SUSE-IU-2026:6395-1: Security update of suse/sl-micro/6.2/rt-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 20 07:57:10 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6395-1
Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.113 , suse/sl-micro/6.2/rt-os-container:latest
Image Release : 7.113
Severity : important
Type : security
References : 1257041 1257044 1265268 1268977 1269066 1269788 1269959 1271192
CVE-2025-15366 CVE-2025-15367 CVE-2026-0864 CVE-2026-11940 CVE-2026-11972
CVE-2026-15308 CVE-2026-4360 CVE-2026-8328
-----------------------------------------------------------------
The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1465
Released: Wed Aug 19 14:39:32 2026
Summary: Security update for python313
Type: security
Severity: important
References: 1257041,1257044,1265268,1268977,1269066,1269788,1269959,1271192,CVE-2025-15366,CVE-2025-15367,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-4360,CVE-2026-8328
This update for python313 fixes the following issues:
- CVE-2025-15366: user-controlled command can allow additional commands injected using newlines (bsc#1257044).
- CVE-2025-15367: control characters may allow the injection of additional commands (bsc#1257041).
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
`configparser` module is used (bsc#1269066).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
hardlinks (bsc#1269959).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
(bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
(bsc#1271192).
The following package changes have been done:
- python313-base-3.13.14-160000.2.1 updated
- libpython3_13-1_0-3.13.14-160000.2.1 updated
- container:suse-sl-micro-6.2-baremetal-os-container-latest-9f2a29b07af0c8a5d7fe1114c7c154124633505966180bec3487927d58f09fd2-0 updated
More information about the sle-container-updates
mailing list