SUSE-IU-2026:5549-1: Security update of suse/sl-micro/6.2/kvm-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Jul 8 08:49:00 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5549-1
Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.41 , suse/sl-micro/6.2/kvm-os-container:latest
Image Release : 8.41
Severity : important
Type : security
References : 1199023 1268061 1268279 1268794 1270133 CVE-2026-3886 CVE-2026-48004
CVE-2026-48914
-----------------------------------------------------------------
The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1174
Released: Tue Jul 7 19:20:48 2026
Summary: Security update for qemu
Type: security
Severity: important
References: 1199023,1268061,1268279,1268794,1270133,CVE-2026-3886,CVE-2026-48004,CVE-2026-48914
This update for qemu fixes the following issues:
Update to version 10.0.11.
Security issues fixed:
- CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied
data in the virtio-gpu driver (bsc#1268061).
- CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling
(bsc#1268794).
- CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133).
Other updates and bugfixes:
- Version 10.0.11:
* Full backport list here: https://lore.kernel.org/qemu-devel/20260627082646.D825717AB67@think4mjt.localdomain/
- Version 10.0.10:
* Full backport list here: https://lore.kernel.org/qemu-devel/20260528061820.CEE521691A9@think4mjt.localdomain/
- ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279).
- i386/tdx: handle TDG.VP.VMCALL <GetQuote> (jsc#PED-9266).
- i386/tdx: handle TDG.VP.VMCALL <GetTdVmCallInfo> (jsc#PED-9266).
- update Linux headers to v6.16-rc3 (jsc#PED-9266).
- i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266).
- i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266).
- [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023).
The following package changes have been done:
- qemu-guest-agent-10.0.11-160000.1.1 updated
More information about the sle-container-updates
mailing list