SUSE-IU-2026:5670-1: Security update of suse/sl-micro/6.2/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Tue Jul 14 07:40:52 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5670-1
Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.60 , suse/sl-micro/6.2/baremetal-os-container:latest
Image Release : 8.60
Severity : important
Type : security
References : 1262719 1265075 1265076 1269220 1269390 1269790 1270252 1270254
CVE-2026-11979 CVE-2026-43896 CVE-2026-44777 CVE-2026-49839 CVE-2026-54679
CVE-2026-6732
-----------------------------------------------------------------
The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1220
Released: Mon Jul 13 09:51:58 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1262719,1269790,CVE-2026-11979,CVE-2026-6732
This update for libxml2 fixes the following issues
- CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719).
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: 1221
Released: Mon Jul 13 12:29:44 2026
Summary: Security update for jq
Type: security
Severity: important
References: 1265075,1265076,1269220,1269390,CVE-2026-43896,CVE-2026-44777,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues
- CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220).
- CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390).
-----------------------------------------------------------------
Advisory ID: 1229
Released: Mon Jul 13 18:23:19 2026
Summary: Security update for cryptsetup
Type: security
Severity: moderate
References: 1270252,1270254
This update for cryptsetup fixes the following issues:
Changes in cryptsetup:
- Fix for (bsc#1270254) to avoid undesired pinning of all volume
keys (via the thread keyring) through the caller's credentials
when the kernel opens a file. This is due to the refactoring in
kernel commit a28d893eb327 ('md: port block device access to file')
that accidentally causes the caller's thread keyring to be kept
alive long beyond the caller's lifetime, the kernel part is tracked
in (bsc#1270252).
* Add keyring key type. [b6fb6fc0]
* Load volume keys in intermediary keyring linked in thread
keyring. [413a3dd0]
* Use unique intermediary keyring name per device. [04ef07a7]
* Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09]
The following package changes have been done:
- libxml2-2-2.13.8-160000.5.1 updated
- libjq1-1.7.1-160000.4.1 updated
- jq-1.7.1-160000.4.1 updated
- cryptsetup-2.8.4-160000.2.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-ff1f5ab1970c4aa78e4db6750506ea01a1ae5f83c5fcce5b876b9b84e4440fd2-0 updated
More information about the sle-container-updates
mailing list