SUSE-CU-2026:7522-1: Security update of private-registry/harbor-portal
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Thu Jul 30 07:08:46 UTC 2026
SUSE Container Update Advisory: private-registry/harbor-portal
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:7522-1
Container Tags : private-registry/harbor-portal:1.1.3 , private-registry/harbor-portal:1.1.3-2.86 , private-registry/harbor-portal:latest
Container Release : 2.86
Severity : important
Type : security
References : 1267525 1268492 1268495 CVE-2026-42055 CVE-2026-48142
-----------------------------------------------------------------
The container private-registry/harbor-portal was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3329-1
Released: Tue Jul 28 11:34:28 2026
Summary: Security update for nginx
Type: security
Severity: important
References: 1267525,1268492,1268495,CVE-2026-42055,CVE-2026-48142
This update for nginx fixes the following issues
- CVE-2026-42055: heap-based buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules
(bsc#1268492).
- CVE-2026-48142: heap buffer over-read in the `ngx_http_charset_module` module (bsc#1268495).
- Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525).
The following package changes have been done:
- system-user-harbor-2.14.4-150700.1.24 updated
- nginx-1.21.5-150600.10.24.1 updated
- harbor-portal-2.14.4-150700.1.24 updated
- container:suse-sle15-15.7-a5e0c95d4920d65d037fe2ab91c98c6e7c6b609d46ff4844855cbfe5770934aa-0 updated
More information about the sle-container-updates
mailing list