SUSE-IU-2026:5709-1: Security update of suse/sle-micro/5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 15 07:14:30 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5709-1
Image Tags        : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.55 , suse/sle-micro/5.5:latest
Image Release     : 5.8.55
Severity          : moderate
Type              : security
References        : 1262044 1262069 1262070 1262071 1262072 CVE-2026-32316 CVE-2026-33947
                        CVE-2026-39956 CVE-2026-39979 CVE-2026-40164 
-----------------------------------------------------------------

The container suse/sle-micro/5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2983-1
Released:    Tue Jul 14 15:19:38 2026
Summary:     Security update for jq
Type:        security
Severity:    moderate
References:  1262044,1262069,1262070,1262071,1262072,CVE-2026-32316,CVE-2026-33947,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164
This update for jq fixes the following issues:

- CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can
  lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044).
- CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to
  excessive resource consumption when processing crafted JSON input (bsc#1262069).
- CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when
  evaluating untrusted jq filters against a release build (bsc#1262070).
- CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an
  out-of-bounds read when processing malformed JSON (bsc#1262071).
- CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a
  denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).


The following package changes have been done:

- libjq1-1.6-150000.3.20.1 updated
- jq-1.6-150000.3.20.1 updated


More information about the sle-container-updates mailing list