SUSE-CU-2026:9133-1: Security update of suse/multi-linux-manager/5.1/x86_64/proxy-ssh

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Mon Aug 24 07:22:47 UTC 2026


SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/proxy-ssh
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9133-1
Container Tags        : suse/multi-linux-manager/5.1/x86_64/proxy-ssh:5.1.5 , suse/multi-linux-manager/5.1/x86_64/proxy-ssh:5.1.5.8.25.1 , suse/multi-linux-manager/5.1/x86_64/proxy-ssh:latest
Container Release     : 8.25.1
Severity              : important
Type                  : security
References            : 1252306 1253043 1257463 1261400 1261982 1261983 1262305 1262684
                        1263366 1263367 1263656 1263658 1267644 1267647 1268131 1268290
                        1270393 1271044 1271046 1271048 1271049 1271052 1271053 1271054
                        1271055 1271712 1271712 CVE-2026-11850 CVE-2026-40226 CVE-2026-40355
                        CVE-2026-40356 CVE-2026-41989 CVE-2026-5435 CVE-2026-54411 CVE-2026-59995
                        CVE-2026-59996 CVE-2026-59997 CVE-2026-59998 CVE-2026-59999 CVE-2026-60000
                        CVE-2026-60001 CVE-2026-60002 CVE-2026-6238 
-----------------------------------------------------------------

The container suse/multi-linux-manager/5.1/x86_64/proxy-ssh was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2848-1
Released:    Fri Jul 10 13:38:57 2026
Summary:     Security update for krb5, krb5-mini
Type:        security
Severity:    important
References:  1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356
This update for krb5, krb5-mini fixes the following issues

- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released:    Wed Jul 15 11:53:06 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released:    Tue Jul 21 09:04:39 2026
Summary:     Recommended update for shadow
Type:        recommended
Severity:    important
References:  1270393
This update for shadow fixes the following issues:

- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released:    Tue Jul 21 16:50:54 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released:    Wed Jul 22 09:25:44 2026
Summary:     Security update for libgcrypt
Type:        security
Severity:    moderate
References:  1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue

- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
  (bsc#1262684).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released:    Fri Jul 24 15:11:25 2026
Summary:     Security update for systemd
Type:        security
Severity:    moderate
References:  1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues

Security issues fixed:

- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).

Other updates and bugfixes:

- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3444-1
Released:    Fri Jul 31 22:04:31 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    moderate
References:  1271712
This update for openssl-3 fixes the following issues:

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released:    Tue Aug 11 15:58:41 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    moderate
References:  1271712
This update for openssl-1_1 fixes the following issues:

- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
  (bsc#1271712).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3605-1
Released:    Thu Aug 13 08:35:24 2026
Summary:     Security update for openssh
Type:        security
Severity:    important
References:  1271044,1271046,1271048,1271049,1271052,1271053,1271054,1271055,CVE-2026-59995,CVE-2026-59996,CVE-2026-59997,CVE-2026-59998,CVE-2026-59999,CVE-2026-60000,CVE-2026-60001,CVE-2026-60002
This update for openssh fixes the following issues:

- Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).

- CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with
  an attacker-controlled server (bsc#1271044).
- CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two
  remote destinations (bsc#1271046).
- CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048).
- CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory
  is not documented (bsc#1271049).
- CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052).
- CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).
- CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).
- CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange
  (bsc#1271055).


The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libudev1-254.27-150600.4.71.2 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libopenssl3-3.2.3-150700.5.40.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated
- krb5-1.20.1-150600.11.19.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- openssh-common-9.6p1-150600.6.49.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- openssh-fips-9.6p1-150600.6.49.1 updated
- openssh-clients-9.6p1-150600.6.49.1 updated
- openssh-server-9.6p1-150600.6.49.1 updated
- openssh-9.6p1-150600.6.49.1 updated
- container:bci-bci-base-15.7-4de2a562289c9545ddd1e888292b3fa87a6156d62d9bb6f2574c92a9e0e8fe98-0 updated


More information about the sle-container-updates mailing list