SUSE-IU-2026:5555-1: Security update of suse/sl-micro/6.0/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Jul 9 07:06:41 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5555-1
Image Tags : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.203 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release : 6.203
Severity : moderate
Type : security
References : 1248600 1262043 1262044 1262069 1262070 1262071 1262072 CVE-2025-9403
CVE-2026-32316 CVE-2026-33947 CVE-2026-33948 CVE-2026-39956 CVE-2026-39979
CVE-2026-40164
-----------------------------------------------------------------
The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 788
Released: Wed Jul 8 13:04:31 2026
Summary: Security update for jq
Type: security
Severity: moderate
References: 1248600,1262043,1262044,1262069,1262070,1262071,1262072,CVE-2025-9403,CVE-2026-32316,CVE-2026-33947,CVE-2026-33948,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164
This update for jq fixes the following issues
Security issues fixed:
- CVE-2025-9403: reacheable assertion in `run_jq_tests` can lead to program termination when processing malformed JSON
input containing invalid Unicode escape sequences (bsc#1248600).
- CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can
lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044).
- CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to
excessive resource consumption when processing crafted JSON input (bsc#1262069).
- CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows
validation bypass via embedded NUL bytes (bsc#1262043).
- CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when
evaluating untrusted jq filters against a release build (bsc#1262070).
- CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an
out-of-bounds read when processing malformed JSON (bsc#1262071).
- CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a
denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).
Other updates and bugfixes:
- spec: add `--enable-pthread-tls` to configure invocation.
The following package changes have been done:
- libjq1-1.6-6.1 updated
- jq-1.6-6.1 updated
More information about the sle-container-updates
mailing list