SUSE-CU-2026:11432-1: Security update of bci/spack

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Oct 3 08:53:10 UTC 2026


SUSE Container Update Advisory: bci/spack
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11432-1
Container Tags        : bci/spack:0.23 , bci/spack:0.23.1 , bci/spack:0.23.1-25.65 , bci/spack:latest
Container Release     : 25.65
Severity              : important
Type                  : security
References            : 1280587 1280589 1280590 1280591 1280592 1280594 1280595 1280596
                        1280597 1280598 1280599 1281125 CVE-2026-35189 CVE-2026-35191
                        CVE-2026-54872 CVE-2026-54875 CVE-2026-72897 CVE-2026-75804 CVE-2026-75805
                        CVE-2026-75806 CVE-2026-77696 CVE-2026-84782 CVE-2026-84784 
-----------------------------------------------------------------

The container bci/spack was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:4414-1
Released:    Fri Oct  2 09:37:26 2026
Summary:     Security update for openssl-3
Type:        security
Severity:    important
References:  1280587,1280589,1280590,1280591,1280592,1280594,1280595,1280596,1280597,1280598,1280599,1281125,CVE-2026-35189,CVE-2026-35191,CVE-2026-54872,CVE-2026-54875,CVE-2026-72897,CVE-2026-75804,CVE-2026-75805,CVE-2026-75806,CVE-2026-77696,CVE-2026-84782,CVE-2026-84784
This update for openssl-3 fixes the following issues:

- CVE-2026-35189: Excessive Memory Allocation in Relative CRLDP Processing (bsc#1280589).
- CVE-2026-35191: QUIC Unvalidated Amplification Credit may be Over Accounted (bsc#1280590).
- CVE-2026-54872: Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves (bsc#1280591).
- CVE-2026-54875: Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V (bsc#1280592).
- CVE-2026-72897: Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake (bsc#1280594).
- CVE-2026-75804: QUIC Connection-Level Flow Control is Not Enforced for Streams (bsc#1280595).
- CVE-2026-75805: NULL Pointer Dereference in CMP Client Revocation Response Handling (bsc#1280596).
- CVE-2026-75806: Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS (bsc#1280597).
- CVE-2026-77696: Timing Side-Channel in SM2 Signature Generation (bsc#1280598).
- CVE-2026-84782: DTLS Retransmits Handshake Messages From a Stale Buffer Offset (bsc#1280587).
- CVE-2026-84784: QUIC: Unbounded RETIRE_CONNECTION_ID Backlog (bsc#1280599).

Other non-security fixes:  
- Add a conflicts with previous crypto-policies versions (bsc#1281125)


The following package changes have been done:

- libopenssl-3-devel-3.5.0-150700.5.53.2 updated


More information about the sle-container-updates mailing list