SUSE-CU-2026:7484-1: Security update of private-registry/1.2/harbor-portal
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Jul 29 07:05:31 UTC 2026
SUSE Container Update Advisory: private-registry/1.2/harbor-portal
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7484-1
Container Tags : private-registry/1.2/harbor-portal:1.2.0 , private-registry/1.2/harbor-portal:1.2.0-1.69 , private-registry/1.2/harbor-portal:latest
Container Release : 1.69
Severity : important
Type : security
References : 1267525 1268492 1268495 CVE-2026-42055 CVE-2026-48142
-----------------------------------------------------------------
The container private-registry/1.2/harbor-portal was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3329-1
Released: Tue Jul 28 11:34:28 2026
Summary: Security update for nginx
Type: security
Severity: important
References: 1267525,1268492,1268495,CVE-2026-42055,CVE-2026-48142
This update for nginx fixes the following issues
- CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules
(bsc#1268492).
- CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module` module (bsc#1268495).
- Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).
The following package changes have been done:
- system-user-harbor-2.15.1-150700.1.22 updated
- nginx-1.21.5-150600.10.24.1 updated
- harbor-portal-2.15.1-150700.1.22 updated
- container:suse-sle15-15.7-0411096f465658d23cf7197d39261fa8d818d8fc75c5ad5ce0e68f97a657663f-0 updated
More information about the sle-container-updates
mailing list