SUSE-CU-2026:11366-1: Security update of bci/gcc

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Oct 2 08:10:51 UTC 2026


SUSE Container Update Advisory: bci/gcc
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11366-1
Container Tags        : bci/gcc:15 , bci/gcc:15.3 , bci/gcc:15.3-13.25
Container Release     : 13.25
Severity              : critical
Type                  : security
References            : 1261606 1262263 1264713 1267631 1268572 1268573 1268886 1269583
                        1270219 1274723 1274726 1275096 1275441 1275594 1275732 1275859
                        1275860 1275915 1276892 1276946 1277247 1277262 1277919 1277921
                        1277922 1278347 1278348 1278349 1281297 1282509 CVE-2026-13595
                        CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-27456 CVE-2026-41080
                        CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613 CVE-2026-53614
                        CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405
                        CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410
                        CVE-2026-56411 CVE-2026-56412 CVE-2026-6368 CVE-2026-66046 CVE-2026-6791
                        CVE-2026-72522 CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957
                        CVE-2026-77117 CVE-2026-78408 CVE-2026-78410 CVE-2026-80489 CVE-2026-8674
                        CVE-2026-86805 
-----------------------------------------------------------------

The container bci/gcc was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1707
Released:    Fri Sep 18 18:31:02 2026
Summary:     Recommended update for gcc15, gcc16
Type:        recommended
Severity:    critical
References:  1277919
This update for gcc15, gcc16 fixes the following issues:

Changes in gcc15:

- Rebuild to rename library packages after the switch to gcc16
  libraries.

Changes in gcc16:

- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]

- Remove support for s390 (32bit), make sure to configure s390x with
  --disable-multilib to avoid configury error without explicit
  disable of multilibs.  Support for s390 is officially deprecated.

-----------------------------------------------------------------
Advisory ID: 1733
Released:    Tue Sep 22 09:23:33 2026
Summary:     Security update for util-linux
Type:        security
Severity:    important
References:  1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:

- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
  Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
  escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
  termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
  redirection (bsc#1278347).

Changes for util-linux:

- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
 (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
 users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
 (bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
 leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
 bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
 Paths must always be canonicalized for unprivileged users to
 ensure safe target resolution. X-mount.nocanonicalize is ignored
 for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
 X-mount.subdir: The safe detached subdirectory is no more
 supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
 (bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
 (bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
 mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
 (bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
 prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
 CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
 (bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
 pam configuration is not symlink to common-*-pc (bsc#1270219).

-----------------------------------------------------------------
Advisory ID: 1754
Released:    Thu Sep 24 09:07:13 2026
Summary:     Security update for expat
Type:        security
Severity:    important
References:  1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:

- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
  denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
  XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
  handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
  overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
  execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
  corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
  code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
  application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
  of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
  (bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
  arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
  disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
  denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
  conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
  storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
  as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
  memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
  insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
  crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).

Changes for expat:

- Updated to version 2.8.4

-----------------------------------------------------------------
Advisory ID: 1769
Released:    Tue Sep 29 14:25:10 2026
Summary:     Security update for glibc
Type:        security
Severity:    important
References:  1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805
This update for glibc fixes the following issues:

- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to
  trigger a process crash (bsc#1281297).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).
- CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges
  (bsc#1282509).

Other changes:

- Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247).


The following package changes have been done:

- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libstdc++6-16.2.0+git9497-160000.2.1 updated
- libatomic1-16.2.0+git9497-160000.2.1 updated
- libasan8-16.2.0+git9497-160000.2.1 updated
- libblkid1-2.41.1-160000.5.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libgomp1-16.2.0+git9497-160000.2.1 updated
- libhwasan0-16.2.0+git9497-160000.2.1 updated
- libitm1-16.2.0+git9497-160000.2.1 updated
- liblsan0-16.2.0+git9497-160000.2.1 updated
- libquadmath0-16.2.0+git9497-160000.2.1 updated
- libsmartcols1-2.41.1-160000.5.1 updated
- libtsan2-16.2.0+git9497-160000.2.1 updated
- libubsan1-16.2.0+git9497-160000.2.1 updated
- libuuid1-2.41.1-160000.5.1 updated
- libmount1-2.41.1-160000.5.1 updated
- libquadmath0-devel-gcc15-15.3.0+git11272-160000.2.1 updated
- libgfortran5-16.2.0+git9497-160000.2.1 updated
- libfdisk1-2.41.1-160000.5.1 updated
- cpp15-15.3.0+git11272-160000.2.1 updated
- util-linux-2.41.1-160000.5.1 updated
- glibc-devel-2.40-160000.7.1 updated
- libstdc++6-devel-gcc15-15.3.0+git11272-160000.2.1 updated
- gcc15-15.3.0+git11272-160000.2.1 updated
- gcc15-fortran-15.3.0+git11272-160000.2.1 updated
- gcc15-c++-15.3.0+git11272-160000.2.1 updated
- container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated


More information about the sle-container-updates mailing list