SUSE-CU-2026:9130-1: Security update of suse/multi-linux-manager/5.1/x86_64/proxy-httpd
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Aug 24 07:22:36 UTC 2026
SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/proxy-httpd
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9130-1
Container Tags : suse/multi-linux-manager/5.1/x86_64/proxy-httpd:5.1.5 , suse/multi-linux-manager/5.1/x86_64/proxy-httpd:5.1.5.8.27.2 , suse/multi-linux-manager/5.1/x86_64/proxy-httpd:latest
Container Release : 8.27.2
Severity : important
Type : security
References : 1240054 1243168 1244141 1245944 1247004 1252306 1253043 1253505
1254201 1257102 1257295 1257463 1258500 1258567 1259225 1259254
1259594 1259720 1259804 1260342 1260396 1261195 1261400 1261606
1261982 1261983 1262012 1262168 1262305 1262631 1262664 1262684
1263366 1263367 1263656 1263658 1263822 1263823 1265334 1266304
1266481 1267619 1267644 1267647 1267871 1268006 1268131 1268151
1268229 1268290 1268309 1268325 1268349 1268402 1268407 1268409
1268413 1268415 1268416 1268417 1268420 1268422 1268427 1268567
1268570 1268673 1268886 1269192 1269267 1269279 1269408 1269583
1269584 1269790 1270008 1270009 1270010 1270016 1270018 1270021
1270040 1270393 1271351 1271352 1271354 1271372 1271645 1271712
1271712 1272164 1272165 1272166 1272167 1272168 1272169 1272171
1274571 1274984 1275217 CVE-2026-10536 CVE-2026-11850 CVE-2026-11979
CVE-2026-12064 CVE-2026-12087 CVE-2026-13595 CVE-2026-27448 CVE-2026-27456
CVE-2026-39821 CVE-2026-40226 CVE-2026-40355 CVE-2026-40356 CVE-2026-40467
CVE-2026-40468 CVE-2026-40553 CVE-2026-41989 CVE-2026-44605 CVE-2026-4873
CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-5435 CVE-2026-54411
CVE-2026-57062 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012
CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-59843 CVE-2026-59844
CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59850
CVE-2026-6238 CVE-2026-8286 CVE-2026-8376 CVE-2026-8458 CVE-2026-8924
CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547
-----------------------------------------------------------------
The container suse/multi-linux-manager/5.1/x86_64/proxy-httpd was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2848-1
Released: Fri Jul 10 13:38:57 2026
Summary: Security update for krb5, krb5-mini
Type: security
Severity: important
References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356
This update for krb5, krb5-mini fixes the following issues
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2925-1
Released: Mon Jul 13 19:53:23 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1262631,1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-4873,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547
This update for curl fixes the following issues
- CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631).
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released: Fri Jul 17 13:39:27 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1269790,CVE-2026-11979
This update for libxml2 fixes the following issue
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3106-1
Released: Fri Jul 17 16:02:05 2026
Summary: Recommended update for kmod
Type: recommended
Severity: moderate
References:
This update for kmod fixes the following issues:
- Use in-kernel decompression if available (jsc#PED-16303):
* libkmod:
+ Add a separate function to load the file contents when it's needed.
When it's not needed on the path of loading modules via finit_module(),
there is no need to mmap the file.
+ Extract 2 functions to handle finit_module vs init_modules differences,
with a fallback from the former to the latter.
+ Don't only set the type as direct, but also keep track of the compression being used.
+ When creating the context, read /sys/kernel/compression to check.
what's the compression type supported by the kernel.
+ Use kernel decompression when available
+ add fallback MODULE_INIT_COMPRESSED_FILE define
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released: Wed Jul 22 09:25:44 2026
Summary: Security update for libgcrypt
Type: security
Severity: moderate
References: 1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue
- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
(bsc#1262684).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3243-1
Released: Fri Jul 24 15:09:32 2026
Summary: Security update for gpg2
Type: security
Severity: low
References: 1269279,CVE-2026-57062
This update for gpg2 fixes the following issue:
- CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released: Fri Jul 24 15:11:25 2026
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues
Security issues fixed:
- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).
Other updates and bugfixes:
- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3330-1
Released: Tue Jul 28 11:35:51 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850
This update for libssh fixes the following issues:
- CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164).
- CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165).
- CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166).
- CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167).
- CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168).
- CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169).
- CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3341-1
Released: Tue Jul 28 12:09:19 2026
Summary: Security update for glib2
Type: security
Severity: important
References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues:
- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
(bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3424-1
Released: Thu Jul 30 13:07:33 2026
Summary: Security update for python3-pyOpenSSL
Type: security
Severity: low
References: 1259804,CVE-2026-27448
This update for python3-pyOpenSSL fixes the following issue:
- CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being
cancelled and allows for possible security measure bypassing (bsc#1259804).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3444-1
Released: Fri Jul 31 22:04:31 2026
Summary: Security update for openssl-3
Type: security
Severity: moderate
References: 1271712
This update for openssl-3 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3455-1
Released: Mon Aug 3 13:46:45 2026
Summary: Security update for gawk
Type: security
Severity: moderate
References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553
This update for gawk fixes the following issues:
- CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351).
- CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352).
- CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3495-1
Released: Tue Aug 4 16:06:59 2026
Summary: Recommended update for policycoreutils
Type: recommended
Severity: moderate
References: 1271645
This update for policycoreutils fixes the following issues:
- Drop /tmp cleanup to avoid TOCTOU issues (bsc#1271645):
* can be dropped once 'policycoreutils/scripts/fixfiles:
drop /tmp cleanup' is in the upstream release
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3558-1
Released: Mon Aug 10 20:01:21 2026
Summary: Security update for perl
Type: security
Severity: important
References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376
This update for perl fixes the following issues:
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released: Tue Aug 11 15:58:41 2026
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1271712
This update for openssl-1_1 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3600-1
Released: Wed Aug 12 13:59:10 2026
Summary: Security update for rpm
Type: security
Severity: important
References: 1240054,1269584,CVE-2026-44605
This update for rpm fixes the following issues:
Security issues fixed:
- CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot
table (bsc#1269584).
Other updates and bugfixes:
- Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3684-1
Released: Fri Aug 21 20:23:10 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3712-1
Released: Mon Aug 24 04:52:59 2026
Summary: Maintenance update for Multi-Linux Manager 5.1.5
Type: recommended
Severity: important
References: 1243168,1244141,1245944,1247004,1253505,1254201,1257102,1257295,1258500,1258567,1259225,1259254,1259594,1259720,1260342,1260396,1261195,1262012,1262168,1262664,1263822,1263823,1265334,1266481,1267619,1267871,1268006,1268151,1268229,1268309,1268325,1268567,1268570,1268673,1269192,1269267,1269408,1270040,1274571,1274984,1275217,CVE-2026-39821
Maintenance update for Multi-Linux Manager 5.1.5: Server, Proxy and Retail Branch Server
This is a codestream only update
The following package changes have been done:
- libssh-config-0.9.8-150600.11.15.1 updated
- glibc-2.38-150600.14.52.1 updated
- libuuid1-2.40.4-150700.4.18.1 updated
- libsmartcols1-2.40.4-150700.4.18.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.12.10-150700.4.14.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libudev1-254.27-150600.4.71.2 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libglib-2_0-0-2.78.6-150600.4.38.1 updated
- libopenssl3-3.2.3-150700.5.40.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libblkid1-2.40.4-150700.4.18.1 updated
- perl-base-5.26.1-150300.17.23.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated
- krb5-1.20.1-150600.11.19.1 updated
- gpg2-2.4.4-150600.3.18.1 updated
- libmount1-2.40.4-150700.4.18.1 updated
- libfdisk1-2.40.4-150700.4.18.1 updated
- libssh4-0.9.8-150600.11.15.1 updated
- libcurl4-8.14.1-150700.7.20.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- util-linux-2.40.4-150700.4.18.1 updated
- curl-8.14.1-150700.7.20.1 updated
- libgmodule-2_0-0-2.78.6-150600.4.38.1 updated
- libgobject-2_0-0-2.78.6-150600.4.38.1 updated
- libkmod2-29-150600.13.6.1 updated
- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- release-notes-multi-linux-manager-proxy-5.1.5-150700.4.18.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- gawk-4.2.1-150000.3.6.1 updated
- policycoreutils-3.5-150600.3.3.1 updated
- python3-rpm-4.14.3-150400.59.19.1 updated
- systemd-254.27-150600.4.71.2 updated
- libgio-2_0-0-2.78.6-150600.4.38.1 updated
- glib2-tools-2.78.6-150600.4.38.1 updated
- python3-pyOpenSSL-21.0.0-150400.22.1 updated
- spacewalk-backend-5.1.18-150700.3.15.15 updated
- container:bci-bci-base-15.7-4de2a562289c9545ddd1e888292b3fa87a6156d62d9bb6f2574c92a9e0e8fe98-0 updated
More information about the sle-container-updates
mailing list