SUSE-IU-2026:5098-1: Security update of suse/sle-micro/rt-5.5

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Jun 27 07:10:29 UTC 2026


SUSE Image Update Advisory: suse/sle-micro/rt-5.5
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:5098-1
Image Tags        : suse/sle-micro/rt-5.5:2.0.4 , suse/sle-micro/rt-5.5:2.0.4-4.5.630 , suse/sle-micro/rt-5.5:latest
Image Release     : 4.5.630
Severity          : important
Type              : security
References        : 1247954 1255416 1258538 1260531 1261700 1262663 1262993 1263769
                        1263879 1263880 1264076 1264093 1264116 1264470 1264610 1265116
                        1265211 1265960 1266214 1266290 1266810 1266969 1267205 1267214
                        1267220 1267361 1267369 1267387 1267621 1267640 1267651 1267652
                        1267697 CVE-2025-10263 CVE-2025-68324 CVE-2026-23392 CVE-2026-31405
                        CVE-2026-31473 CVE-2026-31500 CVE-2026-31613 CVE-2026-31697 CVE-2026-31698
                        CVE-2026-31699 CVE-2026-31758 CVE-2026-31759 CVE-2026-43077 CVE-2026-43198
                        CVE-2026-43366 CVE-2026-43503 CVE-2026-45886 CVE-2026-45970 CVE-2026-45984
                        CVE-2026-46021 CVE-2026-46037 CVE-2026-46113 CVE-2026-46116 CVE-2026-46120
                        CVE-2026-46123 CVE-2026-46150 CVE-2026-46159 CVE-2026-46227 CVE-2026-46273
-----------------------------------------------------------------

The container suse/sle-micro/rt-5.5 was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2630-1
Released:    Thu Jun 25 13:55:00 2026
Summary:     Security update for the Linux Kernel
Type:        security
Severity:    important
References:  1247954,1255416,1258538,1260531,1261700,1262663,1262993,1263769,1263879,1263880,1264076,1264093,1264116,1264470,1264610,1265116,1265211,1265960,1266214,1266290,1266810,1266969,1267205,1267214,1267220,1267361,1267369,1267387,1267621,1267640,1267651,1267652,1267697,CVE-2025-10263,CVE-2025-68324,CVE-2026-23392,CVE-2026-31405,CVE-2026-31473,CVE-2026-31500,CVE-2026-31613,CVE-2026-31697,CVE-2026-31698,CVE-2026-31699,CVE-2026-31758,CVE-2026-31759,CVE-2026-43077,CVE-2026-43198,CVE-2026-43366,CVE-2026-43503,CVE-2026-45886,CVE-2026-45970,CVE-2026-45984,CVE-2026-46021,CVE-2026-46037,CVE-2026-46113,CVE-2026-46116,CVE-2026-46120,CVE-2026-46123,CVE-2026-46150,CVE-2026-46159,CVE-2026-46227,CVE-2026-46273

The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues

The following security issues were fixed:

- CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
- CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416).
- CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).
- CVE-2026-31405: media: dvb-net: fix OOB access in ULE extension header tables (bsc#1261700).
- CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663).
- CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993).
- CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769).
- CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).
- CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).
- CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).
- CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093).
- CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).
- CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
- CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).
- CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265116).
- CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810).
- CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205).
- CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214).
- CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220).
- CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
- CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969).
- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).
- CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640).
- CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).
- CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
- CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652).
- CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697).
- CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651).

The following non security issues were fixed:

- arm64: tlb: Allow XZR argument to TLBI ops (git-fixes).
- arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes).
- KVM: x86: Constrain guest-supported xfeatures only at KVM_GET_XSAVE{2} (bsc#1247954).
- KVM: x86: Remove 'return void' expression for 'void function' (bsc#1247954).
- smb: client: correctly handle ErrorContextData as a flexible array (git-fixes).
- x86/fpu: Allow caller to constrain xfeatures when copying to uabi buffer (bsc#1247954).

-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2637-1
Released:    Thu Jun 25 17:42:10 2026
Summary:     Recommended update for mozilla-nss
Type:        recommended
Severity:    moderate
References:  
This update for mozilla-nss fixes the following issues:

Update to NSS 3.112.5:

* reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max.
* update to version 2.84 of builtins module.

- Added 'Suggests: p11-kit-nss-trust' to favor over mozilla-nss-certs (jsc#PED-15633)


The following package changes have been done:

- libfreebl3-3.112.5-150400.3.69.2 updated
- mozilla-nss-certs-3.112.5-150400.3.69.2 updated
- mozilla-nss-3.112.5-150400.3.69.2 updated
- libsoftokn3-3.112.5-150400.3.69.2 updated
- kernel-rt-5.14.21-150500.13.146.1 updated
- container:suse-sle-micro-5.5-latest-2.0.4-5.8.40 updated


More information about the sle-container-updates mailing list