SUSE-CU-2026:11460-1: Security update of bci/bci-init
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Oct 3 09:43:39 UTC 2026
SUSE Container Update Advisory: bci/bci-init
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11460-1
Container Tags : bci/bci-init:16.0 , bci/bci-init:16.0-13.26
Container Release : 13.26
Severity : important
Type : security
References : 1262263 1264713 1267631 1268572 1268573 1274723 1274726 1275096
1275441 1275594 1275732 1275859 1275860 1275915 1276892 1276946
1277247 1277262 1277707 1277708 1277709 1277710 1277711 1277712
1277713 1277921 1277922 1279893 1280049 1280050 1280051 1280052
1280053 1280054 1281297 1282509 CVE-2026-18374 CVE-2026-19499
CVE-2026-19542 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131
CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406
CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411
CVE-2026-56412 CVE-2026-6368 CVE-2026-66046 CVE-2026-6791 CVE-2026-72522
CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957 CVE-2026-77117
CVE-2026-80489 CVE-2026-86145 CVE-2026-8674 CVE-2026-86805 CVE-2026-89156
CVE-2026-89157 CVE-2026-89158 CVE-2026-89160 CVE-2026-89161 CVE-2026-89162
-----------------------------------------------------------------
The container bci/bci-init was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: 1747
Released: Wed Sep 23 21:42:24 2026
Summary: Security update for pcre2
Type: security
Severity: important
References: 1277707,1277708,1277709,1277710,1277711,1277712,1277713,1279893,1280049,1280050,1280051,1280052,1280053,1280054,CVE-2026-86145,CVE-2026-89156,CVE-2026-89157,CVE-2026-89158,CVE-2026-89160,CVE-2026-89161,CVE-2026-89162
This update for pcre2 fixes the following issues:
- CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893).
- CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054).
- CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053).
- CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052).
- CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject
(bsc#1280051).
- CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match`
(bsc#1280050).
- CVE-2026-89162: information disclosure via `pcre2_serialize_encode` (bsc#1280049).
-----------------------------------------------------------------
Advisory ID: 1748
Released: Wed Sep 23 21:47:23 2026
Summary: Security update for kbd
Type: security
Severity: important
References: 1275441,CVE-2026-72693
This update for kbd fixes the following issue:
- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
`passwordless` root login (bsc#1275441).
-----------------------------------------------------------------
Advisory ID: 1754
Released: Thu Sep 24 09:07:13 2026
Summary: Security update for expat
Type: security
Severity: important
References: 1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:
- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
(bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).
Changes for expat:
- Updated to version 2.8.4
-----------------------------------------------------------------
Advisory ID: 1769
Released: Tue Sep 29 14:25:10 2026
Summary: Security update for glibc
Type: security
Severity: important
References: 1274723,1274726,1276892,1276946,1277247,1277262,1277921,1277922,1281297,1282509,CVE-2026-18374,CVE-2026-19499,CVE-2026-19542,CVE-2026-6368,CVE-2026-6791,CVE-2026-77117,CVE-2026-80489,CVE-2026-8674,CVE-2026-86805
This update for glibc fixes the following issues:
- CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726).
- CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723).
- CVE-2026-8674: reachable assert in `resolv/resolv_conf.c:update_from_conf` allows an attacker in a local network to
trigger a process crash (bsc#1281297).
- CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262).
- CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892).
- CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946).
- CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921).
- CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922).
- CVE-2026-86805: TOCTOU race condition in the dynamic loader allows local attackers to escalate privileges
(bsc#1282509).
Other changes:
- Add -flive-patching=inline-clone to avoid untraceable inter-procedural optimizations (bsc#1277247).
The following package changes have been done:
- glibc-2.40-160000.7.1 updated
- libpcre2-8-0-10.45-160000.4.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libkbdfile1-2.7.1-160000.3.1 updated
- libkfont0-2.7.1-160000.3.1 updated
- libkeymap1-2.7.1-160000.3.1 updated
- kbd-2.7.1-160000.3.1 updated
- container:registry.suse.com-bci-bci-base-16.0-b83d6d585765c2f6aacfa37676547be3e9c2c36fa6b0c7b3f8abdc9ff31f8310-0 updated
More information about the sle-container-updates
mailing list