SUSE-IU-2026:6477-1: Security update of suse/sl-micro/6.0/base-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 27 07:44:15 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6477-1
Image Tags        : suse/sl-micro/6.0/base-os-container:2.1.3 , suse/sl-micro/6.0/base-os-container:2.1.3-7.197 , suse/sl-micro/6.0/base-os-container:latest
Image Release     : 7.197
Severity          : moderate
Type              : security
References        : 1262633 1263440 1264971 1268412 CVE-2026-5773 CVE-2026-7168 CVE-2026-8926
-----------------------------------------------------------------

The container suse/sl-micro/6.0/base-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 865
Released:    Wed Aug 26 17:41:27 2026
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1262633,1263440,1264971,1268412,CVE-2026-5773,CVE-2026-7168,CVE-2026-8926
This update for curl fixes the following issues:

- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).

Changes for curl:

- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
 Content-Length empty body check (bsc#1264971)


The following package changes have been done:

- SL-Micro-release-6.0-25.125 updated
- libcurl-mini4-8.14.1-8.1 updated
- curl-8.14.1-8.1 updated
- container:suse-toolbox-image-1.0.0-9.154 updated


More information about the sle-container-updates mailing list