SUSE-CU-2026:7420-1: Security update of bci/php
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Mon Jul 27 07:40:34 UTC 2026
SUSE Container Update Advisory: bci/php
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7420-1
Container Tags : bci/php:8 , bci/php:8-sles15 , bci/php:8.3.32 , bci/php:8.3.32-24.20 , bci/php:latest
Container Release : 24.20
Severity : important
Type : security
References : 1252306 1253043 1257463 1263656 1263658 1268290 1269790 1270351
1270393 1270712 1271122 1271129 1271151 1271504 CVE-2024-35241
CVE-2024-35242 CVE-2025-67746 CVE-2026-11979 CVE-2026-12184 CVE-2026-14355
CVE-2026-40176 CVE-2026-40261 CVE-2026-45793 CVE-2026-5435 CVE-2026-54411
CVE-2026-59946 CVE-2026-59947 CVE-2026-59948 CVE-2026-6238
-----------------------------------------------------------------
The container bci/php was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3097-1
Released: Fri Jul 17 13:39:27 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1269790,CVE-2026-11979
This update for libxml2 fixes the following issue
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3105-1
Released: Fri Jul 17 15:32:38 2026
Summary: Security update for php-composer2
Type: security
Severity: important
References: 1271122,1271129,1271151,1271504,CVE-2024-35241,CVE-2024-35242,CVE-2025-67746,CVE-2026-40176,CVE-2026-40261,CVE-2026-45793,CVE-2026-59946,CVE-2026-59947,CVE-2026-59948
This update for php-composer2 fixes the following issues:
- CVE-2026-45793: Github Actions issued `GITHUB_TOKEN` disclosure in GitHub Actions logs (bsc#1271504).
- CVE-2026-59946: path traversal in package `bin` field lets dependencies `chmod` arbitrary host files (bsc#1271151).
- CVE-2026-59947: URL-embedded HTTP-Basic username leaks to verbose logs (bsc#1271129).
- CVE-2026-59948: arbitrary file write outside `vendor`directory via malicious transitive package name (bsc#1271122).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3164-1
Released: Tue Jul 21 16:54:22 2026
Summary: Security update for php8
Type: security
Severity: moderate
References: 1270351,1270712,CVE-2026-12184,CVE-2026-14355
This update for php8 fixes the following issues
- Update to version 8.3.32
- CVE-2026-12184: Failure to setup TLS with a remote server can result in a remote DoS (bsc#1270712).
- CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351).
The following package changes have been done:
- glibc-2.38-150600.14.52.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libxml2-2-2.12.10-150700.4.14.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- php8-cli-8.3.32-150700.3.15.1 updated
- php8-8.3.32-150700.3.15.1 updated
- php8-openssl-8.3.32-150700.3.15.1 updated
- php8-mbstring-8.3.32-150700.3.15.1 updated
- php8-zlib-8.3.32-150700.3.15.1 updated
- php8-readline-8.3.32-150700.3.15.1 updated
- php8-curl-8.3.32-150700.3.15.1 updated
- php8-zip-8.3.32-150700.3.15.1 updated
- php8-phar-8.3.32-150700.3.15.1 updated
- php-composer2-2.6.4-150600.3.12.1 updated
- container:bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated
- container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated
More information about the sle-container-updates
mailing list