SUSE-IU-2026:6545-1: Security update of suse/sl-micro/6.0/kvm-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Aug 28 07:21:55 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6545-1
Image Tags        : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.209 , suse/sl-micro/6.0/kvm-os-container:latest
Image Release     : 6.209
Severity          : important
Type              : security
References        : 1199023 1268061 1273447 1275490 CVE-2026-3886 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 866
Released:    Thu Aug 27 14:01:51 2026
Summary:     Security update for qemu
Type:        security
Severity:    important
References:  1199023,1268061,1273447,1275490,CVE-2026-3886
This update for qemu fixes the following issue:

- CVE-2026-3886: lack of proper validation of user-supplied data in the `virtio-gpu` driver can lead to local privilege
  escalation via an integer overflow (bsc#1268061).

Other updates and bugfixes:

- Service: switch back to `tar_scm`.
- Bug fixes:
  * target/s390x: Make container ids in `SysIB_15x` 1-based (bsc#1275490).
  * target/s390x: move `@deprecated-props` to `CpuModelExpansionInfo` (bsc#1273447).
  * target/s390x: filter deprecated properties based on model expansion type (bsc#1273447).
  * target/s390x: flag `te` and `cte` as deprecated (bsc#1273447).
  * target/s390x: report `deprecated-props` in `cpu-model-expansion` reply (bsc#1273447).
- qemu-ga: fix service file against no-autostart (bsc#1199023).


The following package changes have been done:

- qemu-guest-agent-8.2.10-4.1 updated


More information about the sle-container-updates mailing list