SUSE-CU-2026:6834-1: Security update of suse/multi-linux-manager/5.1/x86_64/server

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Wed Jul 8 09:11:07 UTC 2026


SUSE Container Update Advisory: suse/multi-linux-manager/5.1/x86_64/server
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:6834-1
Container Tags        : suse/multi-linux-manager/5.1/x86_64/server:5.1.4 , suse/multi-linux-manager/5.1/x86_64/server:5.1.4.8.22.1 , suse/multi-linux-manager/5.1/x86_64/server:latest
Container Release     : 8.22.1
Severity              : critical
Type                  : security
References            : 1158038 1208800 1226578 1233668 1234100 1234101 1234102 1234103
                        1234104 1234567 1235475 1238890 1239718 1242916 1243268 1245107
                        1246196 1246504 1247707 1247948 1248699 1248699 1248707 1249243
                        1249435 1250782 1250782 1252744 1252964 1253032 1253088 1253193
                        1253740 1254441 1254619 1254900 1254903 1254904 1254905 1255752
                        1255755 1257068 1257200 1257583 1257882 1257894 1257941 1258041
                        1258079 1258144 1258193 1258364 1258382 1258595 1258816 1258873
                        1258893 1258927 1259087 1259208 1259230 1259261 1259311 1259327
                        1259441 1259474 1259479 1259482 1259521 1259553 1259590 1259591
                        1259630 1259635 1259642 1259700 1259706 1259739 1259787 1259802
                        1259836 1259842 1259928 1259931 1259960 1259999 1260031 1260263
                        1260267 1260614 1260806 1260878 1260881 1261025 1261026 1261027
                        1261029 1261158 1261159 1261160 1261161 1261163 1261186 1261188
                        1261206 1261280 1261305 1261307 1261327 1261427 1261427 1261430
                        1261430 1261441 1261546 1261606 1261631 1261723 1261753 1261810
                        1261833 1261841 1261900 1261902 1261970 1262050 1262090 1262091
                        1262092 1262093 1262144 1262222 1262222 1262223 1262285 1262395
                        1262460 1262464 1262465 1262471 1262492 1262595 1262708 1262720
                        1262760 1262761 1262803 1262803 1262950 1262950 1263254 1263494
                        1263501 1263501 1263704 1263705 1263707 1263708 1263709 1263710
                        1263711 1263712 1263713 1263714 1263715 1263716 1263804 1263804
                        1263814 1263816 1263841 1263935 1263950 1263951 1263952 1263953
                        1263954 1263955 1263956 1263957 1263986 1263986 1263987 1263987
                        1264149 1264150 1264163 1264174 1264174 1264185 1264234 1264256
                        1264350 1264511 1264512 1264513 1264514 1264515 1264568 1264706
                        1264707 1264708 1264715 1264965 1264966 1264971 1265134 1265145
                        1265162 1265163 1265165 1265166 1265167 1265168 1265172 1265172
                        1265173 1265173 1265174 1265174 1265175 1265175 1265176 1265177
                        1265177 1265178 1265178 1265179 1265179 1265180 1265181 1265181
                        1265182 1265182 1265223 1265243 1265245 1265246 1265267 1265267
                        1265272 1265273 1265277 1265279 1265280 1265281 1265282 1265283
                        1265284 1265285 1265286 1265287 1265288 1265289 1265290 1265292
                        1265294 1265296 1265299 1265318 1265319 1265349 1265358 1265360
                        1265450 1265591 1265592 1265593 1265594 1265595 1265596 1265620
                        1265935 1265938 1265975 1266012 1266039 1266340 1266340 1266341
                        1266341 1266342 1266342 1266343 1266345 1266349 1266349 1266350
                        1266351 1266352 1266353 1266355 1266356 1266357 1266357 1266370
                        1266556 1266600 1266798 1266799 1266801 1266802 1267189 1267426
                        1267503 1267823 1267849 1267874 1267955 1267956 1267957 1267962
                        1267963 1267965 1267969 1267970 1267971 1267972 1267976 1267977
                        1267978 1268012 1268013 1268395 1268396 1268397 1269253 1269534
                        CVE-2022-21698 CVE-2022-21698 CVE-2024-12084 CVE-2024-12085 CVE-2024-12086
                        CVE-2024-12087 CVE-2024-12088 CVE-2024-12747 CVE-2024-52804 CVE-2025-10158
                        CVE-2025-29923 CVE-2025-47287 CVE-2025-60753 CVE-2025-67724 CVE-2025-67725
                        CVE-2025-67726 CVE-2026-10879 CVE-2026-11822 CVE-2026-11824 CVE-2026-1933
                        CVE-2026-21724 CVE-2026-21725 CVE-2026-2340 CVE-2026-23918 CVE-2026-24072
                        CVE-2026-25707 CVE-2026-26740 CVE-2026-26958 CVE-2026-27456 CVE-2026-27606
                        CVE-2026-27876 CVE-2026-27877 CVE-2026-27879 CVE-2026-28374 CVE-2026-28375
                        CVE-2026-28376 CVE-2026-28379 CVE-2026-28380 CVE-2026-28383 CVE-2026-28780
                        CVE-2026-29167 CVE-2026-29168 CVE-2026-29169 CVE-2026-29170 CVE-2026-29518
                        CVE-2026-3012 CVE-2026-3039 CVE-2026-31958 CVE-2026-3238 CVE-2026-33006
                        CVE-2026-33007 CVE-2026-33186 CVE-2026-33375 CVE-2026-33376 CVE-2026-33377
                        CVE-2026-33378 CVE-2026-33380 CVE-2026-33381 CVE-2026-33523 CVE-2026-33845
                        CVE-2026-33846 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 CVE-2026-34180
                        CVE-2026-34180 CVE-2026-34181 CVE-2026-34183 CVE-2026-34355 CVE-2026-34356
                        CVE-2026-3446 CVE-2026-34477 CVE-2026-34479 CVE-2026-34480 CVE-2026-34481
                        CVE-2026-34743 CVE-2026-34933 CVE-2026-3497 CVE-2026-34986 CVE-2026-34986
                        CVE-2026-35385 CVE-2026-35385 CVE-2026-35388 CVE-2026-35414 CVE-2026-35414
                        CVE-2026-3592 CVE-2026-3593 CVE-2026-3833 CVE-2026-39821 CVE-2026-39881
                        CVE-2026-40179 CVE-2026-40179 CVE-2026-4046 CVE-2026-40475 CVE-2026-40475
                        CVE-2026-41035 CVE-2026-41066 CVE-2026-4111 CVE-2026-41284 CVE-2026-41293
                        CVE-2026-41417 CVE-2026-41602 CVE-2026-41602 CVE-2026-42009 CVE-2026-42010
                        CVE-2026-42011 CVE-2026-42012 CVE-2026-42013 CVE-2026-42014 CVE-2026-42015
                        CVE-2026-42151 CVE-2026-42151 CVE-2026-42154 CVE-2026-42154 CVE-2026-42198
                        CVE-2026-42198 CVE-2026-42307 CVE-2026-42498 CVE-2026-42535 CVE-2026-42536
                        CVE-2026-42578 CVE-2026-42579 CVE-2026-42580 CVE-2026-42581 CVE-2026-42582
                        CVE-2026-42583 CVE-2026-42584 CVE-2026-42585 CVE-2026-42586 CVE-2026-42587
                        CVE-2026-42766 CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769
                        CVE-2026-42770 CVE-2026-43512 CVE-2026-43513 CVE-2026-43514 CVE-2026-43515
                        CVE-2026-43617 CVE-2026-43618 CVE-2026-43619 CVE-2026-43620 CVE-2026-43951
                        CVE-2026-43961 CVE-2026-4408 CVE-2026-44119 CVE-2026-44185 CVE-2026-44186
                        CVE-2026-4424 CVE-2026-44248 CVE-2026-4426 CVE-2026-44431 CVE-2026-44431
                        CVE-2026-44631 CVE-2026-44656 CVE-2026-4480 CVE-2026-44933 CVE-2026-44941
                        CVE-2026-44942 CVE-2026-45130 CVE-2026-45205 CVE-2026-45232 CVE-2026-45445
                        CVE-2026-45446 CVE-2026-45447 CVE-2026-45447 CVE-2026-46483 CVE-2026-48522
                        CVE-2026-48523 CVE-2026-48525 CVE-2026-48526 CVE-2026-48863 CVE-2026-48913
                        CVE-2026-49853 CVE-2026-49854 CVE-2026-49855 CVE-2026-49975 CVE-2026-5121
                        CVE-2026-5260 CVE-2026-5419 CVE-2026-5450 CVE-2026-5704 CVE-2026-5928
                        CVE-2026-5946 CVE-2026-5947 CVE-2026-5950 CVE-2026-5958 CVE-2026-6472
                        CVE-2026-6472 CVE-2026-6473 CVE-2026-6473 CVE-2026-6474 CVE-2026-6474
                        CVE-2026-6475 CVE-2026-6475 CVE-2026-6476 CVE-2026-6477 CVE-2026-6477
                        CVE-2026-6478 CVE-2026-6478 CVE-2026-6479 CVE-2026-6479 CVE-2026-6575
                        CVE-2026-6637 CVE-2026-6637 CVE-2026-6638 CVE-2026-6638 CVE-2026-7383
                        CVE-2026-7383 CVE-2026-8177 CVE-2026-8450 CVE-2026-9076 CVE-2026-9076
                        CVE-2026-9149 CVE-2026-9150 CVE-2026-9698 
-----------------------------------------------------------------

The container suse/multi-linux-manager/5.1/x86_64/server was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2024:4137-1
Released:    Mon Dec  2 13:28:37 2024
Summary:     Security update for python-tornado6
Type:        security
Severity:    moderate
References:  1233668,CVE-2024-52804
This update for python-tornado6 fixes the following issues:

- CVE-2024-52804: Fixed a denial of service caused by quadratic performance of cookie parsing (bsc#1233668)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2025:1649-1
Released:    Thu May 22 09:44:52 2025
Summary:     Security update for python-tornado6
Type:        security
Severity:    important
References:  1243268,CVE-2025-47287
This update for python-tornado6 fixes the following issues:
    
- CVE-2025-47287: excessive logging when parsing malformed `multipart/form-data` can lead to a denial-of-service
  (bsc#1243268).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:10-1
Released:    Mon Jan  5 11:26:28 2026
Summary:     Security update for python-tornado6
Type:        security
Severity:    important
References:  1254903,1254904,1254905,CVE-2025-67724,CVE-2025-67725,CVE-2025-67726
This update for python-tornado6 fixes the following issues:

- CVE-2025-67724: unescaped `reason` argument used in HTTP headers and in HTML default error pages can be used by
  attackers to launch header injection or XSS attacks (bsc#1254903).
- CVE-2025-67725: quadratic complexity of string concatenation operations used by the `HTTPHeaders.add` method can lead
  to DoS when processing a maliciously crafted HTTP request (bsc#1254905).
- CVE-2025-67726: quadratic complexity algorithm used in the `_parseparam` function of `httputil.py` can lead to DoS
  when processing maliciously crafted parameters in a `Content-Disposition` header (bsc#1254904).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1064-1
Released:    Thu Mar 26 11:37:21 2026
Summary:     Security update for python-tornado6
Type:        security
Severity:    important
References:  1259553,1259630,CVE-2026-31958
This update for python-tornado6 fixes the following issues:

- CVE-2026-31958: parsing large multipart bodies with many parts can cause a denial of service (bsc#1259553).
- incomplete validation of cookie attributes allows for injection of user-controlled values in other cookie attributes
  (bsc#1259630).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:1836-1
Released:    Tue May 12 20:06:01 2026
Summary:     Recommended update for libvirt
Type:        recommended
Severity:    moderate
References:  
This update for libvirt, numa-preplace fixes the following issues:

- Add numa-preplace (jsc#PED-15886)  
- qemu: Use numa-preplace instead of numad for numa placement advice (bsc#1242979)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1843-1
Released:    Wed May 13 17:24:48 2026
Summary:     Security update for log4j
Type:        security
Severity:    moderate
References:  1262050,1262091,1262092,1262093,CVE-2026-34477,CVE-2026-34479,CVE-2026-34480,CVE-2026-34481
This update for log4j fixes the following issues:

- CVE-2026-34477: TLS connections vulnerable to interception due to incomplete hostname verification configuration
  checks (bsc#1262050).
- CVE-2026-34479: silent log event loss due to improper XML escaping in `Log4j1XmlLayout` (bsc#1262091).
- CVE-2026-34480: silent log event loss due to improper XML escaping in `XmlLayout` (bsc#1262092).
- CVE-2026-34481: silent log event loss due to improper serialization of non-finite floating-point values in
  `JsonTemplateLayout` (bsc#1262093).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1876-1
Released:    Sat May 16 00:06:36 2026
Summary:     Security update for openssh
Type:        security
Severity:    important
References:  1261427,1261430,CVE-2026-35385,CVE-2026-35414
This update for openssh fixes the following issues

- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1941-1
Released:    Mon May 18 09:44:34 2026
Summary:     Security update for sed
Type:        security
Severity:    moderate
References:  1262144,CVE-2026-5958
This update for sed fixes the following issue:

- CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:1944-1
Released:    Mon May 18 09:47:19 2026
Summary:     Security update for postgresql18
Type:        security
Severity:    important
References:  1263804,1265172,1265173,1265174,1265175,1265176,1265177,1265178,1265179,1265180,1265181,1265182,CVE-2026-6472,CVE-2026-6473,CVE-2026-6474,CVE-2026-6475,CVE-2026-6476,CVE-2026-6477,CVE-2026-6478,CVE-2026-6479,CVE-2026-6575,CVE-2026-6637,CVE-2026-6638
This update for postgresql18 fixes the following issues

Update to version 18.4.

Security issues:

- CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172).
- CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173).
- CVE-2026-6474: Guard against malicious time zone names (bsc#1265174).
- CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175).
- CVE-2026-6476: Properly quote subscription names in pg_createsubscriber (bsc#1265176).
- CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177).
- CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178).
- CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179).
- CVE-2026-6575: Detect faulty input when restoring attribute MCV statistics (bsc#1265180).
- CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181).
- CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182).

Non security issue:

- Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional
  updates (jsc#PED-14820).
- /usr/bin/pg_config is missing after migrating away from update-alternatives (bsc#1263804).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2001-1
Released:    Tue May 19 10:20:57 2026
Summary:     Security update for postgresql16
Type:        security
Severity:    important
References:  1263804,1265172,1265173,1265174,1265175,1265177,1265178,1265179,1265181,1265182,CVE-2026-6472,CVE-2026-6473,CVE-2026-6474,CVE-2026-6475,CVE-2026-6477,CVE-2026-6478,CVE-2026-6479,CVE-2026-6637,CVE-2026-6638
This update for postgresql16 fixes the following issues

Update to version 16.13.

Security issues:

- CVE-2026-6472: ensure the user has CREATE privilege on the schema specified (bsc#1265172).
- CVE-2026-6473: integer overflows in memory-allocation calculations (bsc#1265173).
- CVE-2026-6474: Guard against malicious time zone names (bsc#1265174).
- CVE-2026-6475: Prevent path traversal in pg_basebackup and pg_rewind (bsc#1265175).
- CVE-2026-6477: Mark PQfn() as unsafe, and avoid using it within libpq (bsc#1265177).
- CVE-2026-6478: Use timing-safe string comparisons in authentication code (bsc#1265178).
- CVE-2026-6479: Prevent unbounded recursion while processing startup packets (bsc#1265179).
- CVE-2026-6637: Prevent SQL injection and buffer overruns in contrib/spi (bsc#1265181).
- CVE-2026-6638: Properly quote object names in logical replication origin checks (bsc#1265182).

Non security issue:

- Get rid of update-alternatives for openSUSE/SLE 16.0 and newer to support immutable systems and transactional
  updates (jsc#PED-14824).
- /usr/bin/pg_config is missing after migrating away from update-alternatives (bsc#1263804).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2014-1
Released:    Tue May 19 16:13:13 2026
Summary:     Recommended update for fence-agents
Type:        recommended
Severity:    important
References:  1263816
This update for fence-agents fixes the following issues:

- azure-cli - Stonith failing to start - 'raise ValueError('API version {} 
  does not have operation group 'virtual_machines''.format(api_version))' (bsc#1263816)
- fence_vmware_rest: monitoring is not detecting problems accessing the fence device

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2027-1
Released:    Wed May 20 10:14:16 2026
Summary:     Recommended update for sssd
Type:        recommended
Severity:    important
References:  1246196,1264185
This update for sssd fixes the following issues:

- Reduce the message severity logged when the LDAP server hosts multiple 
  naming contexts without defining a default one in the rootdse (bsc#1264185);
- Do not ignore tests result at build time (bsc#1246196);
- Skip tests depending on soft-hsm;

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2028-1
Released:    Wed May 20 11:07:11 2026
Summary:     Security update for postgresql-jdbc
Type:        security
Severity:    important
References:  1264174,CVE-2026-42198
This update for postgresql-jdbc fixes the following issue

- CVE-2026-42198: client-side denial of service via malicious SCRAM-SHA-256 authentication (bsc#1264174).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2029-1
Released:    Wed May 20 11:18:08 2026
Summary:     Security update for vim
Type:        security
Severity:    moderate
References:  1261833,CVE-2026-39881
This update for vim fixes the following issue:

Security fixes:

- CVE-2026-39881: command injection in NetBeans interface can lead to arbitrary file reads and writes (bsc#1261833).

Other fixes:

- Update to 9.2.0398.
 * 9.2.0398: MS-Windows: missing strptime() support
 * 9.2.0397: tabpanel: double-click opens a new tab
 * 9.2.0396: tests: Test_error_callback_terminal is flaky on macOS
 * 9.2.0395: tests: Test_backupskip() may read from $HOME
 * 9.2.0394: xxd: offsets greater than LONG_MAX print as negative
 * 9.2.0393: MS-Windows: link error with XPM support on UCRT64
 * 9.2.0392: tests: Some tests are flaky
 * 9.2.0391: tests: Comment in test_vim9_cmd breaks syntax highlighting
 * 9.2.0390: filetype: some Beancount files are not recognized
 * 9.2.0389: DECRQM still leaves stray 'pp' on Apple Terminal.app
 * 9.2.0388: strange indent in update_topline()
 * 9.2.0387: DECRQM request may leave stray chars in terminal
 * 9.2.0386: No scroll/scrollbar support in the tabpanel
 * 9.2.0385: Integer overflow with 'ze' and large 'sidescrolloff'
 * 9.2.0384: stale Insstart after <Cmd> cursor move breaks undo
 * 9.2.0383: [security]: runtime(netrw): shell-injection via sftp: and file: URLs
 * 9.2.0382: Wayland: focus-stealing is non-working
 * 9.2.0381: Vim9: Missing check_secure() in exec_instructions()
 * 9.2.0380: completion: a few issues in completion code
 * 9.2.0379: gui.color_approx is never used
 * 9.2.0378: Using int as bool type in win_T struct
 * 9.2.0377: Using int as bool type in gui_T struct
 * 9.2.0376: Vim9: elseif condition compiled in dead branch
 * 9.2.0375: prop_find() does not find a virt text in starting line
 * 9.2.0374: c_CTRL-{G,T} does not handle offset
 * 9.2.0373: Ctrl-R mapping not triggered during completion
 * 9.2.0372: pum: rendering issues with multibyte text and opacity
 * 9.2.0371: filetype: ghostty config files are not recognized
 * 9.2.0370: duplicate code with literal string_T assignment
 * 9.2.0369: multiple definitions of STRING_INIT macro
 * 9.2.0368: too many strlen() calls when adding strings to dicts
 * 9.2.0367: runtime(netrw): ~ note expanded on MS Windows
 * 9.2.0366: pum: flicker when updating pum in place
 * 9.2.0365: using int as bool
 * 9.2.0364: tests: test_smoothscroll_textoff_showbreak() fails
 * 9.2.0363: Vim9: variable shadowed by script-local function
 * 9.2.0362: division by zero with smoothscroll and small windows
 * 9.2.0361: tests: no tests for ch_listen() with IPs
 * 9.2.0360: Cannot handle mouse-clicks in the tabpanel
 * 9.2.0359: wrong VertSplitNC highlighting on winbar
 * 9.2.0358: runtime(vimball): still path traversal attacks possible
 * 9.2.0357: [security]: command injection via backticks in tag files
 * 9.2.0356: Cannot apply 'scrolloff' context lines at end of file
 * 9.2.0355: runtime(tar): missing path traversal checks in tar#Extract()
 * 9.2.0354: filetype: not all Bitbake include files are recognized
 * 9.2.0353: Missing out-of-memory check in register.c
 * 9.2.0352: 'winhighlight' of left window blends into right window
 * 9.2.0351: repeat_string() can be improved
 * 9.2.0350: Enabling modelines poses a risk
 * 9.2.0349: cannot style non-current window separator
 * 9.2.0348: potential buffer underrun when setting statusline like option
 * 9.2.0347: Vim9: script-local variable not found
 * 9.2.0346: Wrong cursor position when entering command line window
 * 9.2.0345: Wrong autoformatting with 'autocomplete'
 * 9.2.0344: channel: ch_listen() can bind to network interface
 * 9.2.0343: tests: test_clientserver may fail on slower systems
 * 9.2.0342: tests: test_excmd.vim leaves swapfiles behind
 * 9.2.0341: some functions can be run from the sandbox
 * 9.2.0340: pum_redraw() may cause flicker
 * 9.2.0339: regexp: nfa_regmatch() allocates and frees too often
 * 9.2.0338: Cannot handle mouseclicks in the tabline
 * 9.2.0337: list indexing broken on big-endian 32-bit platforms
 * 9.2.0336: libvterm: no terminal reflow support
 * 9.2.0335: json_encode() uses recursive algorithm
 * 9.2.0334: GTK: window geometry shrinks with with client-side decorations
 * 9.2.0333: filetype: PklProject files are not recognized
 * 9.2.0332: popup: still opacity rendering issues
 * 9.2.0331: spellfile: stack buffer overflows in spell file generation
 * 9.2.0330: tests: some patterns in tar and zip plugin tests not strict enough
 * 9.2.0329: tests: test_indent.vim leaves swapfiles behind
 * 9.2.0328: Cannot handle mouseclicks in the statusline
 * 9.2.0327: filetype: uv scripts are not detected
 * 9.2.0326: runtime(tar): but with dotted path
 * 9.2.0325: runtime(tar): bug in zstd handling
 * 9.2.0324: 0x9b byte not unescaped in <Cmd> mapping
 * 9.2.0323: filetype: buf.lock files are not recognized
 * 9.2.0322: tests: test_popupwin fails
 * 9.2.0321: MS-Windows: No OpenType font support
 * 9.2.0320: several bugs with text properties
 * 9.2.0319: popup: rendering issues with partially transparent popups
 * 9.2.0318: cannot configure opacity for popup menu
 * 9.2.0317: listener functions do not check secure flag
 * 9.2.0316: [security]: command injection in netbeans interface via defineAnnoType
 * 9.2.0315: missing bound-checks
 * 9.2.0314: channel: can bind to all network interfaces
 * 9.2.0313: Callback channel not registered in GUI
 * 9.2.0312: C-type names are marked as translatable
 * 9.2.0311: redrawing logic with text properties can be improved
 * 9.2.0310: unnecessary work in vim_strchr() and find_term_bykeys()
 * 9.2.0309: Missing out-of-memory check to may_get_cmd_block()
 * 9.2.0308: Error message E1547 is wrong
 * 9.2.0307: more mismatches between return types and documentation
 * 9.2.0306: runtime(tar): some issues with lz4 support
 * 9.2.0305: mismatch between return types and documentation
 * 9.2.0304: tests: test for 9.2.0285 doesn't always fail without the fix
 * 9.2.0303: tests: zip plugin tests don't check for warning message properly
 * 9.2.0302: runtime(netrw): RFC2396 decoding double escaping spaces
 * 9.2.0301: Vim9: void function return value inconsistent
 * 9.2.0300: The vimball plugin needs some love
 * 9.2.0299: runtime(zip): may write using absolute paths
 * 9.2.0298: Some internal variables are not modified
 * 9.2.0297: libvterm: can improve CSI overflow code
 * 9.2.0296: Redundant and incorrect integer pointer casts in drawline.c
 * 9.2.0295: 'showcmd' shows wrong Visual block size with 'linebreak'
 * 9.2.0294: if_lua: lua interface does not work with lua 5.5
 * 9.2.0293: :packadd may lead to heap-buffer-overflow
 * 9.2.0292: E340 internal error when using method call on void value
 * 9.2.0291: too many strlen() calls
 * 9.2.0290: Amiga: no support for AmigaOS 3.x
 * 9.2.0289: 'linebreak' may lead to wrong Visual block highlighting
 * 9.2.0288: libvterm: signed integer overflow parsing long CSI args
 * 9.2.0287: filetype: not all ObjectScript routines are recognized
 * 9.2.0286: still some unnecessary (int) casts in alloc()
 * 9.2.0285: :syn sync grouphere may go beyond end of line
 * 9.2.0284: tabpanel: crash when tabpanel expression returns variable line count
 * 9.2.0283: unnecessary (int) casts before alloc() calls
 * 9.2.0282: tests: Test_viminfo_len_overflow() fails
 * 9.2.0281: tests: Test_netrw_FileUrlEdit.. fails on Windows

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2038-1
Released:    Thu May 21 15:33:31 2026
Summary:     Security update for rsync
Type:        security
Severity:    important
References:  1234100,1234101,1234102,1234103,1234104,1235475,1254441,1262223,1264511,1264512,1264513,1264514,1264515,1265296,CVE-2024-12084,CVE-2024-12085,CVE-2024-12086,CVE-2024-12087,CVE-2024-12088,CVE-2024-12747,CVE-2025-10158,CVE-2026-29518,CVE-2026-41035,CVE-2026-43617,CVE-2026-43618,CVE-2026-43619,CVE-2026-43620,CVE-2026-45232
This update for rsync fixes the following issues

    
- CVE-2026-29518: Symlink-Race TOCTOU in Daemon (bsc#1264511).
- CVE-2026-41035: Count of entries mismatch can lead to a use-after-free (bsc#1262223)
- CVE-2026-43617: Authorization Bypass via Hostname Resolution (bsc#1264515).
- CVE-2026-43618: Integer Overflow Information Disclosure (bsc#1264512).
- CVE-2026-43619: Symlink Race Condition via Path-Based Syscalls (bsc#1264514).
- CVE-2026-43620: Out-of-Bounds Array Read via recv_files() (bsc#1264513).
- CVE-2026-45232: Off-by-one stack OOB write in HTTP CONNECT proxy response parsing (bsc#1265296).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2041-1
Released:    Thu May 21 16:29:18 2026
Summary:     Recommended update for openssl-1_1
Type:        recommended
Severity:    moderate
References:  1250782
This update for openssl-1_1 fixes the following issues:

- Fix 30-test_fips_sli.t fails intermittently on s390x (bsc#1250782):
    * Fix AES_GCM IV test sometimes failing on s390x.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2051-1
Released:    Mon May 25 15:59:43 2026
Summary:     Security update for xz
Type:        security
Severity:    important
References:  1261280,CVE-2026-34743
This update for xz fixes the following issue

- CVE-2026-34743: buffer overflow in lzma_index_append() (bsc#1261280).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2076-1
Released:    Tue May 26 14:36:41 2026
Summary:     Security update for samba
Type:        security
Severity:    critical
References:  1255755,1257200,1259441,1261158,1261159,1261160,1261161,1261163,1261188,CVE-2026-1933,CVE-2026-2340,CVE-2026-3012,CVE-2026-3238,CVE-2026-4408,CVE-2026-4480
This update for samba fixes the following issues

Security issues:

- CVE-2026-1933: Missing access check on reparse point operations (bsc#1261188).
- CVE-2026-2340: vfs_worm does not block directory modification (bsc#1261158).
- CVE-2026-3012: group policy certificate enrollment uses http: // without validation (bsc#1261159).
- CVE-2026-3238: unauthenticated udp packet crashes AD DC nbt server (bsc#1261160).
- CVE-2026-4408: Remote Code Execution in SAMR (bsc#1261163).
- CVE-2026-4480: Unauthenticated Remote Code Execution (bsc#1261161).

Non security issue:

- network:samba:STABLE/samba: 'use-kerberos=desired' broken / Dolphin requires login for Samba shares (bsc#1255755).
- Generated dynamic profile based on path to special 'printers' share. (bsc#1259441).
- Fix regression 'use-kerberos=desired' broken doesn't even try to authenticate with kerberos and instead fallsback 
to NTLM (bsc#1255755).
- Fix memory leak using cups parsed options and filename allocated when processing end of printing job (bsc#1257200).
- Fix manpage for 'net offlinejoin requestodj'.
- Fix 'ctdbd socket' documentation in manpage for smb.conf
- Fix rpc workers with long living clients from growing server
 memory keytab and increasing memory used by workers (bsc#1257200).


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2104-1
Released:    Thu May 28 16:02:52 2026
Summary:     Security update for apache2
Type:        security
Severity:    important
References:  1263935,1263950,1263951,1263952,1263953,1263954,1263955,1263956,1263957,1264150,1264163,CVE-2026-23918,CVE-2026-24072,CVE-2026-28780,CVE-2026-29168,CVE-2026-29169,CVE-2026-33006,CVE-2026-33007,CVE-2026-33523,CVE-2026-33857,CVE-2026-34032,CVE-2026-34059
This update for apache2 fixes the following issues

- CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957).
- CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935).
- CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163).
- CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150).
- CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956).
- CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).
- CVE-2026-33007: NULL pointer dereference in `mod_authn_socache` allows unauthenticated remote user to crash a child
  processes (bsc#1263954).
- CVE-2026-33523: HTTP response splitting forwarding malicious status line (bsc#1263953).
- CVE-2026-33857: off-by-one OOB reads in AJP getter functions (bsc#1263952).
- CVE-2026-34032: heap buffer overread in `mod_proxy_ajp` due to missing null-termination check (bsc#1263951).
- CVE-2026-34059: heap buffer overread and memory disclosure via `ajp_parse_data()` (bsc#1263950).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2115-1
Released:    Fri May 29 17:27:13 2026
Summary:     Security update for gnutls
Type:        security
Severity:    important
References:  1263704,1263705,1263707,1263708,1263709,1263710,1263711,1263712,1263713,1263714,1263715,1263716,CVE-2026-33845,CVE-2026-33846,CVE-2026-3833,CVE-2026-42009,CVE-2026-42010,CVE-2026-42011,CVE-2026-42012,CVE-2026-42013,CVE-2026-42014,CVE-2026-42015,CVE-2026-5260,CVE-2026-5419
This update for gnutls fixes the following issues

- CVE-2026-3833: x509/name-constraints: compare domain names case-insensitive (bsc#1263707).
- CVE-2026-5260: lib/pkcs11_privkey: guard against overreading on short ciphertexts (bsc#1263715).
- CVE-2026-5419: gnutls_cipher_decrypt3: make PKCS#7 unpadding branch free (bsc#1263716).
- CVE-2026-33845: buffers: switch from end_offset over to frag_length (bsc#1263704).
- CVE-2026-33846: buffers: add more checks to DTLS reassembly (bsc#1263705).
- CVE-2026-42009: lib/buffers: ensure packets have differing sequence numbers (bsc#1263708).
- CVE-2026-42010: lib/auth/rsa_psk: fix binary PSK identity lookup (bsc#1263709).
- CVE-2026-42011: x509/name_constraints: fix intersecting empty constraints (bsc#1263710).
- CVE-2026-42012: x509/hostname-verify: make URI/SRV SAN preclude CN fallback (bsc#1263711).
- CVE-2026-42013: x509: prevent fallback on oversized SAN (bsc#1263712).
- CVE-2026-42014: pkcs11_write: fix UAF and leak in gnutls_pkcs11_token_set_pin (bsc#1263713).
- CVE-2026-42015: x509/pkcs12_bag: fix off-by-one in bag element bounds chec (bsc#1263714).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2119-1
Released:    Fri May 29 17:33:15 2026
Summary:     Security update for python-urllib3
Type:        security
Severity:    important
References:  1265267,CVE-2026-44431
This update for python-urllib3 fixes the following issue

- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied
  low-level redirects (bsc#1265267).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2231-1
Released:    Wed Jun  3 12:57:18 2026
Summary:     Security update for glibc
Type:        security
Severity:    important
References:  1261206,1262464,1262465,CVE-2026-4046,CVE-2026-5450,CVE-2026-5928
This update for glibc fixes the following issues

- CVE-2026-4046: assertion failure when converting inputs may be used to remotely crash an application (bsc#1261206).
- CVE-2026-5450: stdio-common: scanf %mc pattern will cause heap overflow when width > 1024 (bsc#1262465).
- CVE-2026-5928: libio: ungetwc could be used to leak data on special conditions (bsc#1262464).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2236-1
Released:    Wed Jun  3 13:00:40 2026
Summary:     Security update for vim
Type:        security
Severity:    important
References:  1262395,1264706,1264707,1264708,1265349,1265360,CVE-2026-42307,CVE-2026-43961,CVE-2026-44656,CVE-2026-45130,CVE-2026-46483
This update for vim fixes the following issues

- CVE-2026-42307: Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin
  bundled with Vim (bsc#1264706).
- CVE-2026-43961: Vimscript Code Injection in netrw NetrwMarkFile() via crafted filename (bsc#1265349).
- CVE-2026-44656: Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's: find command-line
  completion (bsc#1264707).
- CVE-2026-45130: Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when
  loading a crafted spell file (.spl) with UTF-8 encoding active (bsc#1264708).
- CVE-2026-46483: command injection via ` tar#Vimuntar()` in `runtime/autoload/tar.vim` when decompressing `.tgz`
  archives on Unix-like systems (bsc#1265360).

Changes for vim:

- Update to v9.2.0530.
- Fix for incorrectly detecting scientific parameter files as bitbake recipies. (bsc#1262395)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2243-1
Released:    Wed Jun  3 16:09:25 2026
Summary:     Security update 5.0.8 for Multi-Linux Manager Client Tools
Type:        security
Severity:    important
References:  1248699,1248707,1252964,1254619,1257941,1258595,1258873,1258893,1258927,1259208,1259999,1260263,1260267,1260878,1260881,1261025,1261026,1261027,1261029,1261810,1262222,1262950,1263501,1263986,1263987,CVE-2022-21698,CVE-2025-29923,CVE-2026-21724,CVE-2026-21725,CVE-2026-26958,CVE-2026-27606,CVE-2026-27876,CVE-2026-27877,CVE-2026-27879,CVE-2026-28375,CVE-2026-33186,CVE-2026-33375,CVE-2026-34986,CVE-2026-40179,CVE-2026-41602,CVE-2026-42151,CVE-2026-42154
This update fixes the following issues:

golang-github-QubitProducts-exporter_exporter:

- Security Fixes:

  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248707)

golang-github-prometheus-node_exporter:

- Backward Compatibility and packaging changes:
  - Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains
  - Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility

- Version 1.10.2:
  - Fixed typo in Zswap metric name (meminfo)

- Version 1.10.1:
  - Fixed mount points being collected multiple times (filesystem)
  - Refactored mountinfo parsing (bsc#1261810)
  - Added Zswap/Zswapped metrics (meminfo)

- Version 1.10.0:
  - New collectors: PCIe devices, swaps
  - Added systemd virtualization metrics, AIX metrics
  - WiFi packet metrics, additional PCIe and TLB metrics
  - Changed mdadm to use sysfs, added erofs to excluded filesystems
  - Fixed bugs: cpufreq collector, ethtool metrics

golang-github-prometheus-prometheus:
    
- Security issues fixed:

  - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret
    being exposed in plaintext via /-/config endpoint (bsc#1263986)
  - CVE-2026-42154: Remote-read: Reject snappy-compressed requests
    whose declared decoded length exceeds the decode limit
    (bsc#1263987).
  - CVE-2026-40179: UI: Fixed stored XSS via unescaped le label
    values in old UI heatmap chart tick labels (bsc#1262222)
  - CVE-2026-33186: Fixed authorization bypass due to improper
    validation of the HTTP/2 :path pseudo-header (bsc#1260267)
    * Bump google.golang.org/grpc to version 1.79.3
  - CVE-2026-27606: Fixed arbitrary file write via path traversal in
    rollup (bsc#1258893)
    * Bump rollup to version 4.59.0

- Other changes:

  - Remote-Write: Reject snappy-compressed requests whose
    declared decoded length exceeds the decode limit.
  - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816)  


prometheus-postgres_exporter:

- Security Fixes:

  - CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode
    limit (bsc#1263987)
  - CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint
    (bsc#1263986)
  - CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699)

- Highlights of other changes and bug fixes:

  - Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy

grafana was updated from version 11.6.11 to 11.6.14+security01:

- Security Fixes:

  - CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950)
  - CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501)
  - CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results 
    (bsc#1258595)
  - CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873)
  - CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881)
  - CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)
  - CVE-2026-27877: Fixed information disclosure of data-source passwords via public dashboards (bsc#1261026)
  - CVE-2026-28375: Fixed denial of service via testdata data-source (bsc#1261029)
  - CVE-2026-27879: Fixed denial of service via resample query (bsc#1261027)
  - CVE-2026-33186: Fixed authorization bypass due to improper validation of the HTTP/2 :path pseudo-header
    (bsc#1260263)
  - CVE-2026-21724: Fixed authorization bypass allows modification of protected webhook URLs (bsc#1260878)

- Highlights of other changes and bug fixes:

  - Version 11.6.13:

    - Wire the public dashboard service to the HTTP server

  - Version 11.6.12:

    - Update authentication redirect logic
    - Fixed single panel render with variable references

spacecmd:

- Version 5.0.16-0:

  - Update translation strings

uyuni-tools:

- Version 0.1.39-0:

  - mgrpxy ssh tuning should happen before crypto policies (bsc#1254619)
  - Fixed default value for helm registry (bsc#1258927).
  - Use static supportconfig name to avoid dynamic search
    (bsc#1257941)
  - Do not nest multiple tarball files and instead collect
    all files into one tarball (bsc#1252964)
  - Show where final tarball was generated (bsc#1259208)


-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2259-1
Released:    Wed Jun  3 17:31:35 2026
Summary:     Security update for python3-pyOpenSSL
Type:        security
Severity:    moderate
References:  1262803,CVE-2026-40475
This update for python3-pyOpenSSL fixes the following issue

- CVE-2026-40475: improper input handling of null bytes can lead to silent data truncation and security-state
  inconsistency (bsc#1262803).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2261-1
Released:    Wed Jun  3 17:32:08 2026
Summary:     Security update for python-pyOpenSSL
Type:        security
Severity:    moderate
References:  1262803,CVE-2026-40475
This update for python-pyOpenSSL fixes the following issue



-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2276-1
Released:    Fri Jun  5 10:56:23 2026
Summary:     Recommended update for apparmor
Type:        recommended
Severity:    important
References:  1265620
This update for apparmor fixes the following issues:

- Allow execution of /usr/bin/zstd (bsc#1265620)

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2278-1
Released:    Fri Jun  5 11:00:12 2026
Summary:     Recommended update for timezone
Type:        recommended
Severity:    important
References:  1264965
This update for timezone fixes the following issues:

- Update to 2026b:
    * British Columbia moved to permanent -07 on 2026-03-09. (bsc#1264965)
    * Some more overflow bugs have been fixed in zic.
- Update to 2026a:
    * Moldova has used EU transition times since 2022.
    * The 'right' TZif files are no longer installed by default.
    * -DTZ_RUNTIME_LEAPS=0 disables runtime support for leap seconds.
    * TZif files are no longer limited to 50 bytes of abbreviations.
    * zic is no longer limited to 50 leap seconds.
    * Several integer overflow bugs have been fixed.
- Update to 2025c:
    * Update Baja California DST rules in 1953, 1961-1975
    * An unset TZ is no longer invalid when /etc/localtime is
      missing, and is abbreviated 'UTC' not '-00'. This reverts to 2024b behavior
    * tzset etc. are now more cautious about questionable TZ settings.
    * tzset etc. now treat ' ' like '_' in time zone abbreviations
    * tzfree now preserves errno, consistently with POSIX.1-2024 'free'.
    * zic has new options inspired by FreeBSD.
    * multiple changes visible to developers
- Use 'REDO=posix_right' to keep installing 'right' TZif files.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2297-1
Released:    Mon Jun  8 12:16:51 2026
Summary:     Security update for avahi
Type:        security
Severity:    moderate
References:  1261546,CVE-2026-34933
This update for avahi fixes the following issue:

- CVE-2026-34933: Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus
  method call with conflicting publish flags (bsc#1261546).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2298-1
Released:    Mon Jun  8 12:17:11 2026
Summary:     Security update for python311
Type:        security
Severity:    moderate
References:  1258364,1261970,CVE-2026-3446
This update for python311 fixes the following issues:

- CVE-2026-3446: Base64 decoding stops at first padded quad by default (bsc#1261970).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2308-1
Released:    Tue Jun  9 10:13:09 2026
Summary:     Security update for netty, netty-tcnative
Type:        security
Severity:    important
References:  1264350,1265243,1265245,1265246,1265272,1265273,1265277,1265279,1265280,1265292,1265294,1265318,CVE-2026-41417,CVE-2026-42578,CVE-2026-42579,CVE-2026-42580,CVE-2026-42581,CVE-2026-42582,CVE-2026-42583,CVE-2026-42584,CVE-2026-42585,CVE-2026-42586,CVE-2026-42587,CVE-2026-44248
This update for netty, netty-tcnative fixes the following issues

- CVE-2026-41417: missing validations leads to HTTP request smuggling and RTSP request injection via start-line
  injection in `DefaultHttpRequest.setUri()` (bsc#1264350).
- CVE-2026-42578: HTTP Header Injection via HttpProxyHandler Disabled Validation in Netty (bsc#1265243).
- CVE-2026-42579: DNS codec does not enforce RFC 1035 domain name constraints during either encoding or decoding
  (bsc#1265272).
- CVE-2026-42580: chunk size parser silently overflows int and enables request smuggling attacks (bsc#1265273).
- CVE-2026-42581: TE+CL header coexistence in HTTP/1.0 requests bypasses smuggling sanitization (bsc#1265277).
- CVE-2026-42583: resource exhaustion and possible denial of service via `Lz4FrameDecoder` (bsc#1265279).
- CVE-2026-42584: improper handling of inbound responses in `HttpClientCodec` can lead to response desynchronization
  (bsc#1265280).
- CVE-2026-42585: Netty is an asynchronous, event-driven network application framework (bsc#1265292).
- CVE-2026-42586: CRLF Injection in Netty Redis Codec Encoder (bsc#1265245).
- CVE-2026-42587: HttpContentDecompressor maxAllocation bypass via Content-Encoding: br/zstd/snappy enables
  decompression bomb DoS (bsc#1265246).
- CVE-2026-44248: Netty is an asynchronous, event-driven network application framework (bsc#1265294).
- CVE-2026-42582: HTTP/3 QPACK literal unbounded allocation (bsc#1265318). 

Changes for netty:

- Upgrade to upstream version 4.1.133

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2324-1
Released:    Tue Jun  9 16:33:09 2026
Summary:     Security update for perl-XML-LibXML
Type:        security
Severity:    important
References:  1264715,CVE-2026-8177
This update for perl-XML-LibXML fixes the following issue

- CVE-2026-8177: read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
  (bsc#1264715).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2371-1
Released:    Thu Jun 11 16:01:35 2026
Summary:     Security update for openssh
Type:        security
Severity:    important
References:  1259642,1261427,1261430,1261441,1264568,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414
This update for openssh fixes the following issues

- CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642).
- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
- CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441).
- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).
- potential security issue when validating mac (bsc#1264568).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2384-1
Released:    Fri Jun 12 11:33:40 2026
Summary:     Recommended update for python-typing_extensions
Type:        recommended
Severity:    moderate
References:  

This update for python-typing_extensions fixes the following issues:

Update to 4.12.2:

  * Fix regression in v4.12.0 where specialization of certain
  * generics with an overridden `__eq__` method would raise
    errors.
  * Fix tests so they pass on 3.13.0b2
  * Preliminary changes for compatibility with the draft
    implementation of PEP 649 in Python 3.14.
  * Fix regression in v4.12.0 where nested `Annotated` types
    would cause `TypeError` to be raised if the nested
    `Annotated` type had unhashable metadata.
  * Fix incorrect behaviour of `typing_extensions.ParamSpec` on
    Python 3.8 and 3.9 that meant that
    `isinstance(typing_extensions.ParamSpec('P'),
    typing.TypeVar)` would have a different result in some
    situations depending on whether or not a profiling
    function had been set using `sys.setprofile`.
  * This release focuses on compatibility with the upcoming
    release of Python 3.13. Most changes are related to the
    implementation of type parameter defaults (PEP 696).

Update to 4.11.0:

  * Fix tests on Python 3.13.0a5. Patch by Jelle Zijlstra.
  * Fix the runtime behavior of type parameters with defaults
  * Fix minor discrepancy between error messages produced by
    `typing` and `typing_extensions` on Python 3.10.
  * When `include_extra=False`, `get_type_hints()` now strips
    `ReadOnly` from the annotation.

Update to 4.10.0:

  This feature release adds support for PEP 728 (TypedDict with extra
  items) and PEP 742 (``TypeIs``).

  - Add support for PEP 728, supporting the `closed` keyword argument and the
    special `__extra_items__` key for TypedDict. Patch by Zixuan James Li.
  - Add support for PEP 742, adding `typing_extensions.TypeIs`. Patch
    by Jelle Zijlstra.
  - Drop runtime error when a read-only `TypedDict` item overrides a mutable
    one. Type checkers should still flag this as an error. Patch by Jelle
    Zijlstra.
  - Speedup `issubclass()` checks against simple runtime-checkable protocols by
    around 6% (backporting https://github.com/python/cpython/pull/112717, by Alex
    Waygood).
  - Fix a regression in the implementation of protocols where `typing.Protocol`
    classes that were not marked as `@runtime_checkable` would be unnecessarily
    introspected, potentially causing exceptions to be raised if the protocol had
    problematic members. Patch by Alex Waygood, backporting
    https://github.com/python/cpython/pull/113401.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2392-1
Released:    Mon Jun 15 10:05:31 2026
Summary:     Security update for openssl-1_1
Type:        security
Severity:    important
References:  1250782,1266340,1266341,1266342,1266349,1266357,CVE-2026-34180,CVE-2026-42766,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076
This update for openssl-1_1 fixes the following issues

- CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
- CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
- CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
- CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
- CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2425-1
Released:    Wed Jun 17 08:48:32 2026
Summary:     Recommended update for iproute2
Type:        recommended
Severity:    important
References:  1255752
This update for iproute2 fixes the following issues:

- add DPLL support (bsc#1255752 jsc#PED-14083):
    * dpll: add dpll command
    * dpll: fix missing notifications in monitor mode
    * dpll: send object per event in JSON monitor mode
    * dpll: add client side filtering for device and pin show
    * dpll: add direction and state filtering for pin show
    * dpll: add mode setting support
    * dpll: add pin filtering by parent device
    * dpll: add support for fractional frequency offset
    * dpll: fix pin id get type filter parsing
    * lib: add string to boolean helper function
    * lib: move mnlg to lib for shared use
    * sync UAPI header copies with SL-16.0

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2434-1
Released:    Wed Jun 17 16:40:10 2026
Summary:     Recommended update for coreutils
Type:        recommended
Severity:    important
References:  1259327
This update for coreutils fixes the following issues:

- proc: Use affinity mask even on systems with more than 1024 CPUs (bsc#1259327)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2442-1
Released:    Thu Jun 18 09:23:36 2026
Summary:     Security update for perl-HTTP-Daemon
Type:        security
Severity:    important
References:  1266370,CVE-2026-8450
This update for perl-HTTP-Daemon fixes the following issues:

- CVE-2026-8450: Fixed OS command injection via send_file() (bsc#1266370).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2485-1
Released:    Mon Jun 22 14:06:22 2026
Summary:     Security update for util-linux
Type:        security
Severity:    moderate
References:  1261606,CVE-2026-27456
This update for util-linux fixes the following issue

- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2486-1
Released:    Mon Jun 22 14:07:07 2026
Summary:     Security update for python-urllib3
Type:        security
Severity:    important
References:  1265267,CVE-2026-44431
This update for python-urllib3 fixes the following issue

- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied
  low-level redirects (bsc#1265267).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2490-1
Released:    Mon Jun 22 14:34:14 2026
Summary:     Security update for libarchive
Type:        security
Severity:    important
References:  1253088,1259635,1259928,1259931,1261186,CVE-2025-60753,CVE-2026-4111,CVE-2026-4424,CVE-2026-4426,CVE-2026-5121
This update for libarchive fixes the following issues

- CVE-2025-60753: bsdtar hangs and OOMs with zero-length pattern matches (bsc#1253088).
- CVE-2026-4111: logical deadlock the RAR5 filter subsystem and the half-window output limiter leads to infinite loop
  and DoS (bsc#1259635).
- CVE-2026-4424: information disclosure via heap out-of-bounds read in RAR archive processing (bsc#1259928).
- CVE-2026-4426: undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code
  (bsc#1259931).
- CVE-2026-5121: arbitrary code execution via integer overflow in ISO9660 image processing (bsc#1261186).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2528-1
Released:    Tue Jun 23 11:06:07 2026
Summary:     Security update for sqlite3
Type:        security
Severity:    important
References:  1268012,1268013,CVE-2026-11822,CVE-2026-11824
This update for sqlite3 fixes the following issues

Update to 3.53.2:

- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause
  process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).
- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers
  to cause a crash or execute arbitrary code (bsc#1268013).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2531-1
Released:    Tue Jun 23 12:25:09 2026
Summary:     Security update for libsolv, libzypp, zypper
Type:        security
Severity:    important
References:  1158038,1239718,1246504,1247948,1249435,1252744,1253193,1253740,1257068,1257882,1258193,1259311,1259706,1259802,1259842,1265223,1265935,1265938,1266039,1267426,1267874,CVE-2026-25707,CVE-2026-44933,CVE-2026-44941,CVE-2026-44942,CVE-2026-48863,CVE-2026-9149,CVE-2026-9150
This update for libsolv, libzypp, zypper fixes the following issues

- CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
  (bsc#1265935).
- CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums
  (bsc#1265938).
- CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802).
- CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223).
- CVE-2026-44941: path traversal via 'keyhint' (bsc#1267426).
- CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874).
- CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature (bsc#1266039).

Changes in libzypp:

Updated to version 17.38.13 (35):

- A .repo files 'path=' entry must not refer to a location
  outside the repo (bsc#1267874, CVE-2026-44942)
  A 'path=' entry may solely denote a sub-directory of the baseurl
  where the metadata are located. A relative path trying to access
  data outside the baseurl is reported and sanitized.
- Fix potential crash on malformed or malicious repository
  metadata (fixes #740)
- Repo metadata: discard entries referring to a location outside
  the repo (bsc#1259802, CVE-2026-25707)
  Mirroring those data locally would refer to a location outside
  the repo's local cache directory. Those data entries are reported
  and discarded.
- zypp.conf: Allow [env] section to add environment variables.
  This feature is designed to enable environment-specific settings
  or debugging options over an extended period. See zypp.conf(5).
- Prevent configured scripts from escaping the sigcheck directory
  (bsc#1265223, CVE-2026-44933)
- StringV: guard hasPrefix/hasPrefixCI against reading past the
  view end (fixes #735)
- Mandatory signature verification plugin support (PED#11922)
- Fix purge-kernel -rc kernel handling (bsc#1239718)
- Explicitly_set_pool_DISTTYPE_RPM (fixes #726)
- Check for trusted key updates when updating the general keyring
  (bsc#1259706)
- Support multiple MirroredOrigin authorities (bsc#1253193)
- Workaround doxygen bug: doxygen/doxygen#12057
- libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)
- Fix preloader not caching packages from arch specific subrepos
  (bsc#1253740)
- Deprioritize invalid mirrors (fixes openSUSE/zypper#636)
- Fix Product::referencePackage lookup (bsc#1259311)
  Use a provided autoproduct() as hint to the package name of the
  release package. It might be that not just multiple versions of
  the same release package provide the same product version, but
  also different release packages.
- specfile: on fedora use %{_prefix}/share as zyppconfdir if
  %{_distconfdir} is undefined (fixes #693)
  This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake.
- Fall back to a writable location when precaching packages
  without root (bsc#1247948)
- Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.
  See the ZYPP.CONF(5) man page for details.
- Fix runtime check for broken rpm --runposttrans (bsc#1257068)
- Avoid libcurl-mini4 when building as it does not support ftp
  protocol.
- Translation: updated .pot file.
- zypp.conf: follow the UAPI configuration file specification
  (PED-14658)
  In short terms it means we will no longer ship an
  /etc/zypp/zypp.conf, but store our own defaults in
  /usr/etc/zypp/zypp.conf. The systems administrator may choose to
  keep a full copy in /etc/zypp/zypp.conf ignoring our config file
  settings completely, or - the preferred way - to overwrite
  specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files.
  See the ZYPP.CONF(5) man page for details.
- cmake: correctly detect rpm6 (fixes #689)
- Use 'zypp.tmp' as temp directory component to ease setting up
  SELinux policies (bsc#1249435)
- zyppng: Update Provider to current MediaCurl2 download
  approach, drop Metalink ( fixes #682 )

Changes in libsolv:

Updated to version 0.7.39:

- fix solv_chksum_free segfault when called with a NULL pointer
- made repo_add_solv more robust against corrupt files
  [bsc#1265935] [CVE-2026-9149]
- fix potential buffer overflow when verifying EdDSA signatures
  [bsc#1266039] [CVE-2026-48863]
- added limit checks in multiple places to catch overflows
- reduce the size of the language id cache
- fixed Debian canon selection
- fixed dbpath detection in repo_rpmdb_librpm
- reduced stack usage in repo page compression (needed for musl)
- fix parsing of sha512 checksums in debian repositories
  [bsc#1265938] [CVE-2026-9150]
- improve speed of dirpool_add_dir makeing parsing of filelists.xml
  twice as fast
- fix parsing of recommends in the old Mandriva synthesis format
- respect the 'default' attribute in environment optionlist in
  the comps parser
- support suse namespace deps in boolean dependencies [bsc#1258193]
- support for the Elbrus2000 (e2k) architecture
- support language() suse namespace rewriting

Changes in zypper:

Update to version 1.14.98:

- Transactional systems: Delegate rw-commands to
  transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607)
  On a transactional system where the root filesystem is mounted
  read-only, zypper commands that modify the system cannot be
  executed directly.
  If the system provides a transactional-wrapper utility, zypper
  will automatically attempt to invoke it. The wrapper
  transparently executes the zypper command within a new, writable
  snapshot and manages the lifecycle of that snapshot based on the
  command's exit status.
  On transactional systems lacking a transactional-wrapper, users
  must manually invoke specialized tools -such as
  transactional-update- to install, update, or remove software.
- Add --filter-version-change to zypper lu.
  Adds filtering by version change significance to reduce noise in
  update listings. Supports levels: rebuild (hides rebuild-only
  changes) and package (hides all release-only changes).
- Autorefresh ris-services the way as plugin-services (bsc#1246504)
  It's actually wrong to treat service refreshes different
  depending on the service type. For the purpose of a service it
  makes no difference how the data about the repos to use are
  acquired.
- Report download progress for command line rpms (fixes #613)
- Hint to '-vv ref' to see the mirrors used to download the
  metadata (bsc#1257882)
- Service: Allow 'zypper ls SERVICE ...' to test whether a
  service with this alias is defined (bsc#1252744)
  The command prints an abstract of all services passed on the
  command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some
  argument does not name an existing service.
- Keep repo data when updating the service settings (bsc#1252744)
- info: Enhance pattern content table (bsc#1158038)
  Alternatives (multiple packages providing the same requirement)
  are now listed as a single entry in the content table. The entry
  shows either the installed package which satisfies the
  requirement or the requirement itself as type 'Provides'.
  Listing all potential alternatives was miss leading, especially
  if the alternatives were mutual exclusive. It looked like an
  installed pattern had not-installed requirements and it was not
  possible to install all requirements at the same time.

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2627-1
Released:    Thu Jun 25 10:12:38 2026
Summary:     Security update for python-PyJWT
Type:        security
Severity:    important
References:  1266798,1266799,1266801,1266802,CVE-2026-48522,CVE-2026-48523,CVE-2026-48525,CVE-2026-48526
This update for python-PyJWT fixes the following issues

- CVE-2026-48522: `PyJWKClient` passes URI arguments directly to `urllib.request.urlopen()` and allows for SSRF and
  token forgery (bsc#1266798).
- CVE-2026-48523: verifier-side algorithm allow-list bypass when `jwt.decode()` or `jwt.decode_complete()` are called
  with a PyJWK key (bsc#1266799).
- CVE-2026-48525: unbounded Base64URL decoding of unused payload segment in `b64=false` detached JWS allows for DoS
  (bsc#1266801).
- CVE-2026-48526: no validation of use of JSON Web Keys in HMAC algorithm when decoding JSON Web Tokens allows for
  forged HS256 tokens (bsc#1266802).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2637-1
Released:    Thu Jun 25 17:42:10 2026
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  
This update for mozilla-nss fixes the following issues:

Update to NSS 3.112.5:

* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max.
* update to version 2.84 of builtins module.

- Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2642-1
Released:    Fri Jun 26 09:59:08 2026
Summary:     Security update for apache-commons-configuration2, apache-commons-text
Type:        security
Severity:    important
References:  1265299,CVE-2026-45205
This update for apache-commons-configuration2, apache-commons-text fixes the following issues

- CVE-2026-45205: uncontrolled recursion leads to `StackOverflowError` when processing specially crafted configuration
  files (bsc#1265299).

Changes for apache-commons-configuration2:
  
- Upgrade to version 2.15.0:
 + Disable include schemes http[s] by default, see
 AbstractFileLocationStrategy
 + Detect and avoid processing cycles in YAML input
 (YAMLConfiguration) (bsc#1265299, CVE-2026-45205)
 + Extend scheme validation to inner schemes of jar: URLs
 + Add XMLConfiguration.read(Element)
 + Add ConfigurationException.ConfigurationException(String,
 Object...)
 + Add ConfigurationException.ConfigurationException(Throwable,
 String, Object...)
 + Add ConversionException.ConversionException(String, Object...)
 + Add ConversionException.ConversionException(Throwable, String,
 + Add ConfigurationRuntimeException
 .ConfigurationRuntimeException(Throwable, String, Object...)
 * Fixed Bugs
 + Fix Apache RAT plugin console warnings
 + Migrate from deprecated APIs
 + Add org.apache.commons.configuration2.ImmutableConfiguration
 .entrySet()
 .forEach(BiConsumer<String, Object>)
 + Add VEX entry for CVE-2025-48924
 + Shared primitive variable 'throwExceptionOnMissing' in one
 thread may not yield the value of the most recent write from
 another thread [org.apache.commons.configuration2
 .AbstractConfiguration] At AbstractConfiguration.java:
 [line 1493] AT_STALE_THREAD_WRITE_OF_PRIMITIVE
 + Shared primitive variable 'forceSingleLine' in one thread may
 not yield the value of the most recent write from another
 thread [org.apache.commons.configuration2
 .PropertiesConfigurationLayout]
 At PropertiesConfigurationLayout.java:[line 821]
 AT_STALE_THREAD_WRITE_OF_PRIMITIVE
 + CONFIGURATION-849: Fix undoubling of strings
 + CONFIGURATION-852: Mark the package jakarta.servlet.* import
 as optional in OSGi
 + Fix build [WARNING] Parameter 'forkMode' is unknown for plugin
 'maven-surefire-plugin:3.5.3:test (default-test)'
 * New features:
 + Add PrefixedKeysIterator.toString() to package-private
 PrefixedKeysIterator
 + CONFIGURATION-836: New web configurations using the
 jakarta.servlet namespace are now available
 + CONFIGURATION-836: Add org.apache.commons.configuration2.web
 .JakartaServletConfiguration
 .JakartaServletContextConfiguration
 .JakartaServletFilterConfiguration
 .JakartaServletRequestConfiguration
 + Add org.apache.commons.configuration2
 .AbstractHierarchicalConfiguration.getKeysInternal(String,
 String)
 * Fixed Bugs:
 + PropertyConverter.to(Class, Object, DefaultConversionHandler)
 doesn't convert custom java.lang.Number subclasses
 + DefaultConversionHandler.convertValue(Object, Class,
 ConfigurationInterpolator) doesn't convert custom java.lang
 .Number subclasses
 + DefaultConversionHandler.to(Object, Class,
 + CONFIGURATION-848: SubsetConfiguration does not account for
 delimiters as it did in 2.9.0
 + CONFIGURATION-848: CompositeConfiguration does not account for
 + Describe the security model
 + De-emphasize the 1.x version line on the website
 + CONFIGURATION-851: HomeDirectoryLocationStrategy no longer
 resolves the user HOME directory correctly
 + CONFIGURATION-844: Add support for empty sections
 + Add ImmutableConfiguration.containsValue(Object)
 + Fail-fast with a NullPointerException if DataConfiguration
 .DataConfiguration(Configuration) is called with null
 + Fail-fast with a NullPointerException if
 XMLPropertiesConfiguration.XMLPropertiesConfiguration(Element)
 is called with null
 + Fail-fast with a NullPointerException if a SubsetConfiguration
 constructor is called with a null Configuration
 + CONFIGURATION-843: Methods should not be empty
 + Guard MapConfiguration against null maps
 AppletConfiguration(Applet) is called with null
 ServletConfiguration(Servlet) is called with null
 ServletConfiguration(ServletConfig) is called with null
 ServletContextConfiguration(Servlet) is called with null
 ServletContextConfiguration(ServletContext) is called with null
 ServletFilterConfiguration(FilterConfig) is called with null
 ServletRequestConfiguration(ServletRequest) is called with
 null
 + Deprecate DatabaseConfiguration.getDatasource() in favor of
 getDataSource()
 + Fix PMD DynamicCombinedConfiguration in
 AbstractImmutableNodeHandler
 AbstractListDelimiterHandler
 DefaultPrefixLookupsHolder
 DynamicCombinedConfiguration
 PropertiesConfiguration
 + CONFIGURATION-846: Restore previous behavior allowing Spring
 to inject multiple values
 + CONFIGURATION-847: Property with an empty string value was not
 processed

Changes for apache-commons-text:

- Upgrade to version 1.15.0
 * New features
 + Add experimental CycloneDX VEX file
 + TEXT-235: Add Damerau-Levenshtein distance
 + Add unit tests to increase coverage
 + Add new test for CharSequenceTranslator#with()
 + Add tests and assertions to org.apache.commons.text.similarity
 to get to 100% code coverage
 * Fixed Bugs
 + Fix exception message typo in XmlStringLookup
 .XmlStringLookup(Map, Path...)
 + TEXT-236: Inserting at the end of a TextStringBuilder throws
 a StringIndexOutOfBoundsException
 + Fix TextStringBuilderTest.testAppendToCharBuffer() to use
 proper argument type
 + Fix Apache RAT plugin console warnings
 + Fix site XML to use version 2.0.0 XML schema
 + Removed unreachable threshold verification code in
 src/main/java/org/apache/commons/text/similarity
 + Enable secure processing for the XML parser in XmlStringLookup
 in case the underlying JAXP implementation doesn't
 + Interface StringLookup now extends UnaryOperator<String>
 + Interface TextRandomProvider extends IntUnaryOperator
 + Add RandomStringGenerator.Builder
 .usingRandom(IntUnaryOperator)
 + Add PMD check to default Maven goal
 + Add org.apache.commons.text.RandomStringGenerator.Builder
 .setAccumulate(boolean)
 + Fix PMD UnnecessaryFullyQualifiedName in StringLookupFactory
 + Fix PMD UnnecessaryFullyQualifiedName in
 DefaultStringLookupsHolder
 PropertiesStringLookup
 JavaPlatformStringLookup
 + Fix PMD UnnecessaryFullyQualifiedName in StringSubstitutor
 + Fix PMD UnnecessaryFullyQualifiedName in StrSubstitutor
 + Fix PMD UnnecessaryFullyQualifiedName in AlphabetConverter
 + Fix PMD AvoidBranchingStatementAsLastInLoop in
 TextStringBuilder
 + Fix PMD AvoidBranchingStatementAsLastInLoop in StrBuilder
 + org.apache.commons.text.translate.LookupTranslator
 .LookupTranslator(Map CharSequence>) now throws
 NullPointerException instead of
 java.security.InvalidParameterException
 + Remove -nouses directive from maven-bundle-plugin. OSGi
 package imports now state 'uses' definitions for package
 imports, this doesn't affect JPMS
 (from org.apache.commons:commons-parent:80)
 + Deprecate EntityArrays.EntityArrays()
 + StringLookupFactory.DefaultStringLookupsHolder
 .createDefaultStringLookups() maps DefaultStringLookup
 .LOCAL_HOST twice instead of once for LOCAL_HOST and
 LOOPBACK_ADDRESS
 + Add StringLookupFactory.loopbackAddressStringLookup()
 + Add StringLookupFactory.KEY_LOOPBACK_ADDRESS
 + Add DefaultStringLookup.LOOPBACK_ADDRESS
 + Add richer inputs in package org.apache.commons.text
 .similarity with SimilarityInput
 + Add HammingDistance.apply(SimilarityInput, SimilarityInput)
 + Add JaccardDistance.apply(SimilarityInput, SimilarityInput)
 + Add JaccardSimilarity.apply(SimilarityInput, SimilarityInput)
 + Add JaroWinklerDistance.apply(SimilarityInput,
 SimilarityInput)
 + Add JaroWinklerSimilarity.apply(SimilarityInput,
 + Add LevenshteinDetailedDistance.apply(SimilarityInput,
 + Add LevenshteinDistance.apply(SimilarityInput,
 + Fix build on Java 22
 + Fix build on Java 23-ea
 + Make package-private constructor private:
 StrLookup.MapStrLookup.MapStrLookup(Map)
 + Make package-private constructor private: StrLookup
 .SystemPropertiesStrLookup.SystemPropertiesStrLookup()
 + Make package-private class private and final: MapStrLookup
 + Make package-private class private: StrMatcher.CharMatcher
 + Make package-private class private: StrMatcher.CharSetMatcher
 + Make package-private class private: StrMatcher.NoMatcher
 + Make package-private class private: StrMatcher.StringMatcher
 + Make package-private class private: StrMatcher.TrimMatcher
 + Make package-private class private and final:
 IntersectionSimilarity.BagCount
 IntersectionSimilarity.TinyCount
 + Deprecate LevenshteinDistance.LevenshteinDistance() in favor
 of LevenshteinDistance.getDefaultInstance()
 + Deprecate LevenshteinDetailedDistance
 .LevenshteinDetailedDistance() in favor of
 LevenshteinDetailedDistance.getDefaultInstance()
 + TEXT-234: Improve StrBuilder documentation for new line text
 + TEXT-234: Improve TextStringBuilder documentation for new line
 text
 + TEXT-233: Required OSGi Import-Package version numbers in
 MANIFEST.MF
 + Add StringLookupFactory.fileStringLookup(Path...) and
 deprecated fileStringLookup()
 + Add StringLookupFactory.propertiesStringLookup(Path...) and
 deprecated propertiesStringLookup()
 + Add StringLookupFactory.xmlStringLookup(Map, Path...) and
 deprecated xmlStringLookup() and xmlStringLookup(Map)
 + Add StringLookupFactory.builder() for fencing Path resolution
 of the file, properties and XML lookups
 + Add DoubleFormat.Builder.get() as Builder now implements
 Supplier
 + TEXT-232: WordUtils.containsAllWords?() may throw
 PatternSyntaxException
 + TEXT-175: Fix regression for determining whitespace in
 WordUtils
 + Deprecate Builder in favor of Supplier
 + TEXT-224: Set SecureProcessing feature in XmlStringLookup by
 default
 + TEXT-224: Add StringLookupFactory.xmlStringLookup(Map<String,
 Boolean>...)
 + Add @FunctionalInterface to FormatFactory
 + Add RandomStringGenerator.builder()
 + TEXT-229: Add XmlEncoderStringLookup/XmlDecoderStringLookup
 + Add StringSubstitutor.toString()
 + TEXT-219: Fix StringTokenizer.getTokenList to return an
 independent modifiable list
 + Fix Javadoc for StringEscapeUtils.escapeHtml4
 + TextStringBuidler#hashCode() allocates a String on each call
 + TEXT-221: Fix Bundle-SymbolicName to use the package name
 org.apache.commons.text
 + Add and use a package-private singleton for RegexTokenizer
 + Add and use a package-private singleton for CosineSimilarity
 + Add and use a package-private singleton for
 LongestCommonSubsequence
 JaroWinklerSimilarity
 + Add and use a package-private singleton for JaccardSimilarity
 + [StepSecurity] ci: Harden GitHub Actions
 + Improve AlphabetConverter Javadoc
 + Fix exception message in IntersectionResult to make
 set-theoretic sense
 + Add null-check in RandomStringGenerator#Builder#selectFrom()
 to avoid NullPointerException
 + Add null-check in RandomStringGenerator#Builder#withinRange()
 + TEXT-228: Fix TextStringBuilder to over-allocate when ensuring
 capacity
 + Constructor for ResourceBundleStringLookup should be private
 instead of package-private
 + Constructor for UrlDecoderStringLookup should be private
 + Constructor for UrlEncoderStringLookup should be private
 + TEXT-230: Javadoc of org.apache.commons.text.lookup
 .DefaultStringLookup.XML is incorrect
 + Update DoubleFormat to state it is based on Double.toString

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2648-1
Released:    Fri Jun 26 13:05:57 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1266340,1266341,1266342,1266343,1266345,1266349,1266350,1266351,1266352,1266353,1266355,1266356,1266357,CVE-2026-34180,CVE-2026-34181,CVE-2026-34183,CVE-2026-42766,CVE-2026-42767,CVE-2026-42768,CVE-2026-42769,CVE-2026-42770,CVE-2026-45445,CVE-2026-45446,CVE-2026-45447,CVE-2026-7383,CVE-2026-9076
This update for openssl-3 fixes the following issues

- CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340).
- CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341).
- CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342).
- CVE-2026-34181: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (bsc#1266343).
- CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345).
- CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349).
- CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
- CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351).
- CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352).
- CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353).
- CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355).
- CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356).
- CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2661-1
Released:    Fri Jun 26 15:15:48 2026
Summary:     Recommended update for curl
Type:        recommended
Severity:    important
References:  1264971
This update for curl fixes the following issues:

- Call http_size() first to prioritize Transfer-Encoding: chunked over a zero
  Content-Length empty body check (bsc#1264971)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2666-1
Released:    Fri Jun 26 16:07:08 2026
Summary:     Security update for giflib
Type:        security
Severity:    important
References:  1259836,CVE-2026-26740
This update for giflib fixes the following issue

- CVE-2026-26740: heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a
  truncated extension byte count (bsc#1259836).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2675-1
Released:    Mon Jun 29 11:42:14 2026
Summary:     Security update for tomcat
Type:        security
Severity:    important
References:  1265145,1265162,1265163,1265165,1265166,1265167,1265168,CVE-2026-41284,CVE-2026-41293,CVE-2026-42498,CVE-2026-43512,CVE-2026-43513,CVE-2026-43514,CVE-2026-43515
This update for tomcat fixes the following issues

Update to Tomcat 9.0.118:

- CVE-2026-41284: Unbounded read in WebDAV LOCK and PROPFIND handling (bsc#1265162).
- CVE-2026-41293: HTTP/2 request headers not validated (bsc#1265163).
- CVE-2026-42498: WebSocket authentication header exposure (bsc#1265165).
- CVE-2026-43512: digest authenticator will authenticate any unknown user (bsc#1265145).
- CVE-2026-43513: LockOutRealm treats user names as case-sensitive (bsc#1265166).
- CVE-2026-43514: AJP secret compared in non-constant time (bsc#1265167).
- CVE-2026-43515: Security constraints not correctly applied (bsc#1265168).
  
Changes:
  
 * Catalina
 + Add: Enhance version.sh and version.bat to display APR, Tomcat Native, and
 OpenSSL version information (both APR and FFM implementations), along with
 version compatibility warnings and third-party library version
 information. (csutherl)
 + Code: Refactor generation of the remote user element in the access log to
 remove unnecessary code. (markt)
 + Fix: Fix a regression in the previous release that meant ?- could appear
 in the access log rather than ? when the query string was present but
 empty. (markt)
 + Fix: Failed precondition should make WebDAV DELETE fail. #982 submitted by
 Mahmoud Alarby. (remm)
 + Fix: Align the escaping in ExtendedAccessLogValve with the other
 AccessLogValve implementations. (markt)
 + Fix: 70000: fix duplication of special headers in the response after
 commit, following fix for 69967. (remm)
 + Fix: Correct the handling of URIs mapped to a security constraint that
 only specifies the special ** role for all authenticated users. Requests
 without authentication were receiving 403 responses rather than 401
 responses. (markt)
 + Fix: Fix a race condition in StandardContext.getServletContext() that
 could cause the jakarta.servlet.context.tempdir attribute to be lost
 during a context reload. Make the context field volatile and use locking
 to ensure only one ApplicationContext instance is created. (dsoumis)
 + Fix: Update the Windows authentication (kerberos) documentation to reflect
 that both Java and Windows are removing / have removed support for
 RC4-HMAC. The guide now uses AES256-SHA1. (markt)
 + Fix: Add a new initialisation parameter for WebDAV, maxRequestBodySize
 which limits the size of a WebDAV request body for LOCK and PROPFIND. The
 default value is 4096 bytes. (markt)
 + Add: Add a new caseSensitive attribute to the LockOutRealm that controls
 the manner in which user names are treated when making locking decisions.
 The default is false, meaning user names are treated in a case insensitive
 manner. (markt)
 + Fix: Correct the handling of invalid users with DIGEST authentication.
 (markt)
 + Fix: Ensure RealmBase finds all matching extension based security
 constraints. (markt)
 * Coyote
 + Fix: Avoid various edge cases if Content-Length is set via
 setHeader(String,String) or addHeader(String,String) with an invalid value
 by always clearing the previous value whether the new value is valid or
 not and ignoring any invalid new value. (markt)
 + Code: Refactor the calculation of the real index in the HPACK dynamic
 header table implementation to reduce code duplication. (markt)
 + Fix: Fix various minor issues with some HTTP/2 stream error messages for
 HTTP/2. (markt)
 + Fix: Consistently reject URIs containing NULL bytes when normalizing.
 + Fix: Fix a few minor memory leaks on error paths reading TLS keys and
 certificates when using FFM. (markt)
 + Fix: Refactor clean-up after HTTP/2 headers have been processed to aid GC
 after a stream reset. (markt)
 + Fix: Align HTTP/2 trailer fields with HTTP/1.1 and filter out any fields
 not permitted in trailers. (markt)
 + Fix: Free private keys after use in FFM based connector configuration.
 + Fix: Correct an unlikely edge-case parsing bug in the HTTP/2 HPACK header
 decoding that could result in a valid header triggering an unexpected
 connection close. (markt)
 + Fix: Refactor HTTP/2 HPACK encoding so header field names are only
 converted to lower case once during the encoding process. (markt)
 + Fix: Refactor HTTP/2 header field validation so it occurs earlier. Extend
 validation to check for disallowed characters as well as upper case
 characters. (markt)
 + Fix: Add TLS 1.3 groups added in OpenSSL 4.0. (remm)
 + Fix: Add validation that the HTTP/2 :scheme pseudo-header is consistent
 with the use (or not) of TLS. (markt)
 + Fix: Correct the validation of pseudo headers and CONNECT requests to
 align Tomcat's behaviour with RFC 9113, section 8.5. (markt)
 + Fix: Fix a potential integer overflow when allocating capacity from a
 connection level window update to individual HTTP/2 streams. Based on #996
 by Mike Tingey Jr. (markt)
 + Fix: Switch AJP secret comparison to a constant time algorithm. (markt)
 * WebSocket
 + Fix: Fix the initial connection to a WebSocket end point where the
 connection is made via a proxy that requires DIGEST authentication.
 * Other
 + Fix: 69993: Update the URL to the CDDL 1.0 license. (markt)
 + Add: Add warning when OpenSSL binary is not found. (csutherl)
 + Add: Add check for Tomcat Native library, and log warning when it's not
 found to make it easier to see when it's not used by the suite. (csutherl)
 + Update: Update Byte Buddy to 1.18.8. (markt)
 + Update: Update Bouncy Castle to 1.84. (markt)
 + Update: Improvements to French translations. (remm)
 + Update: Improvements to Japanese translations provided by tak7iji. (markt)

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2688-1
Released:    Tue Jun 30 10:20:42 2026
Summary:     Security update for sg3_utils
Type:        security
Severity:    important
References:  1267823
This update for sg3_utils fixes the following issue

- sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2714-1
Released:    Tue Jun 30 14:02:53 2026
Summary:     Security update for tar
Type:        security
Severity:    important
References:  1261900,1265450,1267189,CVE-2026-5704
This update for tar fixes the following issues

Security fixes:

- CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900).

Other fixes:

- Fix tar changing dir permissions temporarily even when using --no-overwrite-dir.
- Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450).
- Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2
 implementation (bsc#1267189).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2725-1
Released:    Thu Jul  2 15:52:16 2026
Summary:     Security update for python-tornado6
Type:        security
Severity:    important
References:  1268395,1268396,1268397,CVE-2026-49853,CVE-2026-49854,CVE-2026-49855
This update for python-tornado6 fixes the following issues

- CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395).
- CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396).
- CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2673-1
Released:    Thu Jul  2 17:04:31 2026
Summary:     Security update for bind
Type:        security
Severity:    important
References:  1263494,1265591,1265592,1265593,1265594,1265595,1265596,CVE-2026-3039,CVE-2026-3592,CVE-2026-3593,CVE-2026-5946,CVE-2026-5947,CVE-2026-5950
This update for bind fixes the following issues:

Security issues:

- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591).
- CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592).
- CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (bsc#1265593).
- CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594).
- CVE-2026-5947: SIG(0) validation during query flood may lead to undefined behavior (bsc#1265595).
- CVE-2026-5950: Unbounded resend loop in BIND 9 resolver (bsc#1265596).

Non security issue:

- bind test failed with version 9.20.21 (bsc#1263494).
- Upgrade to release 9.20.23

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2749-1
Released:    Fri Jul  3 15:04:33 2026
Summary:     Security update for perl-DBI
Type:        security
Severity:    important
References:  1267849,1267957,CVE-2026-10879,CVE-2026-9698
This update for perl-DBI fixes the following issues

- CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited-sized buffer (bsc#1267957).
- CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2754-1
Released:    Fri Jul  3 21:22:01 2026
Summary:     Security update for python3-lxml
Type:        security
Severity:    moderate
References:  1263254,CVE-2026-41066
This update for python3-lxml fixes the following issue

- CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2759-1
Released:    Mon Jul  6 04:04:11 2026
Summary:     Security update for apache2
Type:        security
Severity:    important
References:  1267503,1267955,1267956,1267962,1267963,1267965,1267969,1267970,1267971,1267972,1267976,1267977,1267978,CVE-2026-29167,CVE-2026-29170,CVE-2026-34355,CVE-2026-34356,CVE-2026-42535,CVE-2026-42536,CVE-2026-43951,CVE-2026-44119,CVE-2026-44185,CVE-2026-44186,CVE-2026-44631,CVE-2026-48913,CVE-2026-49975
This update for apache2 fixes the following issues

- CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976).
- CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977).
- CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978).
- CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955).
- CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956).
- CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962).
- CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963).
- CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965).
- CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969).
- CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of
  service (bsc#1267970).
- CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971).
- CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free
  (bsc#1267972).
- CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503).

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2774-1
Released:    Mon Jul  6 09:52:16 2026
Summary:     Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server
Type:        security
Severity:    important
References:  1208800,1226578,1234567,1238890,1242916,1245107,1247707,1248699,1249243,1253032,1254900,1257583,1257894,1258041,1258079,1258144,1258382,1258816,1259087,1259230,1259261,1259474,1259479,1259482,1259521,1259590,1259591,1259700,1259739,1259787,1259960,1260031,1260614,1260806,1261305,1261307,1261327,1261631,1261723,1261753,1261841,1261902,1262090,1262222,1262285,1262460,1262471,1262492,1262595,1262708,1262720,1262760,1262761,1262950,1263501,1263814,1263841,1263986,1263987,1264149,1264174,1264234,1264256,1264966,1265134,1265281,1265282,1265283,1265284,1265285,1265286,1265287,1265288,1265289,1265290,1265319,1265358,1265975,1266012,1266556,1266600,1269253,1269534,CVE-2022-21698,CVE-2026-28374,CVE-2026-28376,CVE-2026-28379,CVE-2026-28380,CVE-2026-28383,CVE-2026-33376,CVE-2026-33377,CVE-2026-33378,CVE-2026-33380,CVE-2026-33381,CVE-2026-34986,CVE-2026-39821,CVE-2026-40179,CVE-2026-41602,CVE-2026-42151,CVE-2026-42154,CVE-2026-42198
Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server

This is a codestream only update


The following package changes have been done:

- glibc-2.38-150600.14.49.1 updated
- libuuid1-2.40.4-150700.4.13.1 updated
- libsqlite3-0-3.53.2-150000.3.42.1 updated
- libsmartcols1-2.40.4-150700.4.13.1 updated
- liblzma5-5.4.1-150600.3.6.1 updated
- libopenssl3-3.2.3-150700.5.36.1 updated
- libblkid1-2.40.4-150700.4.13.1 updated
- sed-4.9-150600.3.3.1 updated
- coreutils-8.32-150400.9.12.1 updated
- libopenssl-3-fips-provider-3.2.3-150700.5.36.1 updated
- libmount1-2.40.4-150700.4.13.1 updated
- libfdisk1-2.40.4-150700.4.13.1 updated
- libcurl4-8.14.1-150700.7.17.1 updated
- libsolv-tools-base-0.7.39-150700.11.10.1 updated
- libzypp-17.38.13-150700.6.13.1 updated
- zypper-1.14.98-150700.13.6.1 updated
- util-linux-2.40.4-150700.4.13.1 updated
- curl-8.14.1-150700.7.17.1 updated
- tar-1.34-150000.3.42.1 updated
- timezone-2026b-150600.91.9.1 updated
- openssl-3-3.2.3-150700.5.36.1 updated
- libapparmor1-3.1.7-150600.5.15.1 updated
- glibc-locale-base-2.38-150600.14.49.1 updated
- golang-github-QubitProducts-exporter_exporter-0.4.0-150000.1.24.2 updated
- libarchive13-3.7.2-150600.3.20.1 updated
- libavahi-common3-0.8-150600.15.18.1 updated
- liberate-formula-0.1.4-150700.3.9.1 updated
- libfreebl3-3.112.5-150400.3.69.2 updated
- libgif7-5.2.2-150000.4.22.1 updated
- libipa_hbac0-2.10.2-150700.9.31.1 updated
- libopenssl1_1-1.1.1w-150700.11.22.1 updated
- libpq5-18.4-150600.13.11.1 updated
- libsgutils2-1_48-2-1.48+12.096114a9-150600.3.6.1 updated
- libsolv-tools-0.7.39-150700.11.10.1 updated
- libsss_idmap0-2.10.2-150700.9.31.1 updated
- libsss_nss_idmap0-2.10.2-150700.9.31.1 updated
- openssh-common-9.6p1-150600.6.42.1 updated
- python311-base-3.11.15-150600.3.56.1 updated
- libpython3_11-1_0-3.11.15-150600.3.56.1 updated
- release-notes-multi-linux-manager-5.1.4-150700.5.34.1 updated
- susemanager-schema-utility-5.1.19-150700.3.22.5 updated
- uyuni-config-modules-5.1.25-150700.3.29.1 updated
- vim-data-common-9.2.0530-150500.20.52.1 updated
- xz-5.4.1-150600.3.6.1 updated
- glibc-locale-2.38-150600.14.49.1 updated
- libavahi-client3-0.8-150600.15.18.1 updated
- postgresql16-16.14-150600.16.33.1 updated
- sg3_utils-1.48+12.096114a9-150600.3.6.1 updated
- libsss_certmap0-2.10.2-150700.9.31.1 updated
- bind-utils-9.20.23-150700.3.25.1 updated
- iproute2-6.4-150600.7.15.1 updated
- glibc-devel-2.38-150600.14.49.1 updated
- mozilla-nss-certs-3.112.5-150400.3.69.2 updated
- openssh-fips-9.6p1-150600.6.42.1 updated
- python311-3.11.15-150600.3.56.1 updated
- susemanager-docs_en-5.1-150700.10.12.1 updated
- redstone-xmlrpc-1.1_20071120-0.150700.11.3.1 updated
- spacewalk-java-lib-5.1.28-150700.3.26.2 updated
- uyuni-reportdb-schema-5.1.7-150700.3.9.4 updated
- prometheus-postgres_exporter-0.10.1-150700.17.3.2 updated
- golang-github-prometheus-node_exporter-1.10.2-150100.3.41.2 updated
- vim-9.2.0530-150500.20.52.1 updated
- perl-DBI-1.647.0-150600.12.11.1 updated
- apache2-prefork-2.4.66-150700.4.23.1 updated
- openssh-server-9.6p1-150600.6.42.1 updated
- openssh-clients-9.6p1-150600.6.42.1 updated
- libgnutls30-3.8.3-150600.4.20.1 updated
- python3-solv-0.7.39-150700.11.10.1 updated
- prometheus-exporters-formula-1.4.3-150700.3.6.1 updated
- libldb2-4.21.10+git.501.277ba349a01-150700.3.26.1 updated
- mozilla-nss-3.112.5-150400.3.69.2 updated
- libsoftokn3-3.112.5-150400.3.69.2 updated
- susemanager-tools-salt-5.1.17-150700.3.15.1 added
- python311-typing_extensions-4.12.2-150600.3.3.1 updated
- python311-tornado6-6.3.2-150400.9.18.1 added
- susemanager-docs_en-pdf-5.1-150700.10.12.1 updated
- susemanager-schema-5.1.19-150700.3.22.5 updated
- susemanager-sync-data-5.1.10-150700.3.12.1 updated
- uyuni-setup-reportdb-5.1.5-150700.3.6.1 updated
- rsync-3.2.7-150600.3.21.1 updated
- apache2-2.4.66-150700.4.23.1 updated
- openssh-9.6p1-150600.6.42.1 updated
- libvirt-libs-11.0.0-150700.4.22.1 updated
- python3-uyuni-common-libs-5.1.6-150700.3.6.1 updated
- virtual-host-gatherer-1.0.31-150700.17.6.1 updated
- spacewalk-backend-sql-postgresql-5.1.17-150700.3.12.7 updated
- python3-lxml-4.9.1-150500.3.7.1 updated
- sssd-ldap-2.10.2-150700.9.31.1 updated
- sssd-2.10.2-150700.9.31.1 updated
- sssd-krb5-common-2.10.2-150700.9.31.1 updated
- samba-client-libs-4.21.10+git.501.277ba349a01-150700.3.26.1 updated
- mozilla-nss-sysinit-3.112.5-150400.3.69.2 added
- perl-XML-LibXML-2.0132-150000.3.8.1 updated
- perl-HTTP-Daemon-6.01-150000.3.8.1 updated
- susemanager-build-keys-15.5.3-150700.5.14.1 updated
- spacecmd-5.1.14-150700.3.12.1 updated
- virtual-host-gatherer-Nutanix-1.0.31-150700.17.6.1 updated
- sssd-krb5-2.10.2-150700.9.31.1 updated
- sssd-dbus-2.10.2-150700.9.31.1 updated
- python3-sssd-config-2.10.2-150700.9.31.1 updated
- sssd-ad-2.10.2-150700.9.31.1 updated
- spacewalk-base-minimal-5.1.21-150700.3.20.11 updated
- susemanager-build-keys-web-15.5.3-150700.5.14.1 updated
- virtual-host-gatherer-Libvirt-1.0.31-150700.17.6.1 updated
- sssd-tools-2.10.2-150700.9.31.1 updated
- sssd-ipa-2.10.2-150700.9.31.1 updated
- tomcat-servlet-4_0-api-9.0.118-150200.108.1 updated
- tomcat-el-3_0-api-9.0.118-150200.108.1 updated
- python311-pyOpenSSL-23.2.0-150400.3.16.1 updated
- python3-firewall-1.3.4-150600.13.6.1 updated
- spacewalk-base-minimal-config-5.1.21-150700.3.20.11 updated
- python3-pyOpenSSL-21.0.0-150400.13.1 updated
- python3-PyJWT-2.4.0-150200.3.14.1 updated
- tomcat-jsp-2_3-api-9.0.118-150200.108.1 updated
- apache-commons-text-1.15.0-150200.5.14.1 updated
- netty-4.1.133-150200.4.46.1 updated
- python311-urllib3-2.0.7-150400.7.30.1 updated
- firewalld-1.3.4-150600.13.6.1 updated
- python3-urllib3-1.25.10-150300.4.27.1 updated
- spacewalk-base-5.1.21-150700.3.20.11 updated
- tomcat-lib-9.0.118-150200.108.1 updated
- log4j-2.20.0-150200.4.33.1 updated
- spacewalk-backend-5.1.17-150700.3.12.7 updated
- log4j-slf4j-2.20.0-150200.4.33.1 updated
- log4j-jcl-2.20.0-150200.4.33.1 updated
- salt-3006.0-150700.14.23.4 updated
- python311-salt-3006.0-150700.14.23.4 updated
- fence-agents-4.13.1+git.1704296072.32469f29-150600.3.35.1 updated
- spacewalk-backend-sql-5.1.17-150700.3.12.7 updated
- postgresql-jdbc-42.2.25-150400.3.15.1 updated
- subscription-matcher-0.44-150700.3.6.1 updated
- salt-master-3006.0-150700.14.23.4 updated
- virtual-host-gatherer-VMware-1.0.31-150700.17.6.1 updated
- virtual-host-gatherer-libcloud-1.0.31-150700.17.6.1 updated
- cobbler-3.3.3-150700.5.9.7 updated
- spacewalk-backend-server-5.1.17-150700.3.12.7 updated
- tomcat-9.0.118-150200.108.1 updated
- salt-api-3006.0-150700.14.23.4 updated
- spacewalk-backend-xmlrpc-5.1.17-150700.3.12.7 updated
- spacewalk-backend-xml-export-libs-5.1.17-150700.3.12.7 updated
- spacewalk-backend-package-push-server-5.1.17-150700.3.12.7 updated
- spacewalk-backend-app-5.1.17-150700.3.12.7 updated
- spacewalk-java-postgresql-5.1.28-150700.3.26.2 updated
- spacewalk-java-config-5.1.28-150700.3.26.2 updated
- spacewalk-html-5.1.21-150700.3.20.11 updated
- spacewalk-taskomatic-5.1.28-150700.3.26.2 updated
- spacewalk-java-5.1.28-150700.3.26.2 updated
- spacewalk-backend-tools-5.1.17-150700.3.12.7 updated
- susemanager-sls-5.1.25-150700.3.29.1 updated
- susemanager-tools-5.1.17-150700.3.15.1 updated
- saltboot-formula-1.1.0-150700.3.9.1 updated
- susemanager-5.1.17-150700.3.15.1 updated
- saline-formula-2026.05.18-150700.3.6.1 updated
- container:bci-bci-init-15.7-78d7c53c5c9d133dade10b227e8c8d97ab1f950bc625d9bb707c3a34802526e5-0 updated


More information about the sle-container-updates mailing list