SUSE-CU-2026:7337-1: Security update of suse/ltss/sle15.6/sle15

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 24 16:12:24 UTC 2026


SUSE Container Update Advisory: suse/ltss/sle15.6/sle15
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7337-1
Container Tags        : suse/ltss/sle15.6/bci-base:15.6 , suse/ltss/sle15.6/bci-base:15.6-5.75 , suse/ltss/sle15.6/bci-base:latest , suse/ltss/sle15.6/sle15:15.6 , suse/ltss/sle15.6/sle15:15.6-5.75 , suse/ltss/sle15.6/sle15:latest
Container Release     : 5.75
Severity              : important
Type                  : security
References            : 1247850 1247858 1250553 1252306 1253043 1256805 1256807 1256808
                        1256809 1256811 1256812 1257463 1257593 1257594 1257595 1269790
                        CVE-2025-10911 CVE-2025-8732 CVE-2026-0989 CVE-2026-0990 CVE-2026-0992
                        CVE-2026-11979 CVE-2026-1757 
-----------------------------------------------------------------

The container suse/ltss/sle15.6/sle15 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:391-1
Released:    Thu Feb  5 15:23:42 2026
Summary:     Security update for libxml2
Type:        security
Severity:    low
References:  1256805,CVE-2026-0989
This update for libxml2 fixes the following issues:

- CVE-2026-0989: Fixed call stack exhaustion leading to application 
  crash due to RelaxNG parser not limiting the recursion depth when 
  resolving `<include>` directives (bsc#1256805)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:570-1
Released:    Tue Feb 17 17:38:47 2026
Summary:     Security update for libxml2
Type:        security
Severity:    moderate
References:  1247850,1247858,1250553,1256807,1256808,1256809,1256811,1256812,1257593,1257594,1257595,CVE-2025-10911,CVE-2025-8732,CVE-2026-0990,CVE-2026-0992,CVE-2026-1757
This update for libxml2 fixes the following issues:

- CVE-2026-0990: Fixed a call stack overflow leading to application crash due to infinite recursion in `xmlCatalogXMLResolveURI`. (bsc#1256807, bsc#1256811)
- CVE-2026-0992: Fixed an excessive resource consumption when processing XML catalogs due to exponential behavior. (bsc#1256809, bsc#1256812)
- CVE-2026-1757: Fixed a memory leak in the `xmllint` interactive shell. (bsc#1257594, bsc#1257595)
- CVE-2025-10911: Fixed a use-after-free with key data stored cross-RVT. (bsc#1250553)
- CVE-2025-8732: Fixed an infinite recursion in catalog parsing functions when processing malformed SGML catalog files. (bsc#1247858)
  
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3096-1
Released:    Fri Jul 17 13:38:59 2026
Summary:     Security update for libxml2
Type:        security
Severity:    important
References:  1269790,CVE-2026-11979
This update for libxml2 fixes the following issue

- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time

The following package changes have been done:

- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.10.3-150500.5.41.1 updated


More information about the sle-container-updates mailing list