SUSE-IU-2026:6320-1: Security update of suse/sl-micro/6.2/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Aug 15 07:08:49 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6320-1
Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.96 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release : 8.96
Severity : important
Type : security
References : 1268352 1268353 CVE-2026-44943 CVE-2026-44944
-----------------------------------------------------------------
The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1458
Released: Fri Aug 14 08:41:35 2026
Summary: Security update for open-iscsi
Type: security
Severity: important
References: 1268352,1268353,CVE-2026-44943,CVE-2026-44944
This update for open-iscsi fixes the following issues:
Update to version 2.1.12.suse+0.8f77cf16:
- CVE-2026-44943: improper limitation of pathname to a restricted directory allows remote MITM attackers to create
root-owned files outside the database and inject lines into records (bsc#1268353).
- CVE-2026-44944: incorrect authorization allows unpriviledged local users to use the `isscsiuio` control socket
(bsc#1268352).
Changes for open-iscsi:
- Version 2.1.12.suse+0.8f77cf16:
* Fix security issues recently discovered by Keith at Linneman Labs.
* iscsi-init.service: use `iscsi-gen-initiatorname`.
* iscsi-gen-initiatorname: use `@IQN_PREFIX@` as default.
* Avoid possible double free of found in `idbm_rec_update_param`.
* iscsi: validate interface IP against target address family.
The following package changes have been done:
- libopeniscsiusr0-0.2.0-160000.4.1 updated
- open-iscsi-2.1.12-160000.4.1 updated
More information about the sle-container-updates
mailing list