SUSE-IU-2026:5860-1: Security update of suse/sl-micro/6.1/baremetal-os-container
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Jul 24 10:35:52 UTC 2026
SUSE Image Update Advisory: suse/sl-micro/6.1/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5860-1
Image Tags : suse/sl-micro/6.1/baremetal-os-container:2.2.1 , suse/sl-micro/6.1/baremetal-os-container:2.2.1-7.138 , suse/sl-micro/6.1/baremetal-os-container:latest
Image Release : 7.138
Severity : important
Type : security
References : 1236217 1244485 1252148 1256818 1256820 1257692 1258406 1258730
1259118 1259264 1259265 1259268 1259385 1265075 1265076 1268290
1268490 1269220 1269390 1269489 1271193 1271194 1271195 CVE-2025-61732
CVE-2025-68119 CVE-2025-68121 CVE-2026-2219 CVE-2026-23865 CVE-2026-25679
CVE-2026-27139 CVE-2026-27142 CVE-2026-43896 CVE-2026-44777 CVE-2026-49839
CVE-2026-54411 CVE-2026-54679 CVE-2026-58055 CVE-2026-59856 CVE-2026-59857
CVE-2026-59858
-----------------------------------------------------------------
The container suse/sl-micro/6.1/baremetal-os-container was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 623
Released: Wed Jul 22 09:45:44 2026
Summary: Recommended update for container-selinux
Type: recommended
Severity: important
References: 1252148,1259118,1268490,CVE-2026-23865
This update for container-selinux fixes the following issues:
- Introduce container_can_execstack boolean for older Java applications
and allow execmem (bsc#1268490)
-----------------------------------------------------------------
Advisory ID: 624
Released: Wed Jul 22 10:53:15 2026
Summary: Security update for nghttp2
Type: security
Severity: moderate
References: 1258406,1258730,1269489,CVE-2026-58055
This update for nghttp2 fixes the following issue
- CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489).
-----------------------------------------------------------------
Advisory ID: 629
Released: Wed Jul 22 10:59:50 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1259385,1268290,CVE-2026-2219,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: 632
Released: Wed Jul 22 13:05:15 2026
Summary: Security update for jq
Type: security
Severity: important
References: 1236217,1256818,1256820,1257692,1265075,1265076,1269220,1269390,CVE-2025-61732,CVE-2025-68119,CVE-2025-68121,CVE-2026-43896,CVE-2026-44777,CVE-2026-49839,CVE-2026-54679
This update for jq fixes the following issues
- CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075).
- CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules include each other can lead to stack exhaustion and process crash (bsc#1265076).
- CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized-string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220).
- CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390).
-----------------------------------------------------------------
Advisory ID: 633
Released: Wed Jul 22 13:18:45 2026
Summary: Security update for vim
Type: security
Severity: important
References: 1244485,1259264,1259265,1259268,1271193,1271194,1271195,CVE-2026-25679,CVE-2026-27139,CVE-2026-27142,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858
This update for vim fixes the following issues
- Updated to version 9.2.0780
- CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194).
- CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195).
- CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193).
The following package changes have been done:
- libxml2-2-2.11.6-slfo.1.1_9.1 updated
- pam-1.6.1-slfo.1.1_5.1 updated
- SL-Micro-release-6.1-slfo.1.12.54 updated
- libnghttp2-14-1.52.0-slfo.1.1_3.1 updated
- vim-data-common-9.2.0780-slfo.1.1_1.1 updated
- libjq1-1.7.1-slfo.1.1_4.1 updated
- vim-small-9.2.0780-slfo.1.1_1.1 updated
- jq-1.7.1-slfo.1.1_4.1 updated
- container-selinux-2.236.0-slfo.1.1_2.1 updated
- container:SL-Micro-base-container-2.2.1-5.155 updated
More information about the sle-container-updates
mailing list