SUSE-IU-2026:6431-1: Security update of suse/sl-micro/6.2/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Aug 25 07:53:17 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6431-1
Image Tags        : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.101 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release     : 8.101
Severity          : moderate
Type              : security
References        : 1244684 1272922 1272923 1272924 1272925 1272926 1272927 1272928
                        1272930 CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529
                        CVE-2026-16530 CVE-2026-16531 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1487
Released:    Mon Aug 24 18:44:51 2026
Summary:     Recommended update for xfsprogs
Type:        recommended
Severity:    moderate
References:  1244684
This update for xfsprogs fixes the following issues:

- Fix: fstests generic/753 fails on xfs (bsc#1244684):
    * xfs_repair: don't fail on INCOMPLETE attrs in leaf blocks

-----------------------------------------------------------------
Advisory ID: 1495
Released:    Mon Aug 24 22:44:34 2026
Summary:     Security update for pcp
Type:        security
Severity:    moderate
References:  1272922,1272923,1272924,1272925,1272926,1272927,1272928,1272930,CVE-2026-16524,CVE-2026-16526,CVE-2026-16527,CVE-2026-16529,CVE-2026-16530,CVE-2026-16531
This update for pcp fixes the following issues:

- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).
- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials
  (bsc#1272923).
- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).
- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).
- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).
- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).
- command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).
- command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).


The following package changes have been done:

- xfsprogs-6.19.0-160000.3.1 updated
- pcp-conf-6.2.0-160000.4.1 updated
- libpcp3-6.2.0-160000.4.1 updated
- libpcp_import1-6.2.0-160000.4.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-727886db56e1524ab4d19f54affb350049ff47ed7ab2cf75ea8d2a4ff498b12f-0 updated


More information about the sle-container-updates mailing list