SUSE-CU-2026:7405-1: Security update of suse/kubectl
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Jul 27 07:28:01 UTC 2026
SUSE Container Update Advisory: suse/kubectl
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7405-1
Container Tags : suse/kubectl:1.35 , suse/kubectl:1.35.4 , suse/kubectl:1.35.4-1.69.20 , suse/kubectl:latest , suse/kubectl:stable
Container Release : 69.20
Severity : important
Type : security
References : 1252306 1253043 1257463 1263656 1263658 CVE-2026-5435 CVE-2026-6238
-----------------------------------------------------------------
The container suse/kubectl was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3050-1
Released: Wed Jul 15 15:09:00 2026
Summary: Security update for helm
Type: security
Severity: important
References:
This update for helm rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
The following package changes have been done:
- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- helm-3.21.2-150000.1.82.1 updated
- container:suse-sle15-15.7-0ef6774b43a9e6ba3202c944b3069e16eb36d4ad208b0d5280641a198f19923c-0 updated
- container:registry.suse.com-bci-bci-micro-15.7-4cdcad941236068fdf4cac1f3008600d478ebbf78236677452a662ae1f3fe792-0 updated
More information about the sle-container-updates
mailing list