SUSE-IU-2026:6480-1: Security update of suse/sl-micro/6.1/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 27 07:59:26 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6480-1
Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.156 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release : 7.156
Severity : moderate
Type : security
References : 1261998 1262633 1263440 1264971 1268412 CVE-2026-40393 CVE-2026-5773
CVE-2026-7168 CVE-2026-8926
-----------------------------------------------------------------
The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 687
Released: Wed Aug 26 17:36:08 2026
Summary: Security update for curl
Type: security
Severity: moderate
References: 1261998,1262633,1263440,1264971,1268412,CVE-2026-40393,CVE-2026-5773,CVE-2026-7168,CVE-2026-8926
This update for curl fixes the following issues:
- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).
Changes for curl:
- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
Content-Length empty body check (bsc#1264971)
The following package changes have been done:
- SL-Micro-release-6.1-slfo.1.12.66 updated
- libcurl4-8.14.1-slfo.1.1_9.1 updated
- container:SL-Micro-base-container-2.2.1-5.173 updated
More information about the sle-container-updates
mailing list