SUSE-CU-2026:11479-1: Security update of suse/sles/16.0/virt-launcher

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Sat Oct 3 09:51:47 UTC 2026


SUSE Container Update Advisory: suse/sles/16.0/virt-launcher
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:11479-1
Container Tags        : suse/sles/16.0/virt-launcher:1.9 , suse/sles/16.0/virt-launcher:1.9.0 , suse/sles/16.0/virt-launcher:1.9.0-2.7
Container Release     : 2.7
Severity              : important
Type                  : security
References            : 1262263 1264713 1265974 1267631 1268572 1268573 1271272 1275096
                        1275441 1275594 1275732 1275859 1275860 1275915 1279561 1279584
                        1279588 1279593 1279595 1279782 1279783 1279784 1279843 1280108
                        1280884 1280910 1280941 CVE-2026-0799 CVE-2026-18238 CVE-2026-18313
                        CVE-2026-31911 CVE-2026-31912 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219
                        CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405
                        CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410
                        CVE-2026-56411 CVE-2026-56412 CVE-2026-6244 CVE-2026-6554 CVE-2026-66046
                        CVE-2026-72522 CVE-2026-72693 CVE-2026-76641 CVE-2026-76956 CVE-2026-76957
                        CVE-2026-88806 
-----------------------------------------------------------------

The container suse/sles/16.0/virt-launcher was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: 1736
Released:    Tue Sep 22 13:11:46 2026
Summary:     Security update for libX11
Type:        security
Severity:    important
References:  1280910,CVE-2026-88806
This update for libX11 fixes the following issue:

- CVE-2026-88806: XkbGetMap Reply Heap-based Buffer Overflow (bsc#1280910).

-----------------------------------------------------------------
Advisory ID: 1741
Released:    Wed Sep 23 11:15:05 2026
Summary:     Recommended update for libvirt
Type:        recommended
Severity:    important
References:  1265974,1279561,1279843,1280884
This update for libvirt fixes the following issues:

Changes in libvirt:

- qemu:
    * Fix missing audit record and shutdown lifecycle event of
      VMs with shutdown times exceeding 40 seconds (bsc#1280884)
    * Fix cleanup of VMs with shutdown times exceeding 40 seconds (bsc#1265974)
    * Fix incoming migration to QEMU 10.0.0 and newer (bsc#1279843)
    * Fix hot plugged host CPUs not being used (bsc#1279561)

-----------------------------------------------------------------
Advisory ID: 1749
Released:    Wed Sep 23 21:44:23 2026
Summary:     Security update for libpcap
Type:        security
Severity:    important
References:  1279584,1279588,1279593,1279595,1279782,1279783,1279784,CVE-2026-0799,CVE-2026-18238,CVE-2026-18313,CVE-2026-31911,CVE-2026-31912,CVE-2026-6244,CVE-2026-6554
This update for libpcap fixes the following issues:

- CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a
  scratch memory register and allows for OOB access (bsc#1279782).
- CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the
  immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero
  (bsc#1279595).
- CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward
  jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584).
- CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly
  validates its headers and allows for an OOB access (bsc#1279783).
- CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ`
  message received from the client and never frees the memory (bsc#1279784).
- CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode.
  In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588).
- CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a
  return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff
  (bsc#1279593).

-----------------------------------------------------------------
Advisory ID: 1748
Released:    Wed Sep 23 21:47:23 2026
Summary:     Security update for kbd
Type:        security
Severity:    important
References:  1275441,CVE-2026-72693
This update for kbd fixes the following issue:

- CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows
  `passwordless` root login (bsc#1275441).

-----------------------------------------------------------------
Advisory ID: 1754
Released:    Thu Sep 24 09:07:13 2026
Summary:     Security update for expat
Type:        security
Severity:    important
References:  1262263,1264713,1267631,1268572,1268573,1275096,1275594,1275732,1275859,1275860,1275915,CVE-2026-41080,CVE-2026-45186,CVE-2026-50219,CVE-2026-56131,CVE-2026-56132,CVE-2026-56403,CVE-2026-56404,CVE-2026-56405,CVE-2026-56406,CVE-2026-56407,CVE-2026-56408,CVE-2026-56409,CVE-2026-56410,CVE-2026-56411,CVE-2026-56412,CVE-2026-66046,CVE-2026-72522,CVE-2026-76641,CVE-2026-76956,CVE-2026-76957
This update for expat fixes the following issues:

- CVE-2026-41080: crafted XML document can cause a denial of service (bsc#1262263).
- CVE-2026-45186: In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a
  denial of service via moderately sized crafted XML input (bsc#1264713).
- CVE-2026-50219: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse,
  XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation (bsc#1267631).
- CVE-2026-56131: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within
  handlers in cases of a policy violation (bsc#1268572).
- CVE-2026-56132: mishandled memory reallocation during array scaffolding in doProlog can cause heap-based buffer
  overflows (bsc#1268573).
- CVE-2026-56403: integer overflow in the storeAtts function can cause memory corruption and potential arbitrary code
  execution (bsc#1275096).
- CVE-2026-56404: integer overflow in the addBinding function can cause undersized memory allocations, memory
  corruption, and application crashes (bsc#1275096).
- CVE-2026-56405: integer overflow in the getAttributeId function can cause heap memory corruption and arbitrary
  code execution (bsc#1275096).
- CVE-2026-56406: missing bounds validation in XML_ParseBuffer can cause integer overflows, memory corruption, and
  application crashes (bsc#1275096).
- CVE-2026-56407: integer overflow in doProlog related to entity text length can cause memory corruption and denial
  of service (bsc#1275096).
- CVE-2026-56408: integer overflow in the copyString function can cause heap memory corruption and application crashes
  (bsc#1275096).
- CVE-2026-56409: integer overflow in the xmlwf utility output filename handling can allow path buffer corruption and
  arbitrary file write conditions (bsc#1275096).
- CVE-2026-56410: integer overflow in resolveSystemId within the xmlwf utility can cause memory corruption, information
  disclosure, and potential code execution (bsc#1275096).
- CVE-2026-56411: integer overflow in endDoctypeDecl via NOTATION declarations in xmlwf can cause memory corruption and
  denial of service (bsc#1275096).
- CVE-2026-56412: incomplete handler call depth tracking in doCdataSection can cause use-after-free
  conditions and arbitrary code execution (bsc#1275096).
- CVE-2026-66046: libexpat: denial of service vulnerability caused by quadratic algorithmic complexity in the
  storeAtts() function in xmlparse.c (bsc#1275732).
- CVE-2026-72522: libexpat: out-of-bounds read and resultant infinite loop due to low surrogates being treated the same
  as high surrogates during Unicode processing (bsc#1275594).
- CVE-2026-76641: Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger
  memory corruption (bsc#1275915).
- CVE-2026-76956: In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to
  insufficient entropy, which results in being vulnerable to hash flooding attacks, causing a denial of service via
  crafted X (bsc#1275860).
- CVE-2026-76957: libexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. (bsc#1275859).

Changes for expat:

- Updated to version 2.8.4

-----------------------------------------------------------------
Advisory ID: 1756
Released:    Thu Sep 24 11:47:49 2026
Summary:     Recommended update for ovmf
Type:        recommended
Severity:    moderate
References:  1280108
This update for ovmf fixes the following issues:

Changes in ovmf:

- Add unversioned 'virt' machine in riscv64 ovmf descriptor (bsc#1280108)

-----------------------------------------------------------------
Advisory ID: 1762
Released:    Fri Sep 25 11:09:47 2026
Summary:     Recommended update for tar
Type:        recommended
Severity:    moderate
References:  1271272,1280941
This update for tar fixes the following issues:

Changes in tar:

- Fixes tar incorrectly skipping members in certain archives containing
  dirs with non-zero sizes. (bsc#1271272)
- Avoid acl_ prefix for functions:
    * The acl.h header from libacl uses acl_ prefix for its functions.
      Avoid defining functions with the same name in order to protect its namespace. (bsc#1280941)


The following package changes have been done:

- libX11-data-1.8.10-160000.4.1 updated
- libexpat1-2.8.4-160000.1.1 updated
- libkbdfile1-2.7.1-160000.3.1 updated
- libkfont0-2.7.1-160000.3.1 updated
- libkeymap1-2.7.1-160000.3.1 updated
- libX11-6-1.8.10-160000.4.1 updated
- tar-1.35-160000.5.1 updated
- kbd-2.7.1-160000.3.1 updated
- libpcap1-1.10.5-160000.5.1 updated
- libvirt-libs-11.4.0-160000.6.1 updated
- libvirt-daemon-log-11.4.0-160000.6.1 updated
- libvirt-client-11.4.0-160000.6.1 updated
- libvirt-daemon-common-11.4.0-160000.6.1 updated
- qemu-ovmf-x86_64-202502-160000.8.1 updated
- libvirt-daemon-driver-qemu-11.4.0-160000.6.1 updated
- container:bci-bci-base-16.0-b83d6d585765c2f6aacfa37676547be3e9c2c36fa6b0c7b3f8abdc9ff31f8310-0 updated
- container:registry.suse.com-bci-bci-micro-16.0-46b3f28a6ade6e6ff39d13ee8e50d3bd1b241d037b9702364dc35000188fbb36-0 updated


More information about the sle-container-updates mailing list