SUSE-CU-2026:8669-1: Security update of suse/sle-micro-rancher/5.4
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 13 07:46:22 UTC 2026
SUSE Container Update Advisory: suse/sle-micro-rancher/5.4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8669-1
Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.167 , suse/sle-micro-rancher/5.4:latest
Container Release : 4.5.167
Severity : important
Type : security
References : 1185845 1237888 1240054 1243603 1254767 1255616 1258718 1262573
1263718 1263788 1264013 1264076 1264089 1265308 1266238 1266850
1267384 1267435 1267494 1267596 1267656 1267715 1268029 1269172
1269174 1269181 1269188 1269289 1269577 1269584 1269623 1269731
1269773 1269986 1269988 1269993 1269997 1270230 1270257 1271526
1271825 1271899 1271904 1271908 1271912 1271964 1272176 1272180
1272207 1272242 1272263 1272268 1272554 1272607 1272678 1272694
1272855 1272865 1272904 1272907 1272918 1273004 1273035 1273097
1273231 1274072 1274432 CVE-2022-4994 CVE-2023-2058 CVE-2023-53995
CVE-2025-21710 CVE-2025-54518 CVE-2026-15816 CVE-2026-31431 CVE-2026-31598
CVE-2026-31628 CVE-2026-31759 CVE-2026-41992 CVE-2026-43033 CVE-2026-44605
CVE-2026-46052 CVE-2026-46056 CVE-2026-46080 CVE-2026-46109 CVE-2026-46145
CVE-2026-46174 CVE-2026-46193 CVE-2026-46243 CVE-2026-46323 CVE-2026-46333
CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52986 CVE-2026-53050
CVE-2026-53131 CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53256
CVE-2026-53260 CVE-2026-53267 CVE-2026-53354 CVE-2026-53357 CVE-2026-53375
CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-63794 CVE-2026-63806
CVE-2026-63807 CVE-2026-63824 CVE-2026-63829 CVE-2026-63893 CVE-2026-63917
CVE-2026-63919 CVE-2026-63921 CVE-2026-63922 CVE-2026-63924 CVE-2026-63971
CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189
CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600
-----------------------------------------------------------------
The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3592-1
Released: Wed Aug 12 11:15:00 2026
Summary: Security update for gzip
Type: security
Severity: moderate
References: 1269623,1272554,CVE-2026-41992
This update for gzip fixes the following issues:
- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3593-1
Released: Wed Aug 12 13:29:35 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1185845,1237888,1243603,1254767,1255616,1258718,1262573,1263718,1263788,1264013,1264076,1264089,1265308,1266238,1266850,1267384,1267435,1267494,1267596,1267656,1267715,1268029,1269172,1269174,1269181,1269188,1269289,1269577,1269731,1269773,1269986,1269988,1269993,1269997,1270230,1270257,1271526,1271825,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272207,1272242,1272263,1272268,1272607,1272678,1272694,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273097,1273231,1274072,CVE-2022-4994,CVE-2023-2058,CVE-2023-53995,CVE-2025-21710,CVE-2025-54518,CVE-2026-31431,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-46052,CVE-2026-46056,CVE-2026-46080,CVE-2026-46109,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46333,CVE-2026-52956,CVE-2026-52958,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53131,CVE-2026-53196,CVE-2026-53224,CVE-2026-53246,CVE-2026-53256,CVE-2026-53260,CVE-2026-53267,CVE-2026-53
354,CVE-2026-53357,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63829,CVE-2026-63893,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600
The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues:
The following security issues were fixed:
- CVE-2022-4994: KVM: x86: wean fast IN from emulator_pio_in (bsc#1273097).
- CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616).
- CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).
- CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).
- CVE-2026-46145: RDMA/mana: Validate rx_hash_key_len (bsc#1267715).
- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
- CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181).
- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).
- CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).
- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
- CVE-2026-53260: preempt: Provide preempt_[dis|en]able_nested() (bsc#1269731).
- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
- CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230).
- CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).
- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).
- CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908).
- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).
- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).
- CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263).
- CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180).
- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).
- CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607).
- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904).
- CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907).
- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918).
- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: recompute network header pointer once (bsc#1272855).
- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678).
- CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694).
- CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865).
- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035).
- CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242).
- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207).
- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231).
- CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004).
- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).
The following non security issues were fixed:
- hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
- mkspec-dtb: Skip missing DTBs.
- pkspec-dtb: Fix dtb-al rename.
- posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
- posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912).
- posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
- posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912).
- posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
- posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
- posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
- posix-timers: Add proper state tracking (bsc#1271912).
- posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
- posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
- posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
- posix-timers: Consolidate signal queueing (bsc#1271912).
- posix-timers: Consolidate timer setup (bsc#1271912).
- posix-timers: Cure si_sys_private race (bsc#1271912).
- posix-timers: Document common_clock_get() correctly (bsc#1271912).
- posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912).
- posix-timers: Polish coding style in a few places (bsc#1271912).
- posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912).
- sctp: validate embedded address parameter length (git-fixes).
- time: Switch to hrtimer_setup() (bsc#1271912).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3599-1
Released: Wed Aug 12 13:53:05 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1274432,CVE-2026-15816
This update for dracut fixes the following issue:
Update to version 055+suse.367.g85633e8.
Securitys issue fixed:
- CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()`
(bsc#1274432).
Other updates and bugfixes:
- Fix(base): sanitize message written by `die()` to the emergency hook.
- Feat(base): add escape function implementing `printf %q`.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3600-1
Released: Wed Aug 12 13:59:10 2026
Summary: Security update for rpm
Type: security
Severity: important
References: 1240054,1269584,CVE-2026-44605
This update for rpm fixes the following issues:
Security issues fixed:
- CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot
table (bsc#1269584).
Other updates and bugfixes:
- Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054).
The following package changes have been done:
- dracut-mkinitrd-deprecated-055+suse.367.g85633e8-150400.3.52.1 updated
- dracut-055+suse.367.g85633e8-150400.3.52.1 updated
- gzip-1.10-150200.16.1 updated
- kernel-default-5.14.21-150400.24.235.1 updated
- rpm-ndb-4.14.3-150400.59.19.1 updated
More information about the sle-container-updates
mailing list