SUSE-IU-2026:5555-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Jul 9 07:06:41 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5555-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.203 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 6.203
Severity          : moderate
Type              : security
References        : 1248600 1262043 1262044 1262069 1262070 1262071 1262072 CVE-2025-9403
                        CVE-2026-32316 CVE-2026-33947 CVE-2026-33948 CVE-2026-39956 CVE-2026-39979
                        CVE-2026-40164 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 788
Released:    Wed Jul  8 13:04:31 2026
Summary:     Security update for jq
Type:        security
Severity:    moderate
References:  1248600,1262043,1262044,1262069,1262070,1262071,1262072,CVE-2025-9403,CVE-2026-32316,CVE-2026-33947,CVE-2026-33948,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164
This update for jq fixes the following issues

Security issues fixed:

- CVE-2025-9403: reacheable assertion in `run_jq_tests` can lead to program termination when processing malformed JSON
  input containing invalid Unicode escape sequences (bsc#1248600).
- CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can
  lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044).
- CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to
  excessive resource consumption when processing crafted JSON input (bsc#1262069).
- CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows
  validation bypass via embedded NUL bytes (bsc#1262043).
- CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when
  evaluating untrusted jq filters against a release build (bsc#1262070).
- CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an
  out-of-bounds read when processing malformed JSON (bsc#1262071).
- CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a
  denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).

Other updates and bugfixes:

- spec: add `--enable-pthread-tls`  to configure invocation.


The following package changes have been done:

- libjq1-1.6-6.1 updated
- jq-1.6-6.1 updated


More information about the sle-container-updates mailing list