SUSE-CU-2026:11374-1: Security update of suse/sles/16.0/libguestfs-tools
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Fri Oct 2 08:15:00 UTC 2026
SUSE Container Update Advisory: suse/sles/16.0/libguestfs-tools
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11374-1
Container Tags : suse/sles/16.0/libguestfs-tools:1.8 , suse/sles/16.0/libguestfs-tools:1.8.4 , suse/sles/16.0/libguestfs-tools:1.8.4-11.6
Container Release : 11.6
Severity : important
Type : security
References : 1262263 1264713 1265974 1267631 1268572 1268573 1271272 1275096
1275441 1275516 1275594 1275732 1275859 1275860 1275915 1279561
1279843 1280108 1280884 1280910 1280941 CVE-2026-41080 CVE-2026-45186
CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404
CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409
CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522
CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 CVE-2026-88806
-----------------------------------------------------------------
The container suse/sles/16.0/libguestfs-tools was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1736
Released: Tue Sep 22 13:11:46 2026
Summary: Security update for libX11
Type: security
Severity: important
References: 1280910,CVE-2026-88806
This update for libX11 fixes the following issue:
- CVE-2026-88806: XkbGetMap Reply Heap-based Buffer Overflow (bsc#1280910).
-----------------------------------------------------------------
Advisory ID: 1741
Released: Wed Sep 23 11:15:05 2026
Summary: Recommended update for libvirt
Type: recommended
Severity: important
References: 1265974,1279561,1279843,1280884
This update for libvirt fixes the following issues:
Changes in libvirt:
- qemu:
* Fix missing audit record and shutdown lifecycle event of
VMs with shutdown times exceeding 40 seconds (bsc#1280884)
* Fix cleanup of VMs with shutdown times exceeding 40 seconds (bsc#1265974)
* Fix incoming migration to QEMU 10.0.0 and newer (bsc#1279843)
* Fix hot plugged host CPUs not being used (bsc#1279561)
-----------------------------------------------------------------
Advisory ID: 1748
Released: Wed Sep 23 21:47:23 2026
Summary: Security update for kbd
Type: security
Severity: important
References: 1275441,CVE-2026-72693
This update for kbd fixes the following issue:
- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
`passwordless` root login (bsc#1275441).
-----------------------------------------------------------------
Advisory ID: 1754
Released: Thu Sep 24 09:07:13 2026
Summary: Security update for expat
Type: security
Severity: important
References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:
- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
(bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).
Changes for expat:
- Updated to version 2.8.4
-----------------------------------------------------------------
Advisory ID: 1757
Released: Thu Sep 24 11:10:39 2026
Summary: Recommended update for dhcpcd
Type: recommended
Severity: moderate
References: 1275516
This update for dhcpcd fixes the following issues:
Changes in dhcpcd:
- Fix: Instance initialization takes long due to (spurious) dhcpcd timeout (bsc#1275516):
* privsep: Fix daemonising broken by RLIMIT_NOFILE of 0
-----------------------------------------------------------------
Advisory ID: 1756
Released: Thu Sep 24 11:47:49 2026
Summary: Recommended update for ovmf
Type: recommended
Severity: moderate
References: 1280108
This update for ovmf fixes the following issues:
Changes in ovmf:
- Add unversioned 'virt' machine in riscv64 ovmf descriptor (bsc#1280108)
-----------------------------------------------------------------
Advisory ID: 1762
Released: Fri Sep 25 11:09:47 2026
Summary: Recommended update for tar
Type: recommended
Severity: moderate
References: 1271272,1280941
This update for tar fixes the following issues:
Changes in tar:
- Fixes tar incorrectly skipping members in certain archives containing
dirs with non-zero sizes. (bsc#1271272)
- Avoid acl_ prefix for functions:
* The acl.h header from libacl uses acl_ prefix for its functions.
Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941)
The following package changes have been done:
- libX11-data-1.8.10-160000.4.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libkbdfile1-2.7.1-160000.3.1 updated
- libkfont0-2.7.1-160000.3.1 updated
- libkeymap1-2.7.1-160000.3.1 updated
- libX11-6-1.8.10-160000.4.1 updated
- tar-1.35-160000.5.1 updated
- kbd-2.7.1-160000.3.1 updated
- dhcpcd-10.5.2-160000.2.1 updated
- libvirt-libs-11.4.0-160000.6.1 updated
- qemu-ovmf-x86_64-202502-160000.8.1 updated
More information about the sle-container-updates
mailing list