SUSE-IU-2026:5975-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 29 07:09:11 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5975-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.216 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 6.216
Severity          : important
Type              : security
References        : 1270198 1270429 1270470 1270582 1270683 1270721 1270831 1270877
                        CVE-2025-24898 CVE-2026-41676 CVE-2026-41677 CVE-2026-41678 CVE-2026-41681
                        CVE-2026-41898 CVE-2026-42327 CVE-2026-44662 
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 817
Released:    Tue Jul 28 19:32:56 2026
Summary:     Security update for libkrun
Type:        security
Severity:    important
References:  1270198,1270429,1270470,1270582,1270683,1270721,1270831,1270877,CVE-2025-24898,CVE-2026-41676,CVE-2026-41677,CVE-2026-41678,CVE-2026-41681,CVE-2026-41898,CVE-2026-42327,CVE-2026-44662
This update for libkrun fixes the following issues:

- CVE-2025-24898: openssl: select_next_proto use after free in rust-openssl (bsc#1270429).
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1
  (bsc#1270198).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
  openssl crate (bsc#1270582).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270683).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
  (bsc#1270721).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
  memory in rust-openssl crate (bsc#1270831).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
  (bsc#1270470).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
  (bsc#1270877).

Changes for libkrun:

- Update vendored openssl crate to version 0.10.81.


The following package changes have been done:

- libkrun1-1.4.10-2.1 updated


More information about the sle-container-updates mailing list