SUSE-CU-2026:11398-1: Security update of private-registry/harbor-jobservice
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Oct 3 07:20:50 UTC 2026
SUSE Container Update Advisory: private-registry/harbor-jobservice
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11398-1
Container Tags : private-registry/harbor-jobservice:2.13 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5 , private-registry/harbor-jobservice:2.13.5-1.83 , private-registry/harbor-jobservice:2.13.5-1.83 , private-registry/harbor-jobservice:latest
Container Release : 1.83
Severity : important
Type : security
References : 1267610 1274723 1274726 1276892 1276946 1277262 1277921 1277922
1280587 1280589 1280590 1280591 1280592 1280594 1280595 1280596
1280597 1280598 1280599 1281125 CVE-2026-18374 CVE-2026-19499
CVE-2026-19542 CVE-2026-35189 CVE-2026-35191 CVE-2026-54872 CVE-2026-54875
CVE-2026-6368 CVE-2026-6791 CVE-2026-72897 CVE-2026-75804 CVE-2026-75805
CVE-2026-75806 CVE-2026-77117 CVE-2026-77696 CVE-2026-80489 CVE-2026-84782
CVE-2026-84784
-----------------------------------------------------------------
The container private-registry/harbor-jobservice was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4250-1
Released: Thu Sep 17 18:00:36 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1267610,1274723,1274726,1276892,1276946,1277262,1277921,1277922,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489
This update for glibc fixes the following issues:
- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4414-1
Released: Fri Oct 2 09:37:26 2026
Summary: Security update for openssl-3
Type: security
Severity: important
References: 1280587,1280589,1280590,1280591,1280592,1280594,1280595,1280596,1280597,1280598,1280599,1281125,CVE-2026-35189,CVE-2026-35191,CVE-2026-54872,CVE-2026-54875,CVE-2026-72897,CVE-2026-75804,CVE-2026-75805,CVE-2026-75806,CVE-2026-77696,CVE-2026-84782,CVE-2026-84784
This update for openssl-3 fixes the following issues:
- CVE-2026-35189: Excessive Memory Allocation in Relative CRLDP Processing (bsc#1280589).
- CVE-2026-35191: QUIC Unvalidated Amplification Credit may be Over Accounted (bsc#1280590).
- CVE-2026-54872: Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves (bsc#1280591).
- CVE-2026-54875: Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V (bsc#1280592).
- CVE-2026-72897: Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake (bsc#1280594).
- CVE-2026-75804: QUIC Connection-Level Flow Control is Not Enforced for Streams (bsc#1280595).
- CVE-2026-75805: NULL Pointer Dereference in CMP Client Revocation Response Handling (bsc#1280596).
- CVE-2026-75806: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS (bsc#1280597).
- CVE-2026-77696: Timing Side-Channel in SM2 Signature Generation (bsc#1280598).
- CVE-2026-84782: DTLS Retransmits Handshake Messages From a Stale Buffer Offset (bsc#1280587).
- CVE-2026-84784: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog (bsc#1280599).
Other non-security fixes:
- Add a conflicts with previous crypto-policies versions (bsc#1281125)
The following package changes have been done:
- glibc-2.38-150600.14.58.1 updated
- libopenssl3-3.5.0-150700.5.53.2 updated
- openssl-3-3.5.0-150700.5.53.2 updated
- system-user-harbor-2.13.5-150700.2.7 updated
- harbor213-jobservice-2.13.5-150700.2.7 updated
- container:suse-sle15-15.7-a487b809bb79c405a61bade69958738f14ef31118f5db914afa582498de5ba00-0 updated
- container:registry.suse.com-bci-bci-micro-15.7-52cd5d552529b8f05d86496cc7452e74d338a8542fff899a25617e783fa4bd6c-0 updated
More information about the sle-container-updates
mailing list