SUSE-CU-2026:9276-1: Security update of suse/ltss/sle15.5/sle15

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Aug 27 09:32:21 UTC 2026


SUSE Container Update Advisory: suse/ltss/sle15.5/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9276-1
Container Tags        : suse/ltss/sle15.5/bci-base:15.5 , suse/ltss/sle15.5/bci-base:15.5-8.66 , suse/ltss/sle15.5/sle15:15.5 , suse/ltss/sle15.5/sle15:15.5-8.66 , suse/ltss/sle15.5/sle15:latest
Container Release     : 8.66
Severity              : important
Type                  : security
References            : 1222465 1234736 1254666 1258859 1261606 1261606 1268886 1269583
                        CVE-2025-14104 CVE-2026-13595 CVE-2026-27456 CVE-2026-27456 CVE-2026-3184
                        CVE-2026-53613 
-----------------------------------------------------------------

The container suse/ltss/sle15.5/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:117-1
Released:    Tue Jan 13 05:33:38 2026
Summary:     Security update for util-linux
Type:        security
Severity:    moderate
References:  1254666,CVE-2025-14104
This update for util-linux fixes the following issues:

- CVE-2025-14104: Fixed heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666).
- lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:856-1
Released:    Tue Mar 10 09:35:24 2026
Summary:     Security update for util-linux
Type:        security
Severity:    moderate
References:  1258859,CVE-2026-3184
This update for util-linux fixes the following issues:

- CVE-2026-3184: Fix full hostname usage for PAM to ensure correct access control for 'login -h' (bsc#1258859).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:1087-1
Released:    Thu Mar 26 16:20:57 2026
Summary:     Recommended update for util-linux
Type:        recommended
Severity:    moderate
References:  1222465,1234736
This update for util-linux fixes the following issues:

- recognize fuse 'portal' as a virtual file system (bsc#1234736).
- fdisk: Fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1962-1
Released:    Mon May 18 10:07:58 2026
Summary:     Security update for util-linux
Type:        security
Severity:    moderate
References:  1261606,CVE-2026-27456
This update for util-linux fixes the following issue

- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3813-1
Released:    Wed Aug 26 12:55:40 2026
Summary:     Security update for util-linux
Type:        security
Severity:    important
References:  1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53613
This update for util-linux fixes the following issues:

- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).


The following package changes have been done:

- libblkid1-2.37.4-150500.9.32.1 updated
- libfdisk1-2.37.4-150500.9.32.1 updated
- libmount1-2.37.4-150500.9.32.1 updated
- libsmartcols1-2.37.4-150500.9.32.1 updated
- libuuid1-2.37.4-150500.9.32.1 updated
- util-linux-2.37.4-150500.9.32.1 updated


More information about the sle-container-updates mailing list