SUSE-IU-2026:6384-1: Security update of suse/sl-micro/6.2/base-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 20 07:44:32 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6384-1
Image Tags        : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.53 , suse/sl-micro/6.2/base-os-container:latest
Image Release     : 8.53
Severity          : important
Type              : security
References        : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192
                        CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972
                        CVE-2026-15308 CVE-2026-4360 CVE-2026-8328 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1465
Released:    Wed Aug 19 14:39:32 2026
Summary:     Security update for python313
Type:        security
Severity:    important
References:  1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328
This update for python313 fixes the following issues:

- CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044).
- CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041).
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
  `configparser` module is used (bsc#1269066).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
  hardlinks (bsc#1269959).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
  enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
  (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
  (bsc#1271192).


The following package changes have been done:

- python313-base-3.13.14-160000.2.1 updated
- libpython3_13-1_0-3.13.14-160000.2.1 updated


More information about the sle-container-updates mailing list