SUSE-IU-2026:5696-1: Security update of suse/sl-micro/6.2/rt-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Jul 14 08:02:06 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5696-1
Image Tags        : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.72 , suse/sl-micro/6.2/rt-os-container:latest
Image Release     : 7.72
Severity          : moderate
Type              : security
References        : 1268290 1270252 1270254 CVE-2026-54411 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1224
Released:    Mon Jul 13 15:54:55 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext-password comparison (bsc#1268290).

-----------------------------------------------------------------
Advisory ID: 1229
Released:    Mon Jul 13 18:23:19 2026
Summary:     Security update for cryptsetup
Type:        security
Severity:    moderate
References:  1270252,1270254
This update for cryptsetup fixes the following issues:

Changes in cryptsetup:

- Fix for (bsc#1270254) to avoid undesired pinning of all volume
  keys (via the thread keyring) through the caller's credentials
  when the kernel opens a file. This is due to the refactoring in
  kernel commit a28d893eb327 ('md: port block device access to file')
  that accidentally causes the caller's thread keyring to be kept
  alive long beyond the caller's lifetime, the kernel part is tracked
  in (bsc#1270252).

  * Add keyring key type. [b6fb6fc0]
  * Load volume keys in intermediary keyring linked in thread
    keyring. [413a3dd0]
  * Use unique intermediary keyring name per device. [04ef07a7]
  * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09]


The following package changes have been done:

- libcryptsetup12-2.8.4-160000.2.1 updated
- pam-1.7.1-160000.5.1 updated
- pam-extra-1.7.1-160000.5.1 updated
- container:suse-sl-micro-6.2-baremetal-os-container-latest-4619fc217787ec85fe1a940cd952e705ad074f6c96b366485b92fcb28898861e-0 updated


More information about the sle-container-updates mailing list