SUSE-CU-2026:6889-1: Security update of suse/ltss/sle15.4/bci-base-fips

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 10 07:59:40 UTC 2026


SUSE Container Update Advisory: suse/ltss/sle15.4/bci-base-fips
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6889-1
Container Tags        : suse/ltss/sle15.4/bci-base-fips:15.4 , suse/ltss/sle15.4/bci-base-fips:15.4.2.83 , suse/ltss/sle15.4/bci-base-fips:latest
Container Release     : 2.83
Severity              : important
Type                  : security
References            : 1259327 1259611 1259734 1259735 1259989 1260026 1261206 1261280
                        1261809 1261969 1261970 1262098 1262319 1262464 1262465 1262654
                        CVE-2025-13462 CVE-2026-1502 CVE-2026-3446 CVE-2026-34743 CVE-2026-3479
                        CVE-2026-3644 CVE-2026-4046 CVE-2026-4224 CVE-2026-4519 CVE-2026-4786
                        CVE-2026-4878 CVE-2026-5450 CVE-2026-5928 CVE-2026-6019 CVE-2026-6100
-----------------------------------------------------------------

The container suse/ltss/sle15.4/bci-base-fips was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1432-1
Released:    Fri Apr 17 12:12:08 2026
Summary:     Security update for libcap
Type:        security
Severity:    important
References:  1261809,CVE-2026-4878
This update for libcap fixes the following issue:

- CVE-2026-4878: Address a potential TOCTOU race condition in cap_set_file() (bsc#1261809).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1715-1
Released:    Wed May  6 14:09:30 2026
Summary:     Security update for python3
Type:        security
Severity:    important
References:  1259611,1259734,1259735,1259989,1260026,1261969,1261970,1262098,1262319,1262654,CVE-2025-13462,CVE-2026-1502,CVE-2026-3446,CVE-2026-3479,CVE-2026-3644,CVE-2026-4224,CVE-2026-4519,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python3 fixes the following issues:

- CVE-2025-13462: incorrect parsing of TarInfo when GNU long name and type AREGTYPE are combined can lead to
  misinterpretation of tar archives (bsc#1259611).
- CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969).
- CVE-2026-3446: base64 decoding stops at first padded quad by default and ignores other information that could be
  processed (bsc#1261970).
- CVE-2026-3479: improper resource argument validation in `pkgutil.get_data()` can lead to path traversal (bsc#1259989).
- CVE-2026-3644: incomplete control character validation in http.cookies can lead to input validation bypass
  (bsc#1259734).
- CVE-2026-4224: parsing XML with deeply nested DTD content models can lead to C stack overflow (bsc#1259735).
- CVE-2026-4519: failure to sanitize leading dashes in URLs in the `webbrowser.open()` API can lead to web browser
  command line option injection (bsc#1260026).
- CVE-2026-4786: URLs prefixed with `%action` can pass the dash-prefix safety check and allow for command injection
  (bsc#1262319).
- CVE-2026-6019: `BaseCookie.js_output()` does not neutralize characters in cookie values embedded in JS (bsc#1262654).
- CVE-2026-6100: use-after-free in `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when process is
  under memory pressure(bsc#1262098).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2118-1
Released:    Fri May 29 17:31:19 2026
Summary:     Security update for xz
Type:        security
Severity:    important
References:  1261280,CVE-2026-34743
This update for xz fixes the following issue

- CVE-2026-34743: buffer overflow in lzma_index_append() (bsc#1261280).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2333-1
Released:    Wed Jun 10 10:41:58 2026
Summary:     Security update for glibc
Type:        security
Severity:    important
References:  1261206,1262464,1262465,CVE-2026-4046,CVE-2026-5450,CVE-2026-5928
This update for glibc fixes the following issues

- CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206).
- CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width > 1024 (bsc#1262465).
- CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2434-1
Released:    Wed Jun 17 16:40:10 2026
Summary:     Recommended update for coreutils
Type:        recommended
Severity:    important
References:  1259327
This update for coreutils fixes the following issues:

- proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327)


The following package changes have been done:

- glibc-2.31-150300.101.1 updated
- liblzma5-5.2.3-150000.4.10.1 updated
- libcap2-2.63-150400.3.6.1 updated
- coreutils-8.32-150400.9.12.1 updated
- python3-base-3.6.15-150300.10.118.1 updated
- libpython3_6m1_0-3.6.15-150300.10.118.1 updated
- container:sles15-ltss-image-15.4.0-6.30 updated


More information about the sle-container-updates mailing list