SUSE-IU-2026:5853-1: Security update of suse/sl-micro/6.0/kvm-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 24 10:24:12 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5853-1
Image Tags        : suse/sl-micro/6.0/kvm-os-container:2.1.3 , suse/sl-micro/6.0/kvm-os-container:2.1.3-6.186 , suse/sl-micro/6.0/kvm-os-container:latest
Image Release     : 6.186
Severity          : important
Type              : security
References        : 1268290 1269790 CVE-2026-11979 CVE-2026-54411 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/kvm-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 806
Released:    Wed Jul 22 10:36:01 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1269790,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: 805
Released:    Wed Jul 22 10:38:14 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).


The following package changes have been done:

- libxml2-2-2.11.6-13.1 updated
- pam-1.6.0-6.1 updated
- SL-Micro-release-6.0-25.112 updated
- container:SL-Micro-base-container-2.1.3-7.176 updated


More information about the sle-container-updates mailing list