SUSE-IU-2026:5670-1: Security update of suse/sl-micro/6.2/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Jul 14 07:40:52 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5670-1
Image Tags        : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.60 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release     : 8.60
Severity          : important
Type              : security
References        : 1262719 1265075 1265076 1269220 1269390 1269790 1270252 1270254
                        CVE-2026-11979 CVE-2026-43896 CVE-2026-44777 CVE-2026-49839 CVE-2026-54679
                        CVE-2026-6732 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1220
Released:    Mon Jul 13 09:51:58 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1262719,1269790,CVE-2026-11979,CVE-2026-6732
This update for libxml2 fixes the following issues

- CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719).
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: 1221
Released:    Mon Jul 13 12:29:44 2026
Summary:     Security update for jq
Type:        security
Severity:    important
References:  1265075,1265076,1269220,1269390,CVE-2026-43896,CVE-2026-44777,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues

- CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220).
- CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390).

-----------------------------------------------------------------
Advisory ID: 1229
Released:    Mon Jul 13 18:23:19 2026
Summary:     Security update for cryptsetup
Type:        security
Severity:    moderate
References:  1270252,1270254
This update for cryptsetup fixes the following issues:

Changes in cryptsetup:

- Fix for (bsc#1270254) to avoid undesired pinning of all volume
  keys (via the thread keyring) through the caller's credentials
  when the kernel opens a file. This is due to the refactoring in
  kernel commit a28d893eb327 ('md: port block device access to file')
  that accidentally causes the caller's thread keyring to be kept
  alive long beyond the caller's lifetime, the kernel part is tracked
  in (bsc#1270252).

  * Add keyring key type. [b6fb6fc0]
  * Load volume keys in intermediary keyring linked in thread
    keyring. [413a3dd0]
  * Use unique intermediary keyring name per device. [04ef07a7]
  * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09]


The following package changes have been done:

- libxml2-2-2.13.8-160000.5.1 updated
- libjq1-1.7.1-160000.4.1 updated
- jq-1.7.1-160000.4.1 updated
- cryptsetup-2.8.4-160000.2.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-ff1f5ab1970c4aa78e4db6750506ea01a1ae5f83c5fcce5b876b9b84e4440fd2-0 updated


More information about the sle-container-updates mailing list