SUSE-CU-2026:7007-1: Security update of suse/sle-micro-rancher/5.4
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Jul 15 07:30:33 UTC 2026
SUSE Container Update Advisory: suse/sle-micro-rancher/5.4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7007-1
Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.148 , suse/sle-micro-rancher/5.4:latest
Container Release : 4.5.148
Severity : important
Type : security
References : 1262044 1262069 1262070 1262071 1262072 1268131 CVE-2026-11850
CVE-2026-32316 CVE-2026-33947 CVE-2026-39956 CVE-2026-39979 CVE-2026-40164
-----------------------------------------------------------------
The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2951-1
Released: Tue Jul 14 11:32:32 2026
Summary: Recommended update for dmidecode
Type: recommended
Severity: moderate
References:
This update for dmidecode fixes the following issues:
- Update to upstream version 3.7 (jsc#PED-16217):
* Support for SMBIOS 3.8.0. This includes a new processor family.
* Support for SMBIOS 3.9.0. This includes chassis type name
adjustments, new rack attributes, slot ID for more slot types,
and new memory device form factors and types.
* Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244.
* Update HPE OEM records 203, 216, 242 and 245.
* EDSFF slot names now include their .S/.L suffix.
- Preserve the use of term 'BIOS' to avoid breaking customer scripts.
- Preserve the use of non-binary units to avoid breaking customer scripts.
- Drop legacy 'Provides:' and 'Obsoletes:' tags.
The split from the pmtools package happened 15 years ago so they are no longer relevant.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2954-1
Released: Tue Jul 14 11:57:20 2026
Summary: Security update for krb5
Type: security
Severity: important
References: 1268131,CVE-2026-11850
This update for krb5 fixes the following issue
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2983-1
Released: Tue Jul 14 15:19:38 2026
Summary: Security update for jq
Type: security
Severity: moderate
References: 1262044,1262069,1262070,1262071,1262072,CVE-2026-32316,CVE-2026-33947,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164
This update for jq fixes the following issues:
- CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can
lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044).
- CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to
excessive resource consumption when processing crafted JSON input (bsc#1262069).
- CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when
evaluating untrusted jq filters against a release build (bsc#1262070).
- CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an
out-of-bounds read when processing malformed JSON (bsc#1262071).
- CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a
denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).
The following package changes have been done:
- dmidecode-3.7-150400.16.14.1 updated
- jq-1.6-150000.3.20.1 updated
- krb5-1.19.2-150400.3.24.1 updated
- libjq1-1.6-150000.3.20.1 updated
More information about the sle-container-updates
mailing list