SUSE-IU-2026:5872-1: Security update of suse/sl-micro/6.1/kvm-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 24 11:24:53 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.1/kvm-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5872-1
Image Tags        : suse/sl-micro/6.1/kvm-os-container:2.2.1 , suse/sl-micro/6.1/kvm-os-container:2.2.1-5.158 , suse/sl-micro/6.1/kvm-os-container:latest
Image Release     : 5.158
Severity          : important
Type              : security
References        : 1252974 1254400 1254401 1254997 1257029 1257031 1257042 1257046
                        1258406 1258730 1259385 1268290 1269489 1269790 CVE-2025-11468
                        CVE-2025-12084 CVE-2025-13836 CVE-2025-13837 CVE-2025-15282 CVE-2025-6075
                        CVE-2026-0672 CVE-2026-0865 CVE-2026-11979 CVE-2026-2219 CVE-2026-54411
                        CVE-2026-58055 
-----------------------------------------------------------------

The container suse/sl-micro/6.1/kvm-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 624
Released:    Wed Jul 22 10:53:15 2026
Summary:     Security update for nghttp2
Type:        security
Severity:    moderate
References:  1258406,1258730,1269489,CVE-2026-58055
This update for nghttp2 fixes the following issue

- CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489).

-----------------------------------------------------------------
Advisory ID: 630
Released:    Wed Jul 22 10:53:15 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1252974,1254400,1254401,1254997,1257029,1257031,1257042,1257046,1269790,CVE-2025-11468,CVE-2025-12084,CVE-2025-13836,CVE-2025-13837,CVE-2025-15282,CVE-2025-6075,CVE-2026-0672,CVE-2026-0865,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: 629
Released:    Wed Jul 22 10:59:50 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1259385,1268290,CVE-2026-2219,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext-password comparison (bsc#1268290).


The following package changes have been done:

- libxml2-2-2.11.6-slfo.1.1_9.1 updated
- pam-1.6.1-slfo.1.1_5.1 updated
- SL-Micro-release-6.1-slfo.1.12.54 updated
- kernel-default-base-6.4.0-50.1.21.30 updated
- libnghttp2-14-1.52.0-slfo.1.1_3.1 updated
- container:SL-Micro-base-container-2.2.1-5.155 updated


More information about the sle-container-updates mailing list