SUSE-IU-2026:5755-1: Security update of suse/sl-micro/6.2/base-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 17 08:34:36 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5755-1
Image Tags        : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.37 , suse/sl-micro/6.2/base-os-container:latest
Image Release     : 8.37
Severity          : important
Type              : security
References        : 1252148 1252148 1258371 1259118 1259118 1261850 1261851 1261852
                        1261853 1261854 1261855 1261856 1261857 1271045 CVE-2025-66614
                        CVE-2026-23865 CVE-2026-23865 CVE-2026-24880 CVE-2026-25854 CVE-2026-29129
                        CVE-2026-29145 CVE-2026-29146 CVE-2026-32990 CVE-2026-34483 CVE-2026-34486
                        CVE-2026-34487 CVE-2026-34500 CVE-2026-50811 
-----------------------------------------------------------------

The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 623
Released:    Wed Apr 22 12:52:20 2026
Summary:     Security update for tomcat
Type:        security
Severity:    important
References:  1252148,1258371,1259118,1261850,1261851,1261852,1261853,1261854,1261855,1261856,1261857,CVE-2025-66614,CVE-2026-23865,CVE-2026-24880,CVE-2026-25854,CVE-2026-29129,CVE-2026-29145,CVE-2026-29146,CVE-2026-32990,CVE-2026-34483,CVE-2026-34486,CVE-2026-34487,CVE-2026-34500
This update for tomcat fixes the following issues:

- CVE-2026-24880: Request smuggling via invalid chunk extension (bsc#1261850).
- CVE-2026-25854: Occasionally open redirect (bsc#1261851).
- CVE-2026-29129: TLS cipher order is not preserved (bsc#1261852).
- CVE-2026-29145: OCSP checks sometimes soft-fail even when soft-fail is disabled (bsc#1261853).
- CVE-2026-29146,CVE-2026-34486: Fix for allowed bypass of EncryptInterceptor (bsc#1261854).
- CVE-2026-34483: Incomplete escaping of JSON access logs (bsc#1261855).
- CVE-2026-34487: Cloud membership for clustering component exposed the Kubernetes bearer token (bsc#1261856).
- CVE-2026-34500: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled (bsc#1261857).
- CVE-2026-32990: The fix for CVE-2025-66614 was incomplete. (bsc#1258371)

-----------------------------------------------------------------
Advisory ID: 1276
Released:    Thu Jul 16 20:48:33 2026
Summary:     Security update for freetype2
Type:        security
Severity:    moderate
References:  1252148,1259118,1271045,CVE-2026-23865,CVE-2026-50811
This update for freetype2 fixes the following issues

- Update to version 2.14.3
- CVE-2026-23865: Integer overflow in the tt_var_load_item_variation_store function (bsc#1259118).
- CVE-2026-50811: out-of-bounds read vulnerabilityin src/truetype/ttgxvar.c in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates (bsc#1271045).


The following package changes have been done:

- libfreetype6-2.14.3-160000.1.1 updated
- container:bci-bci-base-16.0-412c34adcd6973e7882e68040c3c6f77fbbc7e3c89e29e6c91d89d8b3044495c-0 updated


More information about the sle-container-updates mailing list