SUSE-CU-2026:9358-1: Security update of suse/manager/4.3/proxy-salt-broker
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Aug 27 10:53:57 UTC 2026
SUSE Container Update Advisory: suse/manager/4.3/proxy-salt-broker
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9358-1
Container Tags : suse/manager/4.3/proxy-salt-broker:4.3.19 , suse/manager/4.3/proxy-salt-broker:4.3.19.9.72.29 , suse/manager/4.3/proxy-salt-broker:latest
Container Release : 9.72.29
Severity : important
Type : security
References : 1222465 1234736 1254666 1258859 1261606 1261606 1268886 1269583
CVE-2025-14104 CVE-2026-13595 CVE-2026-27456 CVE-2026-27456 CVE-2026-3184
CVE-2026-53613
-----------------------------------------------------------------
The container suse/manager/4.3/proxy-salt-broker was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:510-1
Released: Fri Feb 13 15:52:36 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1254666,CVE-2025-14104
This update for util-linux fixes the following issues:
- CVE-2025-14104: Fixed heap buffer overread in setpwnam() when processing 256-byte usernames (bsc#1254666).
- lscpu: Add support for NVIDIA Olympus arm64 core (jsc#PED-13682).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:982-1
Released: Mon Mar 23 17:48:23 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1258859,CVE-2026-3184
This update for util-linux fixes the following issues:
- CVE-2026-3184: Fix full hostname usage for PAM to ensure correct access control for 'login -h' (bsc#1258859).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:1665-1
Released: Thu Apr 30 16:53:18 2026
Summary: Recommended update for util-linux
Type: recommended
Severity: moderate
References: 1222465,1234736
This update for util-linux fixes the following issues:
- Recognize fuse 'portal' as a virtual file system (bsc#1234736).
- fdisk: Fix possible partition overlay and data corruption if EBR gap is missing (bsc#1222465).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2653-1
Released: Fri Jun 26 14:22:17 2026
Summary: Security update for util-linux
Type: security
Severity: moderate
References: 1261606,CVE-2026-27456
This update for util-linux fixes the following issue
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3812-1
Released: Wed Aug 26 12:54:46 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53613
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
The following package changes have been done:
- libuuid1-2.37.2-150400.8.50.1 updated
- libsmartcols1-2.37.2-150400.8.50.1 updated
- libblkid1-2.37.2-150400.8.50.1 updated
- libfdisk1-2.37.2-150400.8.50.1 updated
- libmount1-2.37.2-150400.8.50.1 updated
- util-linux-2.37.2-150400.8.50.1 updated
- container:sles15-ltss-image-15.4.0-6.44 updated
More information about the sle-container-updates
mailing list