SUSE-CU-2026:7062-1: Security update of suse/sle-micro-rancher/5.4
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Jul 16 07:44:01 UTC 2026
SUSE Container Update Advisory: suse/sle-micro-rancher/5.4
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7062-1
Container Tags : suse/sle-micro-rancher/5.4:5.4.4.5.149 , suse/sle-micro-rancher/5.4:latest
Container Release : 4.5.149
Severity : important
Type : security
References : 1263656 1263658 1264097 1264145 1265421 1267531 1267567 1267635
1267684 1267722 1267918 1267993 1268022 1268402 1268407 1268409
1268413 1268415 1268416 1268417 1268420 1268422 1268427 1268660
1269022 1269033 1269036 1269090 1269100 1269159 1269184 1269193
1269195 1269310 1269398 1269574 1269678 1269681 1269821 1270059
CVE-2026-10536 CVE-2026-12064 CVE-2026-31771 CVE-2026-43038 CVE-2026-46090
CVE-2026-46173 CVE-2026-46229 CVE-2026-46253 CVE-2026-46266 CVE-2026-46274
CVE-2026-46319 CVE-2026-46320 CVE-2026-46331 CVE-2026-52909 CVE-2026-52918
CVE-2026-52923 CVE-2026-52924 CVE-2026-52943 CVE-2026-52955 CVE-2026-52969
CVE-2026-52972 CVE-2026-52993 CVE-2026-53016 CVE-2026-53041 CVE-2026-53053
CVE-2026-53071 CVE-2026-53072 CVE-2026-53133 CVE-2026-53253 CVE-2026-53359
CVE-2026-5435 CVE-2026-6238 CVE-2026-8286 CVE-2026-8458 CVE-2026-8924
CVE-2026-8927 CVE-2026-9079 CVE-2026-9080 CVE-2026-9545 CVE-2026-9547
-----------------------------------------------------------------
The container suse/sle-micro-rancher/5.4 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3029-1
Released: Wed Jul 15 11:52:19 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3043-1
Released: Wed Jul 15 13:51:04 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547
This update for curl fixes the following issues
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3044-1
Released: Wed Jul 15 13:59:23 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1264097,1264145,1265421,1267531,1267567,1267635,1267684,1267722,1267918,1267993,1268022,1268660,1269022,1269033,1269036,1269090,1269100,1269159,1269184,1269193,1269195,1269310,1269398,1269574,1269678,1269681,1269821,1270059,CVE-2026-31771,CVE-2026-43038,CVE-2026-46090,CVE-2026-46173,CVE-2026-46229,CVE-2026-46253,CVE-2026-46266,CVE-2026-46274,CVE-2026-46319,CVE-2026-46320,CVE-2026-46331,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52924,CVE-2026-52943,CVE-2026-52955,CVE-2026-52969,CVE-2026-52972,CVE-2026-52993,CVE-2026-53016,CVE-2026-53041,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53133,CVE-2026-53253,CVE-2026-53359
The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues
The following security issues were fixed:
- CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).
- CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097).
- CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531).
- CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).
- CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).
- CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).
- CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).
- CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).
- CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).
- CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421).
- CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).
- CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).
- CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).
- CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).
- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
- CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).
- CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).
- CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
- CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).
- CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).
- CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).
- CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).
- CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).
- CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574).
- CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).
The following package changes have been done:
- curl-8.14.1-150400.5.86.1 updated
- glibc-locale-base-2.31-150300.104.1 updated
- glibc-2.31-150300.104.1 updated
- kernel-default-5.14.21-150400.24.228.1 updated
- libcurl4-8.14.1-150400.5.86.1 updated
More information about the sle-container-updates
mailing list