From sle-container-updates at lists.suse.com Thu Oct 1 07:10:49 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:10:49 +0200 (CEST) Subject: SUSE-CU-2026:11335-1: Security update of suse/sle-micro/5.3/toolbox Message-ID: <20261001071049.10201FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11335-1 Container Tags : suse/sle-micro/5.3/toolbox:16.3 , suse/sle-micro/5.3/toolbox:16.3-6.11.287 , suse/sle-micro/5.3/toolbox:latest Container Release : 6.11.287 Severity : important Type : security References : 1277757 CVE-2026-13732 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4400-1 Released: Wed Sep 30 10:55:06 2026 Summary: Security update for gdb Type: security Severity: important References: 1277757,CVE-2026-13732 This update for gdb fixes the following issue: - CVE-2026-13732: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). The following package changes have been done: - gdb-16.3-150400.15.32.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:14:11 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:14:11 +0200 (CEST) Subject: SUSE-CU-2026:11336-1: Security update of suse/sle-micro/5.4/toolbox Message-ID: <20261001071411.97A78FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.4/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11336-1 Container Tags : suse/sle-micro/5.4/toolbox:16.3 , suse/sle-micro/5.4/toolbox:16.3-5.19.288 , suse/sle-micro/5.4/toolbox:latest Container Release : 5.19.288 Severity : important Type : security References : 1277757 CVE-2026-13732 ----------------------------------------------------------------- The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4400-1 Released: Wed Sep 30 10:55:06 2026 Summary: Security update for gdb Type: security Severity: important References: 1277757,CVE-2026-13732 This update for gdb fixes the following issue: - CVE-2026-13732: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). The following package changes have been done: - gdb-16.3-150400.15.32.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:17:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:17:13 +0200 (CEST) Subject: SUSE-CU-2026:11337-1: Security update of suse/sle-micro/5.5/toolbox Message-ID: <20261001071713.42337FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sle-micro/5.5/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11337-1 Container Tags : suse/sle-micro/5.5/toolbox:16.3 , suse/sle-micro/5.5/toolbox:16.3-3.12.199 , suse/sle-micro/5.5/toolbox:latest Container Release : 3.12.199 Severity : important Type : security References : 1277757 CVE-2026-13732 ----------------------------------------------------------------- The container suse/sle-micro/5.5/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2026:4400-1 Released: Wed Sep 30 10:55:06 2026 Summary: Security update for gdb Type: security Severity: important References: 1277757,CVE-2026-13732 This update for gdb fixes the following issue: - CVE-2026-13732: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). The following package changes have been done: - gdb-16.3-150400.15.32.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:21:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:21:06 +0200 (CEST) Subject: SUSE-IU-2026:7561-1: Security update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20261001072106.A6512FCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7561-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.167 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.167 Severity : moderate Type : security References : 1272206 CVE-2026-15588 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1788 Released: Wed Sep 30 11:45:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - libglib-2_0-0-2.84.4-160000.5.1 updated - libgobject-2_0-0-2.84.4-160000.5.1 updated - libgmodule-2_0-0-2.84.4-160000.5.1 updated - libgio-2_0-0-2.84.4-160000.5.1 updated - glib2-tools-2.84.4-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-3402b89b1465b79bd3dae918952f4662bedddfe6550634ac750e57d5ced1604e-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:21:07 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:21:07 +0200 (CEST) Subject: SUSE-IU-2026:7562-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20261001072107.AE969FD07@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7562-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.168 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.168 Severity : moderate Type : recommended References : 1282301 ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1792 Released: Wed Sep 30 17:02:45 2026 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate References: 1282301 This update for jitterentropy fixes the following issues: Changes in jitterentropy: - OSR has to be at least 5 according to current reviews. (bsc#1282301) The following package changes have been done: - libjitterentropy3-3.6.3-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-a5647c3cae0c0839b551730820eff1188dabdddc0129403d4000a751b762739c-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:31:20 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:31:20 +0200 (CEST) Subject: SUSE-IU-2026:7568-1: Security update of suse/sl-micro/6.2/base-os-container Message-ID: <20261001073120.7BC8AFCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7568-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.88 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.88 Severity : moderate Type : security References : 1272206 1279961 CVE-2026-15588 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1790 Released: Wed Sep 30 11:29:23 2026 Summary: Recommended update for ca-certificates-mozilla Type: recommended Severity: moderate References: 1279961 This update for ca-certificates-mozilla fixes the following issues: Changes in ca-certificates-mozilla: - Updated to 2.90 state (bsc#1279961): * Removed: + AffirmTrust Commercial + AffirmTrust Networking + AffirmTrust Premium + AffirmTrust Premium ECC + certSIGN ROOT CA + Entrust Root Certification Authority + PKI Root Certification Authority + FIRMAPROFESIONAL CA ROOT-A WEB + GLOBALTRUST 2020 + Secure Global CA + SecureSign Root CA12 + SecureTrust CA + TeliaSonera Root CA v1 + Trustwave Global Certification Authority + Trustwave Global ECC P256 Certification Authority + Trustwave Global ECC P384 Certification Authority + XRamp Global Certification Authority * Added: + SECOM SMIME RSA Root CA 2024 + SECOM TLS ECC Root CA 2024 + SECOM TLS RSA Root CA 2024 + SecureSign Root CA16 + Telia EC Email Root CA v3 + Telia EC TLS Root CA v3 + Telia RSA Email Root CA v3 + Telia RSA TLS Root CA v3 ----------------------------------------------------------------- Advisory ID: 1788 Released: Wed Sep 30 11:45:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - libglib-2_0-0-2.84.4-160000.5.1 updated - libgobject-2_0-0-2.84.4-160000.5.1 updated - libgmodule-2_0-0-2.84.4-160000.5.1 updated - libgio-2_0-0-2.84.4-160000.5.1 updated - glib2-tools-2.84.4-160000.5.1 updated - ca-certificates-mozilla-2.90-160000.1.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:31:21 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:31:21 +0200 (CEST) Subject: SUSE-IU-2026:7569-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20261001073121.A5AEBFD07@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7569-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.89 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.89 Severity : moderate Type : recommended References : 1282301 ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1792 Released: Wed Sep 30 17:02:45 2026 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate References: 1282301 This update for jitterentropy fixes the following issues: Changes in jitterentropy: - OSR has to be at least 5 according to current reviews. (bsc#1282301) The following package changes have been done: - libjitterentropy3-3.6.3-160000.3.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:40:58 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:40:58 +0200 (CEST) Subject: SUSE-IU-2026:7574-1: Security update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20261001074058.8835DFCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7574-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.150 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.150 Severity : moderate Type : security References : 1272206 CVE-2026-15588 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1788 Released: Wed Sep 30 11:45:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - libglib-2_0-0-2.84.4-160000.5.1 updated - libgobject-2_0-0-2.84.4-160000.5.1 updated - libgmodule-2_0-0-2.84.4-160000.5.1 updated - libgio-2_0-0-2.84.4-160000.5.1 updated - glib2-tools-2.84.4-160000.5.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-3402b89b1465b79bd3dae918952f4662bedddfe6550634ac750e57d5ced1604e-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:41:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:41:00 +0200 (CEST) Subject: SUSE-IU-2026:7575-1: Recommended update of suse/sl-micro/6.2/kvm-os-container Message-ID: <20261001074100.37D43FD07@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/kvm-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7575-1 Image Tags : suse/sl-micro/6.2/kvm-os-container:2.3.1 , suse/sl-micro/6.2/kvm-os-container:2.3.1-8.151 , suse/sl-micro/6.2/kvm-os-container:latest Image Release : 8.151 Severity : moderate Type : recommended References : 1282301 ----------------------------------------------------------------- The container suse/sl-micro/6.2/kvm-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1792 Released: Wed Sep 30 17:02:45 2026 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate References: 1282301 This update for jitterentropy fixes the following issues: Changes in jitterentropy: - OSR has to be at least 5 according to current reviews. (bsc#1282301) The following package changes have been done: - libjitterentropy3-3.6.3-160000.3.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-a5647c3cae0c0839b551730820eff1188dabdddc0129403d4000a751b762739c-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:51:34 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:51:34 +0200 (CEST) Subject: SUSE-IU-2026:7583-1: Security update of suse/sl-micro/6.2/rt-os-container Message-ID: <20261001075134.29B17FCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7583-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.193 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.193 Severity : moderate Type : security References : 1272206 CVE-2026-15588 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1788 Released: Wed Sep 30 11:45:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - libglib-2_0-0-2.84.4-160000.5.1 updated - libgobject-2_0-0-2.84.4-160000.5.1 updated - libgmodule-2_0-0-2.84.4-160000.5.1 updated - libgio-2_0-0-2.84.4-160000.5.1 updated - glib2-tools-2.84.4-160000.5.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-9d1db63e206c5e5ca16ae32ca65d7734b731bf2fdf81dad8900b5f153b1921ce-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 07:51:38 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 09:51:38 +0200 (CEST) Subject: SUSE-IU-2026:7584-1: Recommended update of suse/sl-micro/6.2/rt-os-container Message-ID: <20261001075138.32B30FD07@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/rt-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7584-1 Image Tags : suse/sl-micro/6.2/rt-os-container:2.3.1 , suse/sl-micro/6.2/rt-os-container:2.3.1-7.194 , suse/sl-micro/6.2/rt-os-container:latest Image Release : 7.194 Severity : moderate Type : recommended References : 1282301 ----------------------------------------------------------------- The container suse/sl-micro/6.2/rt-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1792 Released: Wed Sep 30 17:02:45 2026 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate References: 1282301 This update for jitterentropy fixes the following issues: Changes in jitterentropy: - OSR has to be at least 5 according to current reviews. (bsc#1282301) The following package changes have been done: - libjitterentropy3-3.6.3-160000.3.1 updated - container:suse-sl-micro-6.2-baremetal-os-container-latest-754e6d46b385bef46c2c153543259c5e99c90595982a9d0fb840dc0665d4af54-0 updated From sle-container-updates at lists.suse.com Thu Oct 1 08:22:13 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 10:22:13 +0200 (CEST) Subject: SUSE-CU-2026:11338-1: Security update of suse/sles/16.0/toolbox Message-ID: <20261001082213.AF9D7FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11338-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.131 , suse/sles/16.0/toolbox:latest Container Release : 1.131 Severity : moderate Type : security References : 1272206 1279961 CVE-2026-15588 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1790 Released: Wed Sep 30 11:29:23 2026 Summary: Recommended update for ca-certificates-mozilla Type: recommended Severity: moderate References: 1279961 This update for ca-certificates-mozilla fixes the following issues: Changes in ca-certificates-mozilla: - Updated to 2.90 state (bsc#1279961): * Removed: + AffirmTrust Commercial + AffirmTrust Networking + AffirmTrust Premium + AffirmTrust Premium ECC + certSIGN ROOT CA + Entrust Root Certification Authority + PKI Root Certification Authority + FIRMAPROFESIONAL CA ROOT-A WEB + GLOBALTRUST 2020 + Secure Global CA + SecureSign Root CA12 + SecureTrust CA + TeliaSonera Root CA v1 + Trustwave Global Certification Authority + Trustwave Global ECC P256 Certification Authority + Trustwave Global ECC P384 Certification Authority + XRamp Global Certification Authority * Added: + SECOM SMIME RSA Root CA 2024 + SECOM TLS ECC Root CA 2024 + SECOM TLS RSA Root CA 2024 + SecureSign Root CA16 + Telia EC Email Root CA v3 + Telia EC TLS Root CA v3 + Telia RSA Email Root CA v3 + Telia RSA TLS Root CA v3 ----------------------------------------------------------------- Advisory ID: 1788 Released: Wed Sep 30 11:45:44 2026 Summary: Security update for glib2 Type: security Severity: moderate References: 1272206,CVE-2026-15588 This update for glib2 fixes the following issue: - CVE-2026-15588: GDBusServer pre-authentication DoS via unbounded SASL line buffering (bsc#1272206). The following package changes have been done: - ca-certificates-mozilla-2.90-160000.1.1 updated - libglib-2_0-0-2.84.4-160000.5.1 updated - libgmodule-2_0-0-2.84.4-160000.5.1 updated From sle-container-updates at lists.suse.com Thu Oct 1 08:22:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Thu, 1 Oct 2026 10:22:15 +0200 (CEST) Subject: SUSE-CU-2026:11339-1: Recommended update of suse/sles/16.0/toolbox Message-ID: <20261001082215.1F646FD07@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11339-1 Container Tags : suse/sles/16.0/toolbox:16.3 , suse/sles/16.0/toolbox:16.3-1.132 , suse/sles/16.0/toolbox:latest Container Release : 1.132 Severity : moderate Type : recommended References : 1282301 ----------------------------------------------------------------- The container suse/sles/16.0/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1792 Released: Wed Sep 30 17:02:45 2026 Summary: Recommended update for jitterentropy Type: recommended Severity: moderate References: 1282301 This update for jitterentropy fixes the following issues: Changes in jitterentropy: - OSR has to be at least 5 according to current reviews. (bsc#1282301) The following package changes have been done: - libjitterentropy3-3.6.3-160000.3.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 07:16:10 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 09:16:10 +0200 (CEST) Subject: SUSE-IU-2026:7606-1: Recommended update of suse/sl-micro/6.2/baremetal-os-container Message-ID: <20261002071610.46606FCFE@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/baremetal-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7606-1 Image Tags : suse/sl-micro/6.2/baremetal-os-container:2.3.1 , suse/sl-micro/6.2/baremetal-os-container:2.3.1-8.170 , suse/sl-micro/6.2/baremetal-os-container:latest Image Release : 8.170 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sl-micro/6.2/baremetal-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1797 Released: Thu Oct 1 11:31:51 2026 Summary: Recommended update for dracut Type: recommended Severity: moderate References: This update for dracut fixes the following issues: Changes in dracut: - Support NTP configuration for airgapped scenarios (jsc#PED-16110) - Allow to easily apply CC compliant configuration when deploying SLES 16.0 (jsc#PED-16702) * feat(chrony): introducing the chrony module * feat(network-manager): write info about NTP servers in dhcpopts file The following package changes have been done: - dracut-059+suse.732.g39fc900f5-160000.1.1 updated - container:suse-sl-micro-6.2-base-os-container-latest-7169ff8d98b1b7557fb24121a109aac9e5db9b9034543cb2e6b28d8c05fafe1f-0 updated From sle-container-updates at lists.suse.com Fri Oct 2 07:26:50 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 09:26:50 +0200 (CEST) Subject: SUSE-IU-2026:7609-1: Recommended update of suse/sl-micro/6.2/base-os-container Message-ID: <20261002072650.DC81EFCF8@maintenance.suse.de> SUSE Image Update Advisory: suse/sl-micro/6.2/base-os-container ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2026:7609-1 Image Tags : suse/sl-micro/6.2/base-os-container:2.3.1 , suse/sl-micro/6.2/base-os-container:2.3.1-8.90 , suse/sl-micro/6.2/base-os-container:latest Image Release : 8.90 Severity : moderate Type : recommended References : ----------------------------------------------------------------- The container suse/sl-micro/6.2/base-os-container was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1797 Released: Thu Oct 1 11:31:51 2026 Summary: Recommended update for dracut Type: recommended Severity: moderate References: This update for dracut fixes the following issues: Changes in dracut: - Support NTP configuration for airgapped scenarios (jsc#PED-16110) - Allow to easily apply CC compliant configuration when deploying SLES 16.0 (jsc#PED-16702) * feat(chrony): introducing the chrony module * feat(network-manager): write info about NTP servers in dhcpopts file The following package changes have been done: - dracut-059+suse.732.g39fc900f5-160000.1.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:02:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:02:15 +0200 (CEST) Subject: SUSE-CU-2026:11348-1: Security update of bci/bci-base-fips Message-ID: <20261002080215.EDB13FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base-fips ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11348-1 Container Tags : bci/bci-base-fips:16.0 , bci/bci-base-fips:16.0-20.12 Container Release : 20.12 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container bci/bci-base-fips was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:03:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:03:00 +0200 (CEST) Subject: SUSE-CU-2026:11349-1: Security update of bci/bci-base Message-ID: <20261002080300.2D7A0FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-base ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11349-1 Container Tags : bci/bci-base:16.0 , bci/bci-base:16.0-23.9 Container Release : 23.9 Severity : important Type : security References : 1271272 1274723 1274726 1276892 1276946 1277247 1277262 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1277921 1277922 1279541 1279893 1280049 1280050 1280051 1280052 1280053 1280054 1280941 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container bci/bci-base was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) ----------------------------------------------------------------- Advisory ID: 1766 Released: Mon Sep 28 12:03:37 2026 Summary: Recommended update for libzypp, libsolv Type: recommended Severity: moderate References: 1279541 This update for libzypp, libsolv fixes the following issues: Changes in libzypp: version 17.38.16 (35): - This fix resolves issues in online migrations to SLES 16.1. (bsc#1279541) Changes in libsolv: bump version to 0.7.39: - improve SUSE product link dependency generation if there are multiple release packages for the same product [bsc#1279541] - fix possible segfault in the SUSE namespace dependency generation ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-locale-base-2.40-160000.7.1 updated - glibc-2.40-160000.7.1 updated - libpcre2-8-0-10.45-160000.4.1 updated - libsolv-tools-base-0.7.40-160000.1.1 updated - libzypp-17.38.16-160000.1.1 updated - skelcd-EULA-BCI-20250701-160000.3.32 updated - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:03:35 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:03:35 +0200 (CEST) Subject: SUSE-CU-2026:11351-1: Recommended update of suse/sles/16.0/cdi-cloner Message-ID: <20261002080335.1B433FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-cloner ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11351-1 Container Tags : suse/sles/16.0/cdi-cloner:1.65 , suse/sles/16.0/cdi-cloner:1.65.0 , suse/sles/16.0/cdi-cloner:1.65.0-6.15 Container Release : 6.15 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-cloner was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:04:28 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:04:28 +0200 (CEST) Subject: SUSE-CU-2026:11353-1: Recommended update of suse/sles/16.0/cdi-importer Message-ID: <20261002080428.93857FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-importer ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11353-1 Container Tags : suse/sles/16.0/cdi-importer:1.65 , suse/sles/16.0/cdi-importer:1.65.0 , suse/sles/16.0/cdi-importer:1.65.0-6.15 Container Release : 6.15 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-importer was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:05:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:05:42 +0200 (CEST) Subject: SUSE-CU-2026:11356-1: Recommended update of suse/sles/16.0/cdi-uploadserver Message-ID: <20261002080542.752CCFCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11356-1 Container Tags : suse/sles/16.0/cdi-uploadserver:1.65 , suse/sles/16.0/cdi-uploadserver:1.65.0 , suse/sles/16.0/cdi-uploadserver:1.65.0-6.15 Container Release : 6.15 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:05:56 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:05:56 +0200 (CEST) Subject: SUSE-CU-2026:11358-1: Recommended update of suse/sles/16.0/cdi-cloner Message-ID: <20261002080556.62700FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-cloner ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11358-1 Container Tags : suse/sles/16.0/cdi-cloner:1.66 , suse/sles/16.0/cdi-cloner:1.66.1 , suse/sles/16.0/cdi-cloner:1.66.1-1.5 Container Release : 1.5 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-cloner was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:06:15 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:06:15 +0200 (CEST) Subject: SUSE-CU-2026:11360-1: Recommended update of suse/sles/16.0/cdi-importer Message-ID: <20261002080615.BD30FFCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-importer ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11360-1 Container Tags : suse/sles/16.0/cdi-importer:1.66 , suse/sles/16.0/cdi-importer:1.66.1 , suse/sles/16.0/cdi-importer:1.66.1-1.5 Container Release : 1.5 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-importer was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:06:48 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:06:48 +0200 (CEST) Subject: SUSE-CU-2026:11363-1: Recommended update of suse/sles/16.0/cdi-uploadserver Message-ID: <20261002080648.7CE4CFCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/cdi-uploadserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11363-1 Container Tags : suse/sles/16.0/cdi-uploadserver:1.66 , suse/sles/16.0/cdi-uploadserver:1.66.1 , suse/sles/16.0/cdi-uploadserver:1.66.1-1.5 Container Release : 1.5 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/cdi-uploadserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:09:25 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:09:25 +0200 (CEST) Subject: SUSE-CU-2026:11364-1: Security update of suse/cosign Message-ID: <20261002080925.0D2E8FCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/cosign ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11364-1 Container Tags : suse/cosign:3 , suse/cosign:3.1 , suse/cosign:3.1.2 , suse/cosign:3.1.2-3.12 , suse/cosign:latest Container Release : 3.12 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277921 1277922 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container suse/cosign was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:10:06 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:10:06 +0200 (CEST) Subject: SUSE-CU-2026:11365-1: Security update of suse/registry Message-ID: <20261002081006.3DF7AFCFE@maintenance.suse.de> SUSE Container Update Advisory: suse/registry ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11365-1 Container Tags : suse/registry:3.1 , suse/registry:3.1 , suse/registry:3.1-7.16 , suse/registry:latest Container Release : 7.16 Severity : important Type : security References : 1252972 1262263 1264713 1267631 1268572 1268573 1273203 1275096 1275594 1275732 1275859 1275860 1275915 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/registry was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1779 Released: Tue Sep 29 18:31:02 2026 Summary: Recommended update for apache2 Type: recommended Severity: moderate References: 1252972,1273203 This update for apache2 fixes the following issues: Changes in apache2: - Rename the worker and event 'mod_cgi' entries to 'mod_cgid' in loadmodule.conf, as that is what the threaded MPMs ship. - Fix: apache2: loadmodule.conf still loads mod_cgi for the worker MPM (relates to bsc#1252972) - httpd -t fails (bsc#1273203) The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - apache2-utils-2.4.66-160000.4.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:10:51 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:10:51 +0200 (CEST) Subject: SUSE-CU-2026:11366-1: Security update of bci/gcc Message-ID: <20261002081051.9412BFCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/gcc ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11366-1 Container Tags : bci/gcc:15 , bci/gcc:15.3 , bci/gcc:15.3-13.25 Container Release : 13.25 Severity : critical Type : security References : 1261606 1262263 1264713 1267631 1268572 1268573 1268886 1269583 1270219 1274723 1274726 1275096 1275441 1275594 1275732 1275859 1275860 1275915 1276892 1276946 1277247 1277262 1277919 1277921 1277922 1278347 1278348 1278349 1281297 1282509 CVE-2026-13595 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-27456 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-6368 CVE-2026-66046 CVE-2026-6791 CVE-2026-72522 CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957 CVE-2026-77117 CVE-2026-78408 CVE-2026-78410 CVE-2026-80489 CVE-2026-8674 CVE-2026-86805 ----------------------------------------------------------------- The container bci/gcc was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libatomic1-16.2.0+git9497-160000.2.1 updated - libasan8-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libexpat1-2.8.4-160000.1.1 updated - libgomp1-16.2.0+git9497-160000.2.1 updated - libhwasan0-16.2.0+git9497-160000.2.1 updated - libitm1-16.2.0+git9497-160000.2.1 updated - liblsan0-16.2.0+git9497-160000.2.1 updated - libquadmath0-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libtsan2-16.2.0+git9497-160000.2.1 updated - libubsan1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libquadmath0-devel-gcc15-15.3.0+git11272-160000.2.1 updated - libgfortran5-16.2.0+git9497-160000.2.1 updated - libfdisk1-2.41.1-160000.5.1 updated - cpp15-15.3.0+git11272-160000.2.1 updated - util-linux-2.41.1-160000.5.1 updated - glibc-devel-2.40-160000.7.1 updated - libstdc++6-devel-gcc15-15.3.0+git11272-160000.2.1 updated - gcc15-15.3.0+git11272-160000.2.1 updated - gcc15-fortran-15.3.0+git11272-160000.2.1 updated - gcc15-c++-15.3.0+git11272-160000.2.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:11:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:11:44 +0200 (CEST) Subject: SUSE-CU-2026:11367-1: Security update of bci/kiwi Message-ID: <20261002081144.C3F25FCFE@maintenance.suse.de> SUSE Container Update Advisory: bci/kiwi ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11367-1 Container Tags : bci/kiwi:10 , bci/kiwi:10.2 , bci/kiwi:10.2.33 , bci/kiwi:10.2.33-20.12 Container Release : 20.12 Severity : critical Type : security References : 1261606 1262263 1262698 1264713 1266262 1267631 1268572 1268573 1268886 1269583 1270219 1274723 1274726 1275096 1275441 1275441 1275594 1275732 1275859 1275860 1275915 1276892 1276946 1277247 1277262 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1277919 1277921 1277922 1278347 1278348 1278349 1279863 1279893 1280049 1280050 1280051 1280052 1280053 1280054 1281297 1282509 CVE-2026-13595 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-27456 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-6368 CVE-2026-66046 CVE-2026-6791 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957 CVE-2026-77117 CVE-2026-78408 CVE-2026-78410 CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container bci/kiwi was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1722 Released: Mon Sep 21 11:58:27 2026 Summary: Recommended update for mozilla-nss Type: recommended Severity: moderate References: 1262698,1266262,1279863 This update for mozilla-nss fixes the following issues: Changes in mozilla-nss: - Fix potential crash when verifying password length in PBKDF2 (boo#1279863) - Fix upper bound to allow FIPS approval for P-521. - Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). - Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. - Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1746 Released: Wed Sep 23 13:57:24 2026 Summary: Recommended update for python-kiwi Type: recommended Severity: moderate References: This update for python-kiwi fixes the following issues: Changes in python-kiwi: - Fix LUKS header checksum reference for reencryption The origin LUKS header checksum stored in /root/.luks.header is used by the kiwi dracut code to decide if the initial reencryption of the root device should happen. The checksum is calculated over the header backup file which is at the same time the file the resulting checksum gets written to. Since the checksum handler returned by get_checksum_handler() calculates the digest lazily when digest() is called, and the call happened inside the open(..., 'w') context, the header backup was already truncated at that point. The stored reference was therefore always the digest of an empty file (e3b0c442... for sha256) and could never match the digest calculated at boot time. As a consequence reencrypt_luks() silently skipped the reencryption and the image stayed encrypted with the build time credentials. Calculate the digest before the file is opened for writing. ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - cpp15-15.3.0+git11272-160000.2.1 updated - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - glibc-gconv-modules-extra-2.40-160000.7.1 updated - libasan8-16.2.0+git9497-160000.2.1 updated - libatomic1-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libexpat1-2.8.4-160000.1.1 updated - libfreebl3-3.125-160000.2.1 updated - libgomp1-16.2.0+git9497-160000.2.1 updated - libhwasan0-16.2.0+git9497-160000.2.1 updated - libitm1-16.2.0+git9497-160000.2.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - liblastlog2-2-2.41.1-160000.5.1 updated - liblsan0-16.2.0+git9497-160000.2.1 updated - libpcre2-16-0-10.45-160000.4.1 updated - libpcre2-32-0-10.45-160000.4.1 updated - libpcre2-posix3-10.45-160000.4.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libtsan2-16.2.0+git9497-160000.2.1 updated - libubsan1-16.2.0+git9497-160000.2.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - libfdisk1-2.41.1-160000.5.1 updated - mozilla-nss-certs-3.125-160000.2.1 updated - kbd-2.7.1-160000.3.1 updated - mozilla-nss-3.125-160000.2.1 updated - libsoftokn3-3.125-160000.2.1 updated - util-linux-2.41.1-160000.5.1 updated - glibc-devel-2.40-160000.7.1 updated - libblkid-devel-2.41.1-160000.5.1 updated - kiwi-systemdeps-core-10.2.33-160000.7.1 updated - util-linux-systemd-2.41.1-160000.5.1 updated - libstdc++6-devel-gcc15-15.3.0+git11272-160000.2.1 updated - gcc15-15.3.0+git11272-160000.2.1 updated - python3-kiwi-10.2.33-160000.7.1 updated - dracut-kiwi-lib-10.2.33-160000.7.1 updated - kiwi-systemdeps-filesystems-10.2.33-160000.7.1 updated - dracut-kiwi-oem-repart-10.2.33-160000.7.1 updated - pcre2-devel-10.45-160000.4.1 updated - libmount-devel-2.41.1-160000.5.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:13:29 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:13:29 +0200 (CEST) Subject: SUSE-CU-2026:11371-1: Recommended update of suse/sles/16.0/virt-exportserver Message-ID: <20261002081329.D3EC7FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-exportserver ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11371-1 Container Tags : suse/sles/16.0/virt-exportserver:1.8 , suse/sles/16.0/virt-exportserver:1.8.4 , suse/sles/16.0/virt-exportserver:1.8.4-11.6 Container Release : 11.6 Severity : moderate Type : recommended References : 1271272 1280941 ----------------------------------------------------------------- The container suse/sles/16.0/virt-exportserver was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - tar-1.35-160000.5.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:14:16 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:14:16 +0200 (CEST) Subject: SUSE-CU-2026:11372-1: Security update of suse/sles/16.0/virt-handler Message-ID: <20261002081416.7CCCBFCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-handler ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11372-1 Container Tags : suse/sles/16.0/virt-handler:1.8 , suse/sles/16.0/virt-handler:1.8.4 , suse/sles/16.0/virt-handler:1.8.4-11.6 Container Release : 11.6 Severity : important Type : security References : 1262263 1264713 1267631 1268572 1268573 1271272 1275096 1275441 1275594 1275732 1275859 1275860 1275915 1280941 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 ----------------------------------------------------------------- The container suse/sles/16.0/virt-handler was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - tar-1.35-160000.5.1 updated - kbd-2.7.1-160000.3.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:14:42 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:14:42 +0200 (CEST) Subject: SUSE-CU-2026:11373-1: Security update of suse/sles/16.0/virt-launcher Message-ID: <20261002081442.57C79FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/virt-launcher ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11373-1 Container Tags : suse/sles/16.0/virt-launcher:1.8 , suse/sles/16.0/virt-launcher:1.8.4 , suse/sles/16.0/virt-launcher:1.8.4-11.6 Container Release : 11.6 Severity : important Type : security References : 1262263 1264713 1265974 1267631 1268572 1268573 1271272 1275096 1275441 1275594 1275732 1275859 1275860 1275915 1279561 1279584 1279588 1279593 1279595 1279782 1279783 1279784 1279843 1280108 1280884 1280910 1280941 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313 CVE-2026-31911 CVE-2026-31912 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-6244 CVE-2026-6554 CVE-2026-66046 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 CVE-2026-88806 ----------------------------------------------------------------- The container suse/sles/16.0/virt-launcher was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1736 Released: Tue Sep 22 13:11:46 2026 Summary: Security update for libX11 Type: security Severity: important References: 1280910,CVE-2026-88806 This update for libX11 fixes the following issue: - CVE-2026-88806: XkbGetMap Reply Heap-based Buffer Overflow (bsc#1280910). ----------------------------------------------------------------- Advisory ID: 1741 Released: Wed Sep 23 11:15:05 2026 Summary: Recommended update for libvirt Type: recommended Severity: important References: 1265974,1279561,1279843,1280884 This update for libvirt fixes the following issues: Changes in libvirt: - qemu: * Fix missing audit record and shutdown lifecycle event of VMs with shutdown times exceeding 40 seconds (bsc#1280884) * Fix cleanup of VMs with shutdown times exceeding 40 seconds (bsc#1265974) * Fix incoming migration to QEMU 10.0.0 and newer (bsc#1279843) * Fix hot plugged host CPUs not being used (bsc#1279561) ----------------------------------------------------------------- Advisory ID: 1749 Released: Wed Sep 23 21:44:23 2026 Summary: Security update for libpcap Type: security Severity: important References: 1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554 This update for libpcap fixes the following issues: - CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). - CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). - CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). - CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). - CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). - CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). - CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1756 Released: Thu Sep 24 11:47:49 2026 Summary: Recommended update for ovmf Type: recommended Severity: moderate References: 1280108 This update for ovmf fixes the following issues: Changes in ovmf: - Add unversioned 'virt' machine in riscv64 ovmf descriptor (bsc#1280108) ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - libX11-data-1.8.10-160000.4.1 updated - libexpat1-2.8.4-160000.1.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - libX11-6-1.8.10-160000.4.1 updated - tar-1.35-160000.5.1 updated - kbd-2.7.1-160000.3.1 updated - libpcap1-1.10.5-160000.5.1 updated - libvirt-libs-11.4.0-160000.6.1 updated - libvirt-daemon-log-11.4.0-160000.6.1 updated - libvirt-client-11.4.0-160000.6.1 updated - libvirt-daemon-common-11.4.0-160000.6.1 updated - qemu-ovmf-x86_64-202502-160000.8.1 updated - libvirt-daemon-driver-qemu-11.4.0-160000.6.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:15:00 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:15:00 +0200 (CEST) Subject: SUSE-CU-2026:11374-1: Security update of suse/sles/16.0/libguestfs-tools Message-ID: <20261002081500.7C8F1FCF8@maintenance.suse.de> SUSE Container Update Advisory: suse/sles/16.0/libguestfs-tools ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11374-1 Container Tags : suse/sles/16.0/libguestfs-tools:1.8 , suse/sles/16.0/libguestfs-tools:1.8.4 , suse/sles/16.0/libguestfs-tools:1.8.4-11.6 Container Release : 11.6 Severity : important Type : security References : 1262263 1264713 1265974 1267631 1268572 1268573 1271272 1275096 1275441 1275516 1275594 1275732 1275859 1275860 1275915 1279561 1279843 1280108 1280884 1280910 1280941 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 CVE-2026-88806 ----------------------------------------------------------------- The container suse/sles/16.0/libguestfs-tools was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1736 Released: Tue Sep 22 13:11:46 2026 Summary: Security update for libX11 Type: security Severity: important References: 1280910,CVE-2026-88806 This update for libX11 fixes the following issue: - CVE-2026-88806: XkbGetMap Reply Heap-based Buffer Overflow (bsc#1280910). ----------------------------------------------------------------- Advisory ID: 1741 Released: Wed Sep 23 11:15:05 2026 Summary: Recommended update for libvirt Type: recommended Severity: important References: 1265974,1279561,1279843,1280884 This update for libvirt fixes the following issues: Changes in libvirt: - qemu: * Fix missing audit record and shutdown lifecycle event of VMs with shutdown times exceeding 40 seconds (bsc#1280884) * Fix cleanup of VMs with shutdown times exceeding 40 seconds (bsc#1265974) * Fix incoming migration to QEMU 10.0.0 and newer (bsc#1279843) * Fix hot plugged host CPUs not being used (bsc#1279561) ----------------------------------------------------------------- Advisory ID: 1748 Released: Wed Sep 23 21:47:23 2026 Summary: Security update for kbd Type: security Severity: important References: 1275441,CVE-2026-72693 This update for kbd fixes the following issue: - CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 ----------------------------------------------------------------- Advisory ID: 1757 Released: Thu Sep 24 11:10:39 2026 Summary: Recommended update for dhcpcd Type: recommended Severity: moderate References: 1275516 This update for dhcpcd fixes the following issues: Changes in dhcpcd: - Fix: Instance initialization takes long due to (spurious) dhcpcd timeout (bsc#1275516): * privsep: Fix daemonising broken by RLIMIT_NOFILE of 0 ----------------------------------------------------------------- Advisory ID: 1756 Released: Thu Sep 24 11:47:49 2026 Summary: Recommended update for ovmf Type: recommended Severity: moderate References: 1280108 This update for ovmf fixes the following issues: Changes in ovmf: - Add unversioned 'virt' machine in riscv64 ovmf descriptor (bsc#1280108) ----------------------------------------------------------------- Advisory ID: 1762 Released: Fri Sep 25 11:09:47 2026 Summary: Recommended update for tar Type: recommended Severity: moderate References: 1271272,1280941 This update for tar fixes the following issues: Changes in tar: - Fixes tar incorrectly skipping members in certain archives containing dirs with non-zero sizes. (bsc#1271272) - Avoid acl_ prefix for functions: * The acl.h header from libacl uses acl_ prefix for its functions. Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941) The following package changes have been done: - libX11-data-1.8.10-160000.4.1 updated - libexpat1-2.8.4-160000.1.1 updated - libkbdfile1-2.7.1-160000.3.1 updated - libkfont0-2.7.1-160000.3.1 updated - libkeymap1-2.7.1-160000.3.1 updated - libX11-6-1.8.10-160000.4.1 updated - tar-1.35-160000.5.1 updated - kbd-2.7.1-160000.3.1 updated - dhcpcd-10.5.2-160000.2.1 updated - libvirt-libs-11.4.0-160000.6.1 updated - qemu-ovmf-x86_64-202502-160000.8.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:21:01 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:21:01 +0200 (CEST) Subject: SUSE-CU-2026:11375-1: Security update of bci/bci-micro Message-ID: <20261002082101.7622BFCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-micro ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11375-1 Container Tags : bci/bci-micro:16.0 , bci/bci-micro:16.0-22.13 Container Release : 22.13 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1277921 1277922 1279893 1280049 1280050 1280051 1280052 1280053 1280054 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container bci/bci-micro was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - skelcd-EULA-BCI-20250701-160000.3.32 updated - glibc-2.40-160000.7.1 updated - libpcre2-8-0-10.45-160000.4.1 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:21:44 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:21:44 +0200 (CEST) Subject: SUSE-CU-2026:11376-1: Security update of bci/bci-minimal Message-ID: <20261002082144.C9616FCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/bci-minimal ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11376-1 Container Tags : bci/bci-minimal:16.0 , bci/bci-minimal:16.0-18.14 Container Release : 18.14 Severity : important Type : security References : 1274723 1274726 1276892 1276946 1277247 1277262 1277707 1277708 1277709 1277710 1277711 1277712 1277713 1277921 1277922 1279893 1280049 1280050 1280051 1280052 1280053 1280054 1281297 1282509 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-6368 CVE-2026-6791 CVE-2026-77117 CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156 CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162 ----------------------------------------------------------------- The container bci/bci-minimal was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1747 Released: Wed Sep 23 21:42:24 2026 Summary: Security update for pcre2 Type: security Severity: important References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162 This update for pcre2 fixes the following issues: - CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). - CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). - CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). - CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). - CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). - CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). - CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049). ----------------------------------------------------------------- Advisory ID: 1769 Released: Tue Sep 29 14:25:10 2026 Summary: Security update for glibc Type: security Severity: important References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805 This update for glibc fixes the following issues: - CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). - CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). - CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to trigger a process crash (bsc#1281297). - CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). - CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). - CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). - CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). - CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). - CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges (bsc#1282509). Other changes: - Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247). The following package changes have been done: - glibc-2.40-160000.7.1 updated - libpcre2-8-0-10.45-160000.4.1 updated - skelcd-EULA-BCI-20250701-160000.3.32 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:22:36 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:22:36 +0200 (CEST) Subject: SUSE-CU-2026:11378-1: Security update of bci/nodejs Message-ID: <20261002082236.8E815FCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11378-1 Container Tags : bci/node:24 , bci/node:24-base , bci/node:24.18.1-base , bci/node:24.18.1-base-11.7 , bci/node:latest , bci/nodejs:24 , bci/nodejs:24-base , bci/nodejs:24.18.1-base , bci/nodejs:24.18.1-base-11.7 , bci/nodejs:latest Container Release : 11.7 Severity : critical Type : security References : 1261606 1262263 1264713 1267631 1268572 1268573 1268886 1269583 1270219 1275096 1275441 1275594 1275732 1275859 1275860 1275915 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libblkid1-2.41.1-160000.5.1 updated - libexpat1-2.8.4-160000.1.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated From sle-container-updates at lists.suse.com Fri Oct 2 08:22:54 2026 From: sle-container-updates at lists.suse.com (sle-container-updates at lists.suse.com) Date: Fri, 2 Oct 2026 10:22:54 +0200 (CEST) Subject: SUSE-CU-2026:11379-1: Security update of bci/nodejs Message-ID: <20261002082254.7C226FCF8@maintenance.suse.de> SUSE Container Update Advisory: bci/nodejs ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2026:11379-1 Container Tags : bci/node:24-micro , bci/node:24.18.1-micro , bci/node:24.18.1-micro-11.7 , bci/nodejs:24-micro , bci/nodejs:24.18.1-micro , bci/nodejs:24.18.1-micro-11.7 Container Release : 11.7 Severity : critical Type : security References : 1261606 1262263 1264713 1267631 1268572 1268573 1268886 1269583 1270219 1275096 1275441 1275594 1275732 1275859 1275860 1275915 1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522 CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957 CVE-2026-78408 CVE-2026-78410 ----------------------------------------------------------------- The container bci/nodejs was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: 1707 Released: Fri Sep 18 18:31:02 2026 Summary: Recommended update for gcc15, gcc16 Type: recommended Severity: critical References: 1277919 This update for gcc15, gcc16 fixes the following issues: Changes in gcc15: - Rebuild to rename library packages after the switch to gcc16 libraries. Changes in gcc16: - Fix build reproducability when PCH is used. - Fix auto-detection of Zen6 [bsc#1277919] - Remove support for s390 (32bit), make sure to configure s390x with --disable-multilib to avoid configury error without explicit disable of multilibs. Support for s390 is officially deprecated. ----------------------------------------------------------------- Advisory ID: 1733 Released: Tue Sep 22 09:23:33 2026 Summary: Security update for util-linux Type: security Severity: important References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410 This update for util-linux fixes the following issues: - CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). - CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). - CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). - CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). - CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). - CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). - CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). - CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: - lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) - lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value - lib/fileutils: fix unused parameter warnings without SYS_openat2 - libmount: add missing fileutils.h include to hook_idmap.c - libmount: add mnt_open_tree() helper for safe tree opening - libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) - libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) - libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook - nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) - nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) - wall, write: sanitize hostname in banner header (bsc#1275441) - Add missing function. (bsc#1275441) - ipcutils: Prevent using uninitialized variable (bsc#1268886) - BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. - INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. - liblastlog2: Wait on busy SQLite connections (bsc#1268886). - libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). - libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) - libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). - fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). - libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). - libmount: ignore X-mount.nocanonicalize for restricted users - libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). - libmount: restrict X-mount.subdir for non-root (bsc#1268886). - libmount: use fd_target in hook_idmap for move_mount() - libmount: add mount ID verification and man page TOCTOU note - loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). - Ignore pam-config error that prevents update failure if common* pam configuration is not symlink to common-*-pc (bsc#1270219). ----------------------------------------------------------------- Advisory ID: 1754 Released: Thu Sep 24 09:07:13 2026 Summary: Security update for expat Type: security Severity: important References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957 This update for expat fixes the following issues: - CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263). - CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input (bsc#1264713). - CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631). - CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation (bsc#1268572). - CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer overflows (bsc#1268573). - CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code execution (bsc#1275096). - CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary code execution (bsc#1275096). - CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and application crashes (bsc#1275096). - CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes (bsc#1275096). - CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and arbitrary file write conditions (bsc#1275096). - CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information disclosure, and potential code execution (bsc#1275096). - CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and denial of service (bsc#1275096). - CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free conditions and arbitrary code execution (bsc#1275096). - CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c (bsc#1275732). - CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same as high surrogates during Unicode processing (bsc#1275594). - CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption (bsc#1275915). - CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via crafted X (bsc#1275860). - CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859). Changes for expat: - Updated to version 2.8.4 The following package changes have been done: - libexpat1-2.8.4-160000.1.1 updated - libgcc_s1-16.2.0+git9497-160000.2.1 updated - libsmartcols1-2.41.1-160000.5.1 updated - libuuid1-2.41.1-160000.5.1 updated - libblkid1-2.41.1-160000.5.1 updated - libstdc++6-16.2.0+git9497-160000.2.1 updated - libmount1-2.41.1-160000.5.1 updated - libfdisk1-2.41.1-160000.5.1 updated - util-linux-2.41.1-160000.5.1 updated - container:bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated - container:registry.suse.com-bci-bci-micro-16.0-c81dbd9910af06c00ebbac8b6618001295122183e687d962ed4fd2a4c4e5140c-0 updated