SUSE-CU-2026:6833-1: Security update of suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 8 09:11:00 UTC 2026


SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6833-1
Container Tags        : suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api:5.1.4 , suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api:5.1.4.8.22.1 , suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api:latest
Container Release     : 8.22.1
Severity              : important
Type                  : security
References            : 1208800 1226578 1234567 1238890 1242916 1245107 1247707 1248699
                        1249243 1253032 1254900 1257583 1257894 1258041 1258079 1258144
                        1258382 1258816 1259087 1259230 1259261 1259327 1259474 1259479
                        1259482 1259521 1259590 1259591 1259700 1259739 1259787 1259960
                        1260031 1260614 1260806 1261206 1261280 1261305 1261307 1261327
                        1261606 1261631 1261723 1261753 1261841 1261902 1262090 1262144
                        1262222 1262285 1262460 1262464 1262465 1262471 1262492 1262595
                        1262708 1262720 1262760 1262761 1262950 1263501 1263814 1263841
                        1263986 1263987 1264149 1264174 1264234 1264256 1264966 1264971
                        1265134 1265281 1265282 1265283 1265284 1265285 1265286 1265287
                        1265288 1265289 1265290 1265319 1265358 1265620 1265975 1266012
                        1266340 1266341 1266342 1266343 1266345 1266349 1266350 1266351
                        1266352 1266353 1266355 1266356 1266357 1266556 1266600 1269253
                        1269534 CVE-2022-21698 CVE-2026-27456 CVE-2026-28374 CVE-2026-28376
                        CVE-2026-28379 CVE-2026-28380 CVE-2026-28383 CVE-2026-33376 CVE-2026-33377
                        CVE-2026-33378 CVE-2026-33380 CVE-2026-33381 CVE-2026-34180 CVE-2026-34181
                        CVE-2026-34183 CVE-2026-34743 CVE-2026-34986 CVE-2026-39821 CVE-2026-40179
                        CVE-2026-4046 CVE-2026-41602 CVE-2026-42151 CVE-2026-42154 CVE-2026-42198
                        CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770
                        CVE-2026-45445 CVE-2026-45446 CVE-2026-45447 CVE-2026-5450 CVE-2026-5928
                        CVE-2026-5958 CVE-2026-7383 CVE-2026-9076 
-----------------------------------------------------------------

The container suse/multi-linux-manager/5.1/x86_64/server-hub-xmlrpc-api was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1941-1
Released:    Mon May 18 09:44:34 2026
Summary:     Security update for sed
Type:        security
Severity:    moderate
References:  1262144,CVE-2026-5958
This update for sed fixes the following issue:

- CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2051-1
Released:    Mon May 25 15:59:43 2026
Summary:     Security update for xz
Type:        security
Severity:    important
References:  1261280,CVE-2026-34743
This update for xz fixes the following issue

- CVE-2026-34743: buffer overflow in lzma_index_append() (bsc#1261280).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2231-1
Released:    Wed Jun  3 12:57:18 2026
Summary:     Security update for glibc
Type:        security
Severity:    important
References:  1261206,1262464,1262465,CVE-2026-4046,CVE-2026-5450,CVE-2026-5928
This update for glibc fixes the following issues

- CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206).
- CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width > 1024 (bsc#1262465).
- CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2276-1
Released:    Fri Jun  5 10:56:23 2026
Summary:     Recommended update for apparmor
Type:        recommended
Severity:    important
References:  1265620
This update for apparmor fixes the following issues:

- Allow execution of /usr/bin/zstd (bsc#1265620)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2434-1
Released:    Wed Jun 17 16:40:10 2026
Summary:     Recommended update for coreutils
Type:        recommended
Severity:    important
References:  1259327
This update for coreutils fixes the following issues:

- proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2485-1
Released:    Mon Jun 22 14:06:22 2026
Summary:     Security update for util-linux
Type:        security
Severity:    moderate
References:  1261606,CVE-2026-27456
This update for util-linux fixes the following issue

- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2648-1
Released:    Fri Jun 26 13:05:57 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1266340,1266341,1266342,1266343,1266345,1266349,1266350,1266351,1266352,1266353,1266355,1266356,1266357,CVE-2026-34180,CVE-2026-34181,CVE-2026-34183,CVE-2026-42766,CVE-2026-42767,CVE-2026-42768,CVE-2026-42769,CVE-2026-42770,CVE-2026-45445,CVE-2026-45446,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076
This update for openssl-3 fixes the following issues

- CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
- CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
- CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
- CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343).
- CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345).
- CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
- CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
- CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351).
- CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352).
- CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353).
- CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355).
- CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356).
- CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2661-1
Released:    Fri Jun 26 15:15:48 2026
Summary:     Recommended update for curl
Type:        recommended
Severity:    important
References:  1264971
This update for curl fixes the following issues:

- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
  Content-Length empty body check (bsc#1264971)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2774-1
Released:    Mon Jul  6 09:52:16 2026
Summary:     Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server
Type:        security
Severity:    important
References:  1208800,1226578,1234567,1238890,1242916,1245107,1247707,1248699,1249243,1253032,1254900,1257583,1257894,1258041,1258079,1258144,1258382,1258816,1259087,1259230,1259261,1259474,1259479,1259482,1259521,1259590,1259591,1259700,1259739,1259787,1259960,1260031,1260614,1260806,1261305,1261307,1261327,1261631,1261723,1261753,1261841,1261902,1262090,1262222,1262285,1262460,1262471,1262492,1262595,1262708,1262720,1262760,1262761,1262950,1263501,1263814,1263841,1263986,1263987,1264149,1264174,1264234,1264256,1264966,1265134,1265281,1265282,1265283,1265284,1265285,1265286,1265287,1265288,1265289,1265290,1265319,1265358,1265975,1266012,1266556,1266600,1269253,1269534,CVE-2022-21698,CVE-2026-28374,CVE-2026-28376,CVE-2026-28379,CVE-2026-28380,CVE-2026-28383,CVE-2026-33376,CVE-2026-33377,CVE-2026-33378,CVE-2026-33380,CVE-2026-33381,CVE-2026-34986,CVE-2026-39821,CVE-2026-40179,CVE-2026-41602,CVE-2026-42151,CVE-2026-42154,CVE-2026-42198
Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server

This is a codestream only update


The following package changes have been done:

- glibc-2.38-150600.14.49.1 updated
- libuuid1-2.40.4-150700.4.13.1 updated
- libsmartcols1-2.40.4-150700.4.13.1 updated
- liblzma5-5.4.1-150600.3.6.1 updated
- libopenssl3-3.2.3-150700.5.36.1 updated
- libblkid1-2.40.4-150700.4.13.1 updated
- sed-4.9-150600.3.3.1 updated
- coreutils-8.32-150400.9.12.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.36.1 updated
- libmount1-2.40.4-150700.4.13.1 updated
- libfdisk1-2.40.4-150700.4.13.1 updated
- libcurl4-8.14.1-150700.7.17.1 updated
- util-linux-2.40.4-150700.4.13.1 updated
- libapparmor1-3.1.7-150600.5.15.1 updated
- xz-5.4.1-150600.3.6.1 updated
- hub-xmlrpc-api-0.9-150700.3.6.1 updated
- container:bci-bci-base-15.7-d2aab68ae05470b62bbe38c4ca03ff5bf72b405197482ed96e34dd0087d7bde2-0 updated


More information about the sle-container-updates mailing list