creation for kernel (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: UD/GSI work requests (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: unify mana_ib functions to support any gdma device (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (bsc#1271011 jsc#PED-16573).
- RDMA/mana_ib: Use num_comp_vectors of ib_device (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Use safer allocation function() (bsc#1251135).
- RDMA/mana_ib: Use struct mana_ib_queue for CQs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Use struct mana_ib_queue for RAW QPs (bsc#1240552 jsc#PED-12576).
- RDMA/mana_ib: Use struct mana_ib_queue for WQs (bsc#1240552 jsc#PED-12576).
- sched/topology: Introduce for_each_numa_hop_mask() (bsc#1239015).
- sched/topology: Introduce sched_numa_hop_mask() (bsc#1239015).
- scsi: storvsc: Handle PERSISTENT_RESERVE_IN truncation for Hyper-V vFC (git-fixes).
- scsi: storvsc: Remove redundant ternary operators (git-fixes).
- scsi: storvsc: Replace symbolic permissions with octal (git-fixes).
- sctp: validate embedded address parameter length (git-fixes).
- tcp: gso: really support BIG TCP (bsc#1246203).
- time: Switch to hrtimer_setup() (bsc#1271912).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3600-1
Released: Wed Aug 12 13:59:10 2026
Summary: Security update for rpm
Type: security
Severity: important
References: 1240054,1269584,CVE-2026-44605
This update for rpm fixes the following issues:
Security issues fixed:
- CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot
table (bsc#1269584).
Other updates and bugfixes:
- Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054).
The following package changes have been done:
- gzip-1.10-150200.16.1 updated
- rpm-4.14.3-150400.59.19.1 updated
- kernel-default-5.14.21-150500.55.182.1 updated
More information about the sle-container-updates
mailing list