SUSE-IU-2026:6431-1: Security update of suse/sl-micro/6.2/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Aug 25 07:53:17 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6431-1
Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.101 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release : 8.101
Severity : moderate
Type : security
References : 1244684 1272922 1272923 1272924 1272925 1272926 1272927 1272928
1272930 CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529
CVE-2026-16530 CVE-2026-16531
-----------------------------------------------------------------
The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1487
Released: Mon Aug 24 18:44:51 2026
Summary: Recommended update for xfsprogs
Type: recommended
Severity: moderate
References: 1244684
This update for xfsprogs fixes the following issues:
- Fix: fstests generic/753 fails on xfs (bsc#1244684):
* xfs_repair: don't fail on INCOMPLETE attrs in leaf blocks
-----------------------------------------------------------------
Advisory ID: 1495
Released: Mon Aug 24 22:44:34 2026
Summary: Security update for pcp
Type: security
Severity: moderate
References: 1272922,1272923,1272924,1272925,1272926,1272927,1272928,1272930,CVE-2026-16524,CVE-2026-16526,CVE-2026-16527,CVE-2026-16529,CVE-2026-16530,CVE-2026-16531
This update for pcp fixes the following issues:
- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).
- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials
(bsc#1272923).
- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).
- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).
- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).
- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).
- command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).
- command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).
The following package changes have been done:
- xfsprogs-6.19.0-160000.3.1 updated
- pcp-conf-6.2.0-160000.4.1 updated
- libpcp3-6.2.0-160000.4.1 updated
- libpcp_import1-6.2.0-160000.4.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-727886db56e1524ab4d19f54affb350049ff47ed7ab2cf75ea8d2a4ff498b12f-0 updated
More information about the sle-container-updates
mailing list