SUSE-IU-2026:5627-1: Security update of suse/sle-micro/rt-5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Jul 12 07:11:40 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/rt-5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5627-1
Image Tags        : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.642 , suse/sle-micro/rt-5.5:latest
Image Release     : 4.5.642
Severity          : important
Type              : security
References        : 1264097 1264145 1265421 1267381 1267531 1267567 1267635 1267684
                        1267722 1267918 1267993 1268022 1268049 1268131 1268660 1269022
                        1269033 1269036 1269090 1269100 1269159 1269184 1269193 1269195
                        1269310 1269398 1269574 1269678 1269681 1269821 1270059 CVE-2026-11850
                        CVE-2026-31771 CVE-2026-43038 CVE-2026-46090 CVE-2026-46173 CVE-2026-46197
                        CVE-2026-46229 CVE-2026-46253 CVE-2026-46266 CVE-2026-46274 CVE-2026-46319
                        CVE-2026-46320 CVE-2026-46330 CVE-2026-46331 CVE-2026-52909 CVE-2026-52918
                        CVE-2026-52923 CVE-2026-52924 CVE-2026-52943 CVE-2026-52955 CVE-2026-52969
                        CVE-2026-52972 CVE-2026-52993 CVE-2026-53016 CVE-2026-53041 CVE-2026-53053
                        CVE-2026-53071 CVE-2026-53072 CVE-2026-53133 CVE-2026-53253 CVE-2026-53359
-----------------------------------------------------------------

The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2840-1
Released:    Fri Jul 10 11:24:44 2026
Summary:     Security update for the Linux Kernel
Type:        security
Severity:    important
References:  1264097,1264145,1265421,1267381,1267531,1267567,1267635,1267684,1267722,1267918,1267993,1268022,1268049,1268660,1269022,1269033,1269036,1269090,1269100,1269159,1269184,1269193,1269195,1269310,1269398,1269574,1269678,1269681,1269821,1270059,CVE-2026-31771,CVE-2026-43038,CVE-2026-46090,CVE-2026-46173,CVE-2026-46197,CVE-2026-46229,CVE-2026-46253,CVE-2026-46266,CVE-2026-46274,CVE-2026-46319,CVE-2026-46320,CVE-2026-46330,CVE-2026-46331,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52924,CVE-2026-52943,CVE-2026-52955,CVE-2026-52969,CVE-2026-52972,CVE-2026-52993,CVE-2026-53016,CVE-2026-53041,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53133,CVE-2026-53253,CVE-2026-53359
The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues

The following security issues were fixed:

- CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).
- CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097).
- CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531).
- CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).
- CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).
- CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).
- CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).
- CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).
- CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).
- CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).
- CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049).
- CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421).
- CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).
- CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).
- CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).
- CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).
- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
- CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).
- CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).
- CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
- CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).
- CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).
- CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).
- CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).
- CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).
- CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574).
- CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2847-1
Released:    Fri Jul 10 13:38:22 2026
Summary:     Security update for krb5
Type:        security
Severity:    important
References:  1268131,CVE-2026-11850
This update for krb5 fixes the following issue

- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).


The following package changes have been done:

- krb5-1.20.1-150500.3.23.1 updated
- kernel-rt-5.14.21-150500.13.151.1 updated
- container:suse-sle-micro-5.5-latest-2.0.4-5.8.50 updated


More information about the sle-container-updates mailing list