SUSE-IU-2026:6408-1: Security update of suse/sl-micro/6.0/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Aug 22 07:48:31 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6408-1
Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.232 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release : 6.232
Severity : important
Type : security
References : 1239671 1241012 1241667 1259642 1261427 1261430 1261441 1261606
1264568 1268886 1269583 CVE-2025-32728 CVE-2026-13595 CVE-2026-27456
CVE-2026-3497 CVE-2026-35385 CVE-2026-35388 CVE-2026-35414 CVE-2026-53612
CVE-2026-53613 CVE-2026-53614
-----------------------------------------------------------------
The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 859
Released: Fri Aug 21 16:14:36 2026
Summary: Security update for openssh
Type: security
Severity: important
References: 1239671,1241012,1241667,1259642,1261427,1261430,1261441,1264568,CVE-2025-32728,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414
This update for openssh fixes the following issues:
- CVE-2025-32728: fix logic error in DisableForwarding option (bsc#1241012).
- CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642).
- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
Other issues fixed::
- ignores write permissions for Group and World Directory Permissions (bsc#1241667).
- wall tool not longer printing any message to terminals (bsc#1239671)
- potential issue in validating mac (bsc#1264568):
* Improve %prep LDAP regex to preserve subdirectories (e.g., ope-
nbsd-compat/) and handle optional [ab]/ prefixes.
-----------------------------------------------------------------
Advisory ID: 858
Released: Fri Aug 21 16:17:45 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
The following package changes have been done:
- libuuid1-2.39.3-8.1 updated
- libsmartcols1-2.39.3-8.1 updated
- libblkid1-2.39.3-8.1 updated
- libfdisk1-2.39.3-8.1 updated
- libmount1-2.39.3-8.1 updated
- util-linux-2.39.3-8.1 updated
- SL-Micro-release-6.0-25.124 updated
- util-linux-systemd-2.39.3-8.1 updated
- openssh-common-9.6p1-6.1 updated
- openssh-server-9.6p1-6.1 updated
- openssh-clients-9.6p1-6.1 updated
- openssh-9.6p1-6.1 updated
- container:SL-Micro-base-container-2.1.3-7.195 updated
More information about the sle-container-updates
mailing list