SUSE-CU-2026:9134-1: Security update of suse/multi-linux-manager/5.1/x86_64/proxy-tftpd
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Aug 24 07:22:50 UTC 2026
SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/proxy-tftpd
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9134-1
Container Tags : suse/multi-linux-manager/5.1/x86_64/proxy-tftpd:5.1.5 , suse/multi-linux-manager/5.1/x86_64/proxy-tftpd:5.1.5.8.25.1 , suse/multi-linux-manager/5.1/x86_64/proxy-tftpd:latest
Container Release : 8.25.1
Severity : important
Type : security
References : 1252306 1253043 1254867 1257463 1259804 1263366 1263367 1263656
1263658 1265413 1268131 1270365 1271712 1271712 CVE-2025-66471
CVE-2026-11850 CVE-2026-27448 CVE-2026-40355 CVE-2026-40356 CVE-2026-45409
CVE-2026-5435 CVE-2026-6238
-----------------------------------------------------------------
The container suse/multi-linux-manager/5.1/x86_64/proxy-tftpd was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2848-1
Released: Fri Jul 10 13:38:57 2026
Summary: Security update for krb5, krb5-mini
Type: security
Severity: important
References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356
This update for krb5, krb5-mini fixes the following issues
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2854-1
Released: Fri Jul 10 19:58:37 2026
Summary: Security update for python-urllib3
Type: security
Severity: moderate
References: 1254867,1270365,CVE-2025-66471
This update for python-urllib3 fixes the following issue
- egression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3100-1
Released: Fri Jul 17 13:41:45 2026
Summary: Security update for python-idna
Type: security
Severity: moderate
References: 1265413,CVE-2026-45409
This update for python-idna fixes the following issue
- CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3424-1
Released: Thu Jul 30 13:07:33 2026
Summary: Security update for python3-pyOpenSSL
Type: security
Severity: low
References: 1259804,CVE-2026-27448
This update for python3-pyOpenSSL fixes the following issue:
- CVE-2026-27448: unhandled exception in `set_tlsext_servername_callback` callback can result in connection not being
cancelled and allows for possible security measure bypassing (bsc#1259804).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3444-1
Released: Fri Jul 31 22:04:31 2026
Summary: Security update for openssl-3
Type: security
Severity: moderate
References: 1271712
This update for openssl-3 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3578-1
Released: Tue Aug 11 15:58:41 2026
Summary: Security update for openssl-1_1
Type: security
Severity: moderate
References: 1271712
This update for openssl-1_1 fixes the following issues:
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
The following package changes have been done:
- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libopenssl3-3.2.3-150700.5.40.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.40.1 updated
- krb5-1.20.1-150600.11.19.1 updated
- openssl-3-3.2.3-150700.5.40.1 updated
- libopenssl1_1-1.1.1w-150700.11.25.2 updated
- python3-idna-2.6-150000.3.9.1 updated
- python3-pyOpenSSL-21.0.0-150400.22.1 updated
- python3-urllib3-1.25.10-150300.4.30.1 updated
- container:bci-bci-base-15.7-4de2a562289c9545ddd1e888292b3fa87a6156d62d9bb6f2574c92a9e0e8fe98-0 updated
More information about the sle-container-updates
mailing list