SUSE-CU-2026:11367-1: Security update of bci/kiwi
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Oct 2 08:11:44 UTC 2026
SUSE Container Update Advisory: bci/kiwi
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11367-1
Container Tags : bci/kiwi:10 , bci/kiwi:10.2 , bci/kiwi:10.2.33 , bci/kiwi:10.2.33-20.12
Container Release : 20.12
Severity : critical
Type : security
References : 1261606 1262263 1262698 1264713 1266262 1267631 1268572 1268573
1268886 1269583 1270219 1274723 1274726 1275096 1275441 1275441
1275594 1275732 1275859 1275860 1275915 1276892 1276946 1277247
1277262 1277707 1277708 1277709 1277710 1277711 1277712 1277713
1277919 1277921 1277922 1278347 1278348 1278349 1279863 1279893
1280049 1280050 1280051 1280052 1280053 1280054 1281297 1282509
CVE-2026-13595 CVE-2026-18374 CVE-2026-19499 CVE-2026-19542 CVE-2026-27456
CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613
CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404
CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409
CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-6368 CVE-2026-66046
CVE-2026-6791 CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76642
CVE-2026-76956 CVE-2026-76957 CVE-2026-77117 CVE-2026-78408 CVE-2026-78410
CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156
CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162
-----------------------------------------------------------------
The container bci/kiwi was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1707
Released: Fri Sep 18 18:31:02 2026
Summary: Recommended update for gcc15, gcc16
Type: recommended
Severity: critical
References: 1277919
This update for gcc15, gcc16 fixes the following issues:
Changes in gcc15:
- Rebuild to rename library packages after the switch to gcc16
libraries.
Changes in gcc16:
- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]
- Remove support for s390 (32bit), make sure to configure s390x with
--disable-multilib to avoid configury error without explicit
disable of multilibs. Support for s390 is officially deprecated.
-----------------------------------------------------------------
Advisory ID: 1722
Released: Mon Sep 21 11:58:27 2026
Summary: Recommended update for mozilla-nss
Type: recommended
Severity: moderate
References: 1262698,1266262,1279863
This update for mozilla-nss fixes the following issues:
Changes in mozilla-nss:
- Fix potential crash when verifying password length in PBKDF2 (boo#1279863)
- Fix upper bound to allow FIPS approval for P-521.
- Approve HKDF and key concatenation in the context of TLS. This enables approved TLS
1.3 channels with PQC (bsc#1262698).
- Don't consider unapproved algorithms for TLS 1.3 in FIPS mode.
- Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262).
-----------------------------------------------------------------
Advisory ID: 1733
Released: Tue Sep 22 09:23:33 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
redirection (bsc#1278347).
Changes for util-linux:
- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
(bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
(bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
Paths must always be canonicalized for unprivileged users to
ensure safe target resolution. X-mount.nocanonicalize is ignored
for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
X-mount.subdir: The safe detached subdirectory is no more
supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
(bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
(bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
(bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
(bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
pam configuration is not symlink to common-*-pc (bsc#1270219).
-----------------------------------------------------------------
Advisory ID: 1746
Released: Wed Sep 23 13:57:24 2026
Summary: Recommended update for python-kiwi
Type: recommended
Severity: moderate
References:
This update for python-kiwi fixes the following issues:
Changes in python-kiwi:
- Fix LUKS header checksum reference for reencryption
The origin LUKS header checksum stored in /root/.luks.header is
used by the kiwi dracut code to decide if the initial reencryption
of the root device should happen. The checksum is calculated over
the header backup file which is at the same time the file the
resulting checksum gets written to.
Since the checksum handler returned by get_checksum_handler()
calculates the digest lazily when digest() is called, and the
call happened inside the open(..., 'w') context, the header backup
was already truncated at that point. The stored reference was
therefore always the digest of an empty file
(e3b0c442... for sha256) and could never match the digest
calculated at boot time. As a consequence reencrypt_luks()
silently skipped the reencryption and the image stayed encrypted
with the build time credentials.
Calculate the digest before the file is opened for writing.
-----------------------------------------------------------------
Advisory ID: 1747
Released: Wed Sep 23 21:42:24 2026
Summary: Security update for pcre2
Type: security
Severity: important
References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162
This update for pcre2 fixes the following issues:
- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).
- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).
- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject
(bsc#1280051).
- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`
(bsc#1280050).
- CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049).
-----------------------------------------------------------------
Advisory ID: 1748
Released: Wed Sep 23 21:47:23 2026
Summary: Security update for kbd
Type: security
Severity: important
References: 1275441,CVE-2026-72693
This update for kbd fixes the following issue:
- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
`passwordless` root login (bsc#1275441).
-----------------------------------------------------------------
Advisory ID: 1754
Released: Thu Sep 24 09:07:13 2026
Summary: Security update for expat
Type: security
Severity: important
References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:
- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
(bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).
Changes for expat:
- Updated to version 2.8.4
-----------------------------------------------------------------
Advisory ID: 1769
Released: Tue Sep 29 14:25:10 2026
Summary: Security update for glibc
Type: security
Severity: important
References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805
This update for glibc fixes the following issues:
- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to
trigger a process crash (bsc#1281297).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).
- CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges
(bsc#1282509).
Other changes:
- Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247).
The following package changes have been done:
- cpp15-15.3.0+git11272-160000.2.1 updated
- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libstdc++6-16.2.0+git9497-160000.2.1 updated
- glibc-gconv-modules-extra-2.40-160000.7.1 updated
- libasan8-16.2.0+git9497-160000.2.1 updated
- libatomic1-16.2.0+git9497-160000.2.1 updated
- libblkid1-2.41.1-160000.5.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libfreebl3-3.125-160000.2.1 updated
- libgomp1-16.2.0+git9497-160000.2.1 updated
- libhwasan0-16.2.0+git9497-160000.2.1 updated
- libitm1-16.2.0+git9497-160000.2.1 updated
- libkbdfile1-2.7.1-160000.3.1 updated
- liblastlog2-2-2.41.1-160000.5.1 updated
- liblsan0-16.2.0+git9497-160000.2.1 updated
- libpcre2-16-0-10.45-160000.4.1 updated
- libpcre2-32-0-10.45-160000.4.1 updated
- libpcre2-posix3-10.45-160000.4.1 updated
- libsmartcols1-2.41.1-160000.5.1 updated
- libtsan2-16.2.0+git9497-160000.2.1 updated
- libubsan1-16.2.0+git9497-160000.2.1 updated
- libuuid1-2.41.1-160000.5.1 updated
- libmount1-2.41.1-160000.5.1 updated
- libkfont0-2.7.1-160000.3.1 updated
- libkeymap1-2.7.1-160000.3.1 updated
- libfdisk1-2.41.1-160000.5.1 updated
- mozilla-nss-certs-3.125-160000.2.1 updated
- kbd-2.7.1-160000.3.1 updated
- mozilla-nss-3.125-160000.2.1 updated
- libsoftokn3-3.125-160000.2.1 updated
- util-linux-2.41.1-160000.5.1 updated
- glibc-devel-2.40-160000.7.1 updated
- libblkid-devel-2.41.1-160000.5.1 updated
- kiwi-systemdeps-core-10.2.33-160000.7.1 updated
- util-linux-systemd-2.41.1-160000.5.1 updated
- libstdc++6-devel-gcc15-15.3.0+git11272-160000.2.1 updated
- gcc15-15.3.0+git11272-160000.2.1 updated
- python3-kiwi-10.2.33-160000.7.1 updated
- dracut-kiwi-lib-10.2.33-160000.7.1 updated
- kiwi-systemdeps-filesystems-10.2.33-160000.7.1 updated
- dracut-kiwi-oem-repart-10.2.33-160000.7.1 updated
- pcre2-devel-10.45-160000.4.1 updated
- libmount-devel-2.41.1-160000.5.1 updated
- container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated
More information about the sle-container-updates
mailing list