SUSE-IU-2026:5755-1: Security update of suse/sl-micro/6.2/base-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Jul 17 08:34:36 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5755-1
Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.37 , suse/sl-micro/6.2/base-os-container:latest
Image Release : 8.37
Severity : important
Type : security
References : 1252148 1252148 1258371 1259118 1259118 1261850 1261851 1261852
1261853 1261854 1261855 1261856 1261857 1271045 CVE-2025-66614
CVE-2026-23865 CVE-2026-23865 CVE-2026-24880 CVE-2026-25854 CVE-2026-29129
CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34486
CVE-2026-34487 CVE-2026-34500 CVE-2026-50811
-----------------------------------------------------------------
The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 623
Released: Wed Apr 22 12:52:20 2026
Summary: Security update for tomcat
Type: security
Severity: important
References: 1252148,1258371,1259118,1261850,1261851,1261852,1261853,1261854,1261855,1261856,1261857,CVE-2025-66614,CVE-2026-23865,CVE-2026-24880,CVE-2026-25854,CVE-2026-29129,CVE-2026-29145,CVE-2026-29146,CVE-2026-32990,CVE-2026-34483,CVE-2026-34486,CVE-2026-34487,CVE-2026-34500
This update for tomcat fixes the following issues:
- CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850).
- CVE-2026-25854: Occasionally open redirect (bsc#1261851).
- CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852).
- CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853).
- CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854).
- CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855).
- CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856).
- CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857).
- CVE-2026-32990: The fix for CVE-2025-66614 was incomplete. (bsc#1258371)
-----------------------------------------------------------------
Advisory ID: 1276
Released: Thu Jul 16 20:48:33 2026
Summary: Security update for freetype2
Type: security
Severity: moderate
References: 1252148,1259118,1271045,CVE-2026-23865,CVE-2026-50811
This update for freetype2 fixes the following issues
- Update to version 2.14.3
- CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118).
- CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045).
The following package changes have been done:
- libfreetype6-2.14.3-160000.1.1 updated
- container:bci-bci-base-16.0-412c34adcd6973e7882e68040c3c6f77fbbc7e3c89e29e6c91d89d8b3044495c-0 updated
More information about the sle-container-updates
mailing list