SUSE-CU-2026:11378-1: Security update of bci/nodejs

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Fri Oct 2 08:22:36 UTC 2026


SUSE Container Update Advisory: bci/nodejs
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11378-1
Container Tags        : bci/node:24 , bci/node:24-base , bci/node:24.18.1-base , bci/node:24.18.1-base-11.7 , bci/node:latest , bci/nodejs:24 , bci/nodejs:24-base , bci/nodejs:24.18.1-base , bci/nodejs:24.18.1-base-11.7 , bci/nodejs:latest
Container Release     : 11.7
Severity              : critical
Type                  : security
References            : 1261606 1262263 1264713 1267631 1268572 1268573 1268886 1269583
                        1270219 1275096 1275441 1275594 1275732 1275859 1275860 1275915
                        1277919 1278347 1278348 1278349 CVE-2026-13595 CVE-2026-27456
                        CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-53612 CVE-2026-53613
                        CVE-2026-53614 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404
                        CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409
                        CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-66046 CVE-2026-72522
                        CVE-2026-76641 CVE-2026-76642 CVE-2026-76956 CVE-2026-76957 CVE-2026-78408
                        CVE-2026-78410 
-----------------------------------------------------------------

The container bci/nodejs was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1707
Released:    Fri Sep 18 18:31:02 2026
Summary:     Recommended update for gcc15, gcc16
Type:        recommended
Severity:    critical
References:  1277919
This update for gcc15, gcc16 fixes the following issues:

Changes in gcc15:

- Rebuild to rename library packages after the switch to gcc16
  libraries.

Changes in gcc16:

- Fix build reproducability when PCH is used.
- Fix auto-detection of Zen6 [bsc#1277919]

- Remove support for s390 (32bit), make sure to configure s390x with
  --disable-multilib to avoid configury error without explicit
  disable of multilibs.  Support for s390 is officially deprecated.

-----------------------------------------------------------------
Advisory ID: 1733
Released:    Tue Sep 22 09:23:33 2026
Summary:     Security update for util-linux
Type:        security
Severity:    important
References:  1261606,1268886,1269583,1270219,1275441,1278347,1278348,1278349,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614,CVE-2026-76642,CVE-2026-78408,CVE-2026-78410
This update for util-linux fixes the following issues:

- CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606).
- CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886).
- CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886).
- CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec
  Bypass in SUID mount(8) (bsc#1268886).
- CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege
  escalation (bsc#1278349).
- CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or
  termination of root processes (bsc#1278348).
- CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode`
  redirection (bsc#1278347).

Changes for util-linux:

- lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441)
- lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value
- lib/fileutils: fix unused parameter warnings without SYS_openat2
- libmount: add missing fileutils.h include to hook_idmap.c
- libmount: add mnt_open_tree() helper for safe tree opening
- libmount: pin source path with openat2() for restricted users
 (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: restrict source path canonicalization for non-root
 users (bsc#1275441, bsc#1278347, CVE-2026-78410)
- libmount: skip post-mount hooks after failed mount helper
 (bsc#1275441, bsc#1278349, CVE-2026-76642)
- libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook
- nsenter: close cgroup.procs fd after join to prevent authority
 leak (bsc#1275441, bsc#1278348, CVE-2026-78408)
- nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441,
 bsc#1278348, CVE-2026-78408)
- wall, write: sanitize hostname in banner header (bsc#1275441)
- Add missing function. (bsc#1275441)
- ipcutils: Prevent using uninitialized variable (bsc#1268886)
- BREAKING CHANGE:
 Paths must always be canonicalized for unprivileged users to
 ensure safe target resolution. X-mount.nocanonicalize is ignored
 for them.
- INCOMAPTIBLE CHANGE (linux < 6.15):
 X-mount.subdir: The safe detached subdirectory is no more
 supported for unprivileged users for safety reasons.
- liblastlog2: Wait on busy SQLite connections (bsc#1268886).
- libmount: Fix subvolid buffer overflow in get_btrfs_fs_root
 (bsc#1268886).
- libblkid: Fix use-after-free in nested partition probing
 (bsc#1269583, bsc#1268886, CVE-2026-13595)
- libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy
 mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx).
- fileutils: add ul_open_no_symlinks() needed by other patches
 (bsc#1268886).
- libmount: add fd_target to context for TOCTOU race condition
 prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g).
- libmount: ignore X-mount.nocanonicalize for restricted users
- libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886,
 CVE-2026-53612, GHSA-g8wm-75wr-g2vh).
- libmount: restrict X-mount.subdir for non-root (bsc#1268886).
- libmount: use fd_target in hook_idmap for move_mount()
- libmount: add mount ID verification and man page TOCTOU note
- loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file
 (bsc#1268886#c2, bsc#1261606).
- Ignore pam-config error that prevents update failure if common*
 pam configuration is not symlink to common-*-pc (bsc#1270219).

-----------------------------------------------------------------
Advisory ID: 1754
Released:    Thu Sep 24 09:07:13 2026
Summary:     Security update for expat
Type:        security
Severity:    important
References:  1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:

- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
  denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
  XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
  handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
  overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
  execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
  corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
  code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
  application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
  of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
  (bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
  arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
  disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
  denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
  conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
  storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
  as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
  memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
  insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
  crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).

Changes for expat:

- Updated to version 2.8.4


The following package changes have been done:

- libgcc_s1-16.2.0+git9497-160000.2.1 updated
- libstdc++6-16.2.0+git9497-160000.2.1 updated
- libblkid1-2.41.1-160000.5.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libsmartcols1-2.41.1-160000.5.1 updated
- libuuid1-2.41.1-160000.5.1 updated
- libmount1-2.41.1-160000.5.1 updated
- libfdisk1-2.41.1-160000.5.1 updated
- util-linux-2.41.1-160000.5.1 updated
- container:registry.suse.com-bci-bci-base-16.0-62985aa8edf7f04db3b4310e94844af1c7f442499fe4445a61e4c6cd4df2333b-0 updated


More information about the sle-container-updates mailing list