SUSE-IU-2026:5686-1: Security update of suse/sl-micro/6.2/kvm-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Jul 14 07:55:31 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5686-1
Image Tags        : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.53 , suse/sl-micro/6.2/kvm-os-container:latest
Image Release     : 8.53
Severity          : moderate
Type              : security
References        : 1268290 1270252 1270254 CVE-2026-54411 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1224
Released:    Mon Jul 13 15:54:55 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext-password comparison (bsc#1268290).

-----------------------------------------------------------------
Advisory ID: 1229
Released:    Mon Jul 13 18:23:19 2026
Summary:     Security update for cryptsetup
Type:        security
Severity:    moderate
References:  1270252,1270254
This update for cryptsetup fixes the following issues:

Changes in cryptsetup:

- Fix for (bsc#1270254) to avoid undesired pinning of all volume
  keys (via the thread keyring) through the caller's credentials
  when the kernel opens a file. This is due to the refactoring in
  kernel commit a28d893eb327 ('md: port block device access to file')
  that accidentally causes the caller's thread keyring to be kept
  alive long beyond the caller's lifetime, the kernel part is tracked
  in (bsc#1270252).

  * Add keyring key type. [b6fb6fc0]
  * Load volume keys in intermediary keyring linked in thread
    keyring. [413a3dd0]
  * Use unique intermediary keyring name per device. [04ef07a7]
  * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09]


The following package changes have been done:

- libcryptsetup12-2.8.4-160000.2.1 updated
- pam-1.7.1-160000.5.1 updated
- pam-extra-1.7.1-160000.5.1 updated
- container:suse-sl-micro-6.2-base-os-container-latest-dd1e55420a0a437031f2fdffbfc7c2ea957846664d6b2e6fc803aa688f3a33ef-0 updated


More information about the sle-container-updates mailing list