SUSE-CU-2026:7343-1: Security update of suse/sle-micro/5.3/toolbox

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Jul 25 07:11:35 UTC 2026


SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7343-1
Container Tags        : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.256 , suse/sle-micro/5.3/toolbox:latest
Container Release     : 6.11.256
Severity              : important
Type                  : security
References            : 1270008 1270009 1270010 1270016 1270018 1270021 CVE-2026-58010
                        CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014 CVE-2026-58016
-----------------------------------------------------------------

The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3235-1
Released:    Fri Jul 24 14:41:42 2026
Summary:     Security update for glib2
Type:        security
Severity:    important
References:  1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues:

- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
  (bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
  bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
  read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
  bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).


The following package changes have been done:

- libglib-2_0-0-2.70.5-150400.3.37.1 updated
- libgmodule-2_0-0-2.70.5-150400.3.37.1 updated


More information about the sle-container-updates mailing list