SUSE-IU-2026:6615-1: Security update of suse/sl-micro/6.1/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Aug 29 07:29:50 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6615-1
Image Tags        : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.160 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release     : 7.160
Severity          : moderate
Type              : security
References        : 1259362 1260903 1262631 1262632 1262635 1262636 1262638 1269623
                        1272554 1274856 1274857 1274858 CVE-2026-1965 CVE-2026-41992
                        CVE-2026-4873 CVE-2026-4948 CVE-2026-5545 CVE-2026-6253 CVE-2026-6276
                        CVE-2026-6429 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 694
Released:    Fri Aug 28 13:00:32 2026
Summary:     Security update for cpio
Type:        security
Severity:    moderate
References:  1260903,1274856,1274857,1274858,CVE-2026-4948,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:

- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
  links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
  service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
  terminal control sequence injection via crafted archive member names (bsc#1274858).

-----------------------------------------------------------------
Advisory ID: 695
Released:    Fri Aug 28 13:12:50 2026
Summary:     Security update for gzip
Type:        security
Severity:    moderate
References:  1259362,1262631,1262632,1262635,1262636,1262638,1269623,1272554,CVE-2026-1965,CVE-2026-41992,CVE-2026-4873,CVE-2026-5545,CVE-2026-6253,CVE-2026-6276,CVE-2026-6429
This update for gzip fixes the following issues:

- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
  between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).


The following package changes have been done:

- gzip-1.13-slfo.1.1_4.1 updated
- cpio-2.15-slfo.1.1_3.1 updated
- SL-Micro-release-6.1-slfo.1.12.69 updated
- container:SL-Micro-base-container-2.2.1-5.176 updated


More information about the sle-container-updates mailing list