SUSE-CU-2026:11406-1: Security update of suse/ltss/sle15.6/bci-base-fips

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Oct 3 08:26:32 UTC 2026


SUSE Container Update Advisory: suse/ltss/sle15.6/bci-base-fips
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11406-1
Container Tags        : suse/ltss/sle15.6/bci-base-fips:15.6 , suse/ltss/sle15.6/bci-base-fips:15.6-35.106 , suse/ltss/sle15.6/bci-base-fips:latest
Container Release     : 35.106
Severity              : important
Type                  : security
References            : 1280587 1280589 1280591 1280596 1280597 1280598 CVE-2026-35189
                        CVE-2026-54872 CVE-2026-75805 CVE-2026-75806 CVE-2026-77696 CVE-2026-84782
-----------------------------------------------------------------

The container suse/ltss/sle15.6/bci-base-fips was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4419-1
Released:    Fri Oct  2 12:23:25 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1280587,1280589,1280591,1280596,1280597,1280598,CVE-2026-35189,CVE-2026-54872,CVE-2026-75805,CVE-2026-75806,CVE-2026-77696,CVE-2026-84782
This update for openssl-3 fixes the following issues:

- CVE-2026-35189: Excessive Memory Allocation in Relative CRLDP Processing (bsc#1280589).
- CVE-2026-54872: Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves (bsc#1280591).
- CVE-2026-75805: NULL Pointer Dereference in CMP Client Revocation Response Handling (bsc#1280596).
- CVE-2026-75806: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS (bsc#1280597).
- CVE-2026-77696: Timing Side-Channel in SM2 Signature Generation (bsc#1280598).
- CVE-2026-84782: DTLS Retransmits Handshake Messages From a Stale Buffer Offset (bsc#1280587).


The following package changes have been done:

- libopenssl3-3.1.4-150600.5.67.1 updated
- container:sles15-ltss-image-15.6.0-5.97 updated


More information about the sle-container-updates mailing list