SUSE-IU-2026:5991-1: Security update of suse/sl-micro/6.0/baremetal-os-container

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Thu Jul 30 07:13:15 UTC 2026


SUSE Image Update Advisory: suse/sl-micro/6.0/baremetal-os-container
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5991-1
Image Tags        : suse/sl-micro/6.0/baremetal-os-container:2.1.3 , suse/sl-micro/6.0/baremetal-os-container:2.1.3-6.219 , suse/sl-micro/6.0/baremetal-os-container:latest
Image Release     : 6.219
Severity          : moderate
Type              : security
References        : 1239461 1254323 1255451 CVE-2024-58251 CVE-2025-24912 CVE-2025-59529
-----------------------------------------------------------------

The container suse/sl-micro/6.0/baremetal-os-container was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 818
Released:    Wed Jul 29 11:39:58 2026
Summary:     Security update for net-tools
Type:        security
Severity:    low
References:  1254323,CVE-2024-58251
This update for net-tools fixes the following issues:

- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323).

-----------------------------------------------------------------
Advisory ID: 819
Released:    Wed Jul 29 11:55:00 2026
Summary:     Security update for wpa_supplicant
Type:        security
Severity:    low
References:  1239461,CVE-2025-24912
This update for wpa_supplicant fixes the following issue:

- CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS
  server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461).

-----------------------------------------------------------------
Advisory ID: 820
Released:    Wed Jul 29 11:58:45 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1255451,CVE-2025-59529
This update for avahi fixes the following issue:

- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).


The following package changes have been done:

- SL-Micro-release-6.0-25.117 updated
- wpa_supplicant-2.10-6.1 updated
- libavahi-common3-0.8-10.1 updated
- libavahi-core7-0.8-10.1 updated
- libavahi-client3-0.8-10.1 updated
- net-tools-2.10-5.1 updated
- avahi-0.8-10.1 updated
- container:SL-Micro-base-container-2.1.3-7.184 updated


More information about the sle-container-updates mailing list