SUSE-CU-2026:9276-1: Security update of suse/ltss/sle15.5/sle15
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 27 09:32:21 UTC 2026
SUSE Container Update Advisory: suse/ltss/sle15.5/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9276-1
Container Tags : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.66 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.66 , suse/ltss/sle15.5/sle15:latest
Container Release : 8.66
Severity : important
Type : security
References : 1222465 1234736 1254666 1258859 1261606 1261606 1268886 1269583
CVE-2025-14104 CVE-2026-13595 CVE-2026-27456 CVE-2026-27456 CVE-2026-3184
CVE-2026-53613
-----------------------------------------------------------------
The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:117-1
Released: Tue Jan 13 05:33:38 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1254666,CVE-2025-14104
This update for util-linux fixes the following issues:
- CVE-2025-14104: Fixed heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666).
- lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:856-1
Released: Tue Mar 10 09:35:24 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1258859,CVE-2026-3184
This update for util-linux fixes the following issues:
- CVE-2026-3184: Fix full hostname usage for PAM to ensure correct access control for 'login -h' (bsc#1258859).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:1087-1
Released: Thu Mar 26 16:20:57 2026
Summary: Recommended update for util-linux
Type: recommended
Severity: moderate
References: 1222465,1234736
This update for util-linux fixes the following issues:
- recognize fuse 'portal' as a virtual file system (bsc#1234736).
- fdisk: Fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1962-1
Released: Mon May 18 10:07:58 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1261606,CVE-2026-27456
This update for util-linux fixes the following issue
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3813-1
Released: Wed Aug 26 12:55:40 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53613
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
The following package changes have been done:
- libblkid1-2.37.4-150500.9.32.1 updated
- libfdisk1-2.37.4-150500.9.32.1 updated
- libmount1-2.37.4-150500.9.32.1 updated
- libsmartcols1-2.37.4-150500.9.32.1 updated
- libuuid1-2.37.4-150500.9.32.1 updated
- util-linux-2.37.4-150500.9.32.1 updated
More information about the sle-container-updates
mailing list