SUSE-IU-2026:4504-1: Security update of suse/sle-micro/5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Jun 12 07:13:55 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:4504-1
Image Tags        : suse/sle-micro/5.5:2.0.4 , suse/sle-micro/5.5:2.0.4-5.8.27 , suse/sle-micro/5.5:latest
Image Release     : 5.8.27
Severity          : important
Type              : security
References        : 1259642 1261427 1261430 1261441 1264568 CVE-2026-3497 CVE-2026-35385
                        CVE-2026-35388 CVE-2026-35414 
-----------------------------------------------------------------

The container suse/sle-micro/5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2375-1
Released:    Thu Jun 11 18:05:37 2026
Summary:     Security update for openssh
Type:        security
Severity:    important
References:  1259642,1261427,1261430,1261441,1264568,CVE-2026-3497,CVE-2026-35385,CVE-2026-35388,CVE-2026-35414
This update for openssh fixes the following issues

- CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642).
- CVE-2026-35385: a file downloaded by scp may be installed setuid or setgid (bsc#1261427).
- CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441).
- CVE-2026-35414: mishandling of authorized_keys principals option (bsc#1261430).
- potential security issue when validating mac (bsc#1264568).


The following package changes have been done:

- openssh-common-8.4p1-150300.3.65.1 updated
- openssh-server-8.4p1-150300.3.65.1 updated
- openssh-clients-8.4p1-150300.3.65.1 updated
- openssh-8.4p1-150300.3.65.1 updated


More information about the sle-container-updates mailing list