SUSE-IU-2026:6274-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 13 07:53:45 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6274-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.223 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 6.223
Severity          : critical
Type              : security
References        : 1272922 1272923 1272924 1272925 1272926 1272927 1272928 1272930
                        CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 CVE-2026-16530
                        CVE-2026-16531 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 842
Released:    Tue Aug 11 13:11:14 2026
Summary:     Security update for pcp
Type:        security
Severity:    critical
References:  1272922,1272923,1272924,1272925,1272926,1272927,1272928,1272930,CVE-2026-16524,CVE-2026-16526,CVE-2026-16527,CVE-2026-16529,CVE-2026-16530,CVE-2026-16531
This update for pcp fixes the following issues:

- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).
- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials
  (bsc#1272923).
- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).
- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).
- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).
- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).
- command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).
- command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).


The following package changes have been done:

- SL-Micro-release-6.0-25.120 updated
- pcp-conf-6.2.0-2.1 updated
- libpcp3-6.2.0-2.1 updated
- libpcp_import1-6.2.0-2.1 updated
- container:SL-Micro-base-container-2.1.3-7.186 updated


More information about the sle-container-updates mailing list