SUSE-CU-2026:7476-1: Security update of bci/bci-init

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Jul 28 08:35:26 UTC 2026


SUSE Container Update Advisory: bci/bci-init
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7476-1
Container Tags        : bci/bci-init:15.7 , bci/bci-init:15.7-53.21 , bci/bci-init:latest
Container Release     : 53.21
Severity              : important
Type                  : security
References            : 1252306 1253043 1257463 1261400 1261982 1261983 1262305 1262684
                        1267644 1267647 1268290 1270393 CVE-2026-40226 CVE-2026-41989
                        CVE-2026-54411 
-----------------------------------------------------------------

The container bci/bci-init was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3106-1
Released:    Fri Jul 17 16:02:05 2026
Summary:     Recommended update for kmod
Type:        recommended
Severity:    moderate
References:  
This update for kmod fixes the following issues:

- Use in-kernel decompression if available (jsc#PED-16303):
    * libkmod:
        + Add a separate function to load the file contents when it's needed.
          When it's not needed on the path of loading modules via finit_module(),
          there is no need to mmap the file.
        + Extract 2 functions to handle finit_module vs init_modules differences,
          with a fallback from the former to the latter.
        + Don't only set the type as direct, but also keep track of the compression being used.
        + When creating the context, read /sys/kernel/compression to check. 
          what's the compression type supported by the kernel.
        + Use kernel decompression when available
        + add fallback MODULE_INIT_COMPRESSED_FILE define

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released:    Fri Jul 17 22:18:41 2026
Summary:     Recommended update for gcc15
Type:        recommended
Severity:    moderate
References:  1252306,1253043,1257463
This update for gcc15 fixes the following issues:

- Update to GCC 15.3 release 

- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
  versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t.  Filter out -Wtime_t-conversion
  from flags to build D target library files. [jsc#PED-15601] 
- Remove loongarch64 from quadmath_arch. On LoongArch long double
  is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
  even when not available at build time.  [bsc#1253043] 
- Backport fix that cures a miscompile of libgo on arm.  [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released:    Tue Jul 21 09:04:39 2026
Summary:     Recommended update for shadow
Type:        recommended
Severity:    important
References:  1270393
This update for shadow fixes the following issues:

- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released:    Tue Jul 21 16:50:54 2026
Summary:     Security update for pam
Type:        security
Severity:    moderate
References:  1268290,CVE-2026-54411
This update for pam fixes the following issue

- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3182-1
Released:    Wed Jul 22 09:25:44 2026
Summary:     Security update for libgcrypt
Type:        security
Severity:    moderate
References:  1262684,CVE-2026-41989
This update for libgcrypt fixes the following issue

- CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service
  (bsc#1262684).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released:    Fri Jul 24 15:11:25 2026
Summary:     Security update for systemd
Type:        security
Severity:    moderate
References:  1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues

Security issues fixed:

- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).

Other updates and bugfixes:

- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).


The following package changes have been done:

- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- libgcrypt20-1.11.0-150700.5.10.1 updated
- pam-1.3.0-150000.6.89.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- shadow-4.17.2-150600.17.21.1 updated
- libkmod2-29-150600.13.6.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- systemd-254.27-150600.4.71.2 updated
- container:registry.suse.com-bci-bci-base-15.7-ebddffccbf4bb88422fb5a0e0f8d75b3241585ef8851edcbd3bae809dd8a95b4-0 updated


More information about the sle-container-updates mailing list