SUSE-IU-2026:6483-1: Security update of suse/sl-micro/6.1/rt-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 27 08:06:10 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6483-1
Image Tags        : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.170 , suse/sl-micro/6.1/rt-os-container:latest
Image Release     : 5.170
Severity          : moderate
Type              : security
References        : 1261998 1262633 1263440 1264971 1268412 CVE-2026-40393 CVE-2026-5773
                        CVE-2026-7168 CVE-2026-8926 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 687
Released:    Wed Aug 26 17:36:08 2026
Summary:     Security update for curl
Type:        security
Severity:    moderate
References:  1261998,1262633,1263440,1264971,1268412,CVE-2026-40393,CVE-2026-5773,CVE-2026-7168,CVE-2026-8926
This update for curl fixes the following issues:

- CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633).
- CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440).
- CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412).

Changes for curl:

- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
 Content-Length empty body check (bsc#1264971)


The following package changes have been done:

- SL-Micro-release-6.1-slfo.1.12.66 updated
- libcurl4-8.14.1-slfo.1.1_9.1 updated
- container:SL-Micro-container-2.2.1-7.156 updated


More information about the sle-container-updates mailing list