SUSE-IU-2026:6618-1: Security update of suse/sl-micro/6.1/rt-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Aug 29 07:36:50 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.1/rt-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6618-1
Image Tags : suse/sl-micro/6.1/rt-os-container:2.2.1 , suse/sl-micro/6.1/rt-os-container:2.2.1-5.173 , suse/sl-micro/6.1/rt-os-container:latest
Image Release : 5.173
Severity : moderate
Type : security
References : 1259362 1260903 1262631 1262632 1262635 1262636 1262638 1269623
1272554 1274856 1274857 1274858 CVE-2026-1965 CVE-2026-41992
CVE-2026-4873 CVE-2026-4948 CVE-2026-5545 CVE-2026-6253 CVE-2026-6276
CVE-2026-6429 CVE-2026-66484 CVE-2026-66485 CVE-2026-66486
-----------------------------------------------------------------
The container suse/sl-micro/6.1/rt-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 694
Released: Fri Aug 28 13:00:32 2026
Summary: Security update for cpio
Type: security
Severity: moderate
References: 1260903,1274856,1274857,1274858,CVE-2026-4948,CVE-2026-66484,CVE-2026-66485,CVE-2026-66486
This update for cpio fixes the following issues:
- CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard
links outside intended directory via malicious tar archives (bsc#1274856).
- CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of
service via crafted archives (bsc#1274857).
- CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for
terminal control sequence injection via crafted archive member names (bsc#1274858).
-----------------------------------------------------------------
Advisory ID: 695
Released: Fri Aug 28 13:12:50 2026
Summary: Security update for gzip
Type: security
Severity: moderate
References: 1259362,1262631,1262632,1262635,1262636,1262638,1269623,1272554,CVE-2026-1965,CVE-2026-41992,CVE-2026-4873,CVE-2026-5545,CVE-2026-6253,CVE-2026-6276,CVE-2026-6429
This update for gzip fixes the following issues:
- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).
The following package changes have been done:
- gzip-1.13-slfo.1.1_4.1 updated
- cpio-2.15-slfo.1.1_3.1 updated
- SL-Micro-release-6.1-slfo.1.12.69 updated
- container:SL-Micro-container-2.2.1-7.160 updated
More information about the sle-container-updates
mailing list