SUSE-IU-2026:6014-1: Security update of suse/sle-micro/5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jul 31 07:08:51 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6014-1
Image Tags        : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.74 , suse/sle-micro/5.5:latest
Image Release     : 5.8.74
Severity          : low
Type              : security
References        : 1268275 CVE-2025-31133 CVE-2025-52565 CVE-2026-41579 
-----------------------------------------------------------------

The container suse/sle-micro/5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3433-1
Released:    Thu Jul 30 20:54:35 2026
Summary:     Security update for runc
Type:        security
Severity:    low
References:  1268275,CVE-2025-31133,CVE-2025-52565,CVE-2026-41579
This update for runc fixes the following issues:

Update to 1.3.6.

- CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations
  (bsc#1268275).

Other updates and bugfixes:

- Version 1.3.6:
  * When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable)
    to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes
    applies masks to per-CPU sysfs directories which get expensive quickly).
- Version 1.3.5:
  * Recursive atime-related mount flags (rrelatime et al.) are now applied properly.
  * PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when
    running runc create and has thus been reverted.
  * Updated builds to Go 1.25, libseccomp v2.6.0.
  * Minor signing keyring updates.


The following package changes have been done:

- runc-1.3.6-150000.101.1 updated


More information about the sle-container-updates mailing list