SUSE-CU-2026:7392-1: Security update of bci/golang

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sun Jul 26 08:15:22 UTC 2026


SUSE Container Update Advisory: bci/golang
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7392-1
Container Tags        : bci/golang:1.25 , bci/golang:1.25-sles15 , bci/golang:1.25.12 , bci/golang:1.25.12-2.76.19 , bci/golang:oldstable
Container Release     : 76.19
Severity              : moderate
Type                  : security
References            : 1252306 1253043 1257463 1262684 1263656 1263658 CVE-2026-41989
                        CVE-2026-5435 CVE-2026-6238 
-----------------------------------------------------------------

The container bci/golang was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2972-1
Released:    Tue Jul 14 13:33:14 2026
Summary:     Recommended update for lifecycle-data-sle-module-development-tools
Type:        recommended
Severity:    moderate
References:  
This update for lifecycle-data-sle-module-development-tools fixes the following issues:

- lifecycle of gcc14 got extended until end of july.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released:    Wed Jul 15 11:53:06 2026
Summary:     Security update for glibc
Type:        security
Severity:    moderate
References:  1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues

- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
  (bsc#1263658).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released:    Wed Jul 22 09:25:44 2026
Summary:     Security update for libgcrypt
Type:        security
Severity:    moderate
References:  1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue

- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
  (bsc#1262684).


The following package changes have been done:

- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- libcurl4-8.14.1-150700.7.20.1 updated
- libatomic1-15.3.0+git11272-150000.1.12.1 updated
- libgomp1-15.3.0+git11272-150000.1.12.1 updated
- libitm1-15.3.0+git11272-150000.1.12.1 updated
- liblsan0-15.3.0+git11272-150000.1.12.1 updated
- lifecycle-data-sle-module-development-tools-1-150200.3.39.1 updated
- glibc-devel-2.38-150600.14.52.1 updated
- container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated


More information about the sle-container-updates mailing list